Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

61–70 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#61

Earlier quoted context omitted.

Around here, typical to have 1 to 3 federal races, 5 to 8 statewide offices, 10 to 20 county and municipal contests, a handful of judge retention questions, and 1 to 20 other referendums. About half the races are usually uncontested. It may take some time to fill out a ballot paper. But the act of voting itself is inserting the ballot paper into the locked and monitored ballot box, which takes a second or two. My pol…

Yes, electronic voting machines are the problem. That is what this article is about.

And I'm saying they can never not be a problem. The usage requirements make them 100% incompatible with election security.

They are broken by design, and utterly unfixable. The specifics of the known exploits are therefore somewhat irrelevant, because there will always be some means of compromising them. So the only way forward would be to treat every last one of them as permanently untrusted hardware.

While there may be some way to make them useful in an election, for now, until that PhD cryptography paper comes out that solves the problem, the only reasonable thing