Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

541–550 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#541
post #508

Earlier quoted context omitted.

> Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. What? There are entire systems built around doing exactly that. Embedded, military, high-trust. It's never state of the art performance or mass deployed, because most people…

>What? There is no way to demonstrate that what is executing is the source code unless you're compiling at execution time from a local vetted copy of the source code. Is the guy who vetted the source code vetted? Who vets the vetter? Is the compiler actually compiling the source code? Is the compiler compiling as generally expected? What about bugs in the compiler? Is the source code even what it claims (binary blobs…

The questions you're asking make it seem like (a) you're not thinking about this very hard, (b) you're trying to reach the answer you've already decided on, or (c) you're not familiar with high trust systems.

Still, in the interest of a conversation, some brief answers. Please ask in detail about any you're interested in (but realize I'm going to balance the time I spend answering with the time you spend researching and asking).

"Is the guy who vetted the source code vetted?" Yes, because he or she was assigned a key and signed the code with it.

"Who vets the vetter?" Whatever level of diligence you want, up to and including TS+SCI level.

"Is the compiler actually compiling the source code? Is the compiler compiling as generally expected? What about bugs in the compiler?" This is why you test. And it's pathological to believe that well-tested compilers, that have built trillions of lines of code, are going to only fail to successfully compile election code.

"Is the source code even what it claims (binary blobs!)?" See test and also dependency review and qualification.

"What about the hardware? Are there any black box enclaves?" Yes, by design, because that's how secure systems are built. And no, the enclaves aren't black boxes.

"Bugs? Does it actually crunch as would be generally expected of a number cruncher?" Testing and validation.

"Does it even have the vetted software?" Signed executables, enforced by trusted hardware.

> Meanwhile, someone counting paper ballots by hand can be immediately understood by anyone and everyone. It's simple and it's brutally effective

No, it's not. Because people are messy, error-prone entities, especially when it comes to doing a boring process 100+ times in a row.

You're not comparing against perfection: you're comparing against at best bored/distracted and at worst possibly-partisan humans.

Human counts rarely match exactly, because humans make mistakes. And then they make mistakes in the recounts intended to validate counts.

If you can't envision all the ways humans can fail, then I'd reflect on why things never fail at your work because of people, and everything always runs smoothly.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#542
post #511

Earlier quoted context omitted.

Thank you for engaging point by point. Let’s look: 1) Easy to check by whom? With paper, it’s a bunch of people yelling to the news they saw discrepancies. In USA, we have probably the most expensive election in the world and we heard it all in 2020 from sour Republicans. To this day many people believe the election wasn’t secure and was “stolen”, including with physical ballots being shipped in, etc. On the one hand…

Since Bush was the one to push them into NATO back in 2008 when the Ukrainian public strongly opposed NATO membership until 2014, but he worked with Yuschenko to do it anyway. Except he did not "push them into NATO in 2008". 2008 was the year that Ukraine's membership application was formally rejected by NATO , and there it has sat, in the doghouse, ever since. But Putin invaded anyway, because the NATO noise was nev…

NATO member countries didn’t really want Ukraine, Ukrainian citizens really didn’t want NATO, but in 2008 Bush vowed to press for both Ukraine and Georgia to join NATO.

https://www.reuters.com/article/world/bush-to-press-for-ukra...

Saakashvili of Georgia (who is now in jail for corruption) also had two breakaway republics at the time — Ossetia and Abhazia — and he engaged in a war with them and kept hoping NATO would come. Back then Putin wasn’t even president, it was Medvedev. Anyway, the same exact war started happening back then, with Russia invading Georgia with tanks moving slowly to the capitol, Tbilisi. Their goal was to intimidate them into agreeing to stop shelling the two breakaway republics and leave them alone. (Georgia and Armenia, in turn, had been protected by Russia from Ottomans, much the same way).

The difference in that war was that it ended in a week, because Nicolas Sarkozy (the French president) negotiated a peace agreement successfully. Since then Russia hasn’t invaded Georgia further, simply protected Abhazia and Ossetia, in fact Georgia has been normalizing relations with Russia and opened up direct flights and tourism last year etc. A great outcome for all civilians, compared to what could have been a senseless war. I was in Georgia last year and saw it firsthand.

Meanwhile, after the regime change revolution in Ukraine in 2014, the CIA had 8 years to build up weapons and paramilitaries etc. Same exact playbooj that ravaged Afghanistan w the mujahideen (Arabic for “jihadists”) and Afghan Arabs, masterminded by Zbignew Brezhinski. This time it was CIA in Ukraine: https://news.yahoo.com/cia-trained-ukrainian-paramilitaries-...

So in 2022 when Russians tried the same playbook (intimidate Kyiv into not shelling the two breakway republics) they didn’t expect the Ukrainians to walk away from the negotiating table. They waited for them in Belarus under Lukashenko (where they had signed the Minsk accords years earlier, endorsed unanimously by the UN security council) but the Ukrainian negotiators kept delaying and venue shopping, and the SBU (Ukrainian KGB) even killed one of them as “a traitor” for being too eager to negotiate, a man appointed by the President himsdlf and who the Ukrainian state department called “a hero”.

I personally spoke to David Arakhamia (the guy w the hat) on Facebook Messenger in the first days of the war, he had many Ukrainians on his FB wall begging him to make a deal and avert the war. I tool screenshots and the pleading posts are still there. He privately told me he agreed w me. But when the negotiators entered the room they left after 2 hours. We don’t kmow what happens in closed rooms — whether Baker promised “not an inch” to Gorbachev, or whether the Ukrainian or Russian negotiators ever negotiated in good faith. But the civilians, the people deserve better representation. The war continued, and the tanks found themselves around Kyiv and major firefights in Bucha vs Azov and other armed groups with RPGs shooting at tanks. Kind of like the red triangle videos of Hamas vs Israeli tanks. It’s really unfortunate and was avoidable. Russia expected it to go like the last war, it didn’t.

Naftali Bennett was the Israeli PM and he could have played the role of Nicolas Sarkozy did with Medvedev (Russia) and Saakashvili (Georgia). He has a tell-all interview in Hebrew about how he had negotiated peace DIRECTLY between Putin and Zelensky, and had them both make major concessions — eg Ukraine wouldn’t join NATO, and Putin promised not to kill Zelensky. In his interview he said that Zelensky double-checked this and then came out to record his famous video “I am not afraid, I am here” and saying he needs ammunition, not a ride.

Why did Bennett not succeed? He said he “coordinated everything to the smallest detail” with the US and UK, he “doesn’t do as he pleases”, and they told him he MUST stop the peace deal. He said he “thought they were wrong” and still does. That peace is worth a shot. But he didn’t continue, and the war didnt stop 2 weeks into it.

https://www.youtube.com/watch?v=0yma0LxyVVs

Erdogan luckilh WAS able to negotiate a year-long grain export deal in the midst of a war, which likely saved millions of lives — Yemen had been very dependent on Ukrainian grain and had a famine from yet ANOTHER proxy war (this one between Iran and Saudis w US weapons, same kind of war but with roles reversed). But no one seemed to care about Yemenis, despite millions being in far more dire hunger conditions than Ukrainians ever were.

The world is complex, but Bush had started the stupid push into NATO, even as NATO members were slowwalking him. My guess is he was angry at Putin’s Munich speech in 2007 NATO, calling out USA for invading Iraq and violating international law. Back in 2001 Putin was the first president after 9/11 to call Bush and offer condolences and they made a joint anti-terrorism initiative. Putin wanted to join NATO back in 2001, he asked the NATO heads but was always rejected. Since 2002(!) Russia tried to stop the invasion of Iraq in the security council and every other way it could but Bush couldn’t be stopped. That is when I think Russia realized that after Kosovo and Iraq, that NATO isnt purely defensive and USA isnt going to be constrained by international law. Putin’s speech in 2007 made Bush want to flip Russia’s neighbors (about which every ambassador said it was a red line for anyone in Russia, “not just Putin”) so the result was predetermined:

https://theconversation.com/ukraine-war-follows-decades-of-w...

As for why Bush did it — I will let Bush say it in his own words: https://www.youtube.com/watch?v=MTX5uvZWu3Q

Re: Colorado scrambles to change voting-system passwords after accidental leak

#543
post #352

Earlier quoted context omitted.

It avoids dangling chads and improperly filled bubbles which were both used to steal the 2000 presidential election. I have never used such a machine but the UX could be a lot clearer than the analog filp-and-punch machines used in Florida in 2000. I don’t love software in the voting process but printing the choices is verifiable and reduces ambiguity in the voting process.

It seems like quite a stretch to say the 2000 election was stolen. There were definitely ballot issues, but Gore challenged it and ultimately decided of his own accord to concede. He could have continued the challenge and drawn the process out, throwing in throwing in the towel to allow the process to end was his choice, it wasn't stolen.

He didn’t “decide of his own accord to concede”. The US Supreme Court decided for him by ending any further path to count votes in Florida so Gore conceded when be had no other options.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#544

Earlier quoted context omitted.

scanned paper ballots. simple, fast, auditable. humans are WAY more error prone than computers at counting.

so then the attack becomes introducing enough error at critical counts such that it affects the result without being regarded as having been tampered with pretty easy if your company produced the machines

How would this defeat doing a statistical hand sampling of the ballots to verify the electronic counting is accurate?

Re: Colorado scrambles to change voting-system passwords after accidental leak

#545
post #272

Earlier quoted context omitted.

This is the kind of boring "both side-ism" that I just don't understand. I have no great love of either party, but one side is openly speculating about all sorts of things that cannot be described as anything other than outright authoritarian, and the other party ... is not. And no, some disagreements on free speech or the 2nd amendment or whatnot is not even close. And no, "oh, he's not really serious about it" does…

The issue in question was truth, not authoritarianism. Specifically, the issue was truth about election security. The point was that both sides will, and have, claim election fraud when they lose, and "most secure election in history" when they win. More generally: In the current election, Harris isn't the firehose of lies that Trump is. She isn't a shining beacon of truth, either.

"Most secure election in history" was a superlative I'm not happy with either, no. But the core of it is correct: there is no evidence of wide-spread fraud.

The core of the other side is outright lies and fraud, rooted in nothing more than one person's narcissism.

Equating these two is just bizarre. "Murder, arson, and jaywalking". Or something like that.

And "both sides will, and have, claim election fraud when they lose" is just not true. There have been a few disagreements over the decades of course, some more reasonable than others, but nothing like 2016 has happened in recent history, from either party.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#546

Earlier quoted context omitted.

scanned paper ballots. simple, fast, auditable. humans are WAY more error prone than computers at counting.

so then the attack becomes introducing enough error at critical counts such that it affects the result without being regarded as having been tampered with pretty easy if your company produced the machines

Random audits can generally solve this. Take a random count from a random machine and validate that it matches the hand count. If I’m trying to rig an election I would have to be very reckless to just cross my fingers and hope that the systems I hacked aren’t audited. I’d have to bribe the auditors or something, and at that point it’s simpler to just bribe people anyway and not bother with the whole hacking part.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#547
post #350

Earlier quoted context omitted.

Every polling place and every vote-counting center is open to observers from both parties, by law. Your idea that one party is shut out of this system has no basis in reality.

Nope. There is a lawsuit right now in Georgia over the decision by some locations to accept ballots over the weekend without GOP observers present. Counting without bipartisan observers happened frequently in 2020. Also "observers" weren't mentioned in my original post. Just because someone watches a count is irrelevant to my original points.

You mean the one that was rejected? The lawsuit was wrong legally and morally— these are people who are eligible to vote casting their vote in a more secure manner than mailing it in, and doing so prior to election day.

There's just no moral defense of rule-lawyering to throw out valid ballots or turn away voters, and judges in red and blue states alike aren't having it.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#548
post #505

Earlier quoted context omitted.

>It adds another layer of safety. Do we still have to be able to trust the rest of the system? Yup. But I cannot trust anything at all if I cannot even verify that my vote was submitted correctly in the first place. I don't disagree that it's strictly better, but the improvements in security are marginal. Any audits/recounts would be done by looking at the human readable part of the ballot, and would therefore be una…

With a scantron voting system every single voter becomes an auditor. That’s orders of magnitude more auditing than will ever be achieved by randomized barcode audits and it will catch far smaller discrepancies. Even if a machine made only one mistake ever, it would stand a chance of getting caught. Not so with barcodes. Seems a pretty substantial difference to me.

>That’s orders of magnitude more auditing than will ever be achieved by randomized barcode audits and it will catch far smaller discrepancies. Even if a machine made only one mistake ever, it would stand a chance of getting caught. Not so with barcodes.

When was the last time you had a printer print the wrong thing? Moreover, if an election is close enough that a few votes matter, there's definitely going to be a manual recount, so any advantage is purely academic (eg. knowing that candidate A won by 51.704% rather than 51.703%). Point is, either the error is big enough that it's trivially detected with spot checks, or the margins are so close that a manual recount is performed automatically.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#549
post #506

Computers anywhere in the vote casting process introduce new, additional failure modes. These modes may be intentional (hacking) or unintentional (misconfiguring the paper size of the ballots). They may be mundane (power failure, out of ink) or esoteric (logic error). Even computerized counting has a nonzero error rate (so does human counting, but that can be challenged by human observers). Computers add cost for acq…

scanned paper ballots. simple, fast, auditable. humans are WAY more error prone than computers at counting.

Not sure if this is a "thing" or if there's a problem with it, but why not live-stream video of every vote being counted so the entire population could validate at least the counting portion of voting.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#550

Earlier quoted context omitted.

It's important to recognize that the US system involves many more races and questions on the ballot than in other (especially parliamentary) systems. Electronic-free counting in many states would significantly extend counting times; many voters have 20+ choices to make, and each of these choices would have to be counted and tracked, which introduces failure modes of their own. Counting by hand makes sense when each b…

I would suggest that the solution is less voting. Ballots are insanely complicated and there’s absolutely zero knowledge the average person has about whether any of the people are good candidates. So then they turn to their favorite voting guides which just shifts the power to unaccountable political groups instead of making the single representative you elect responsible for figuring it out. And there’s too many ele…

I find it interesting that all the countries that the US "helped" to democratize all end up with a parliamentary system instead of the US system. Unfortunately I suspect the US is just stuck with it.
Post reply on HN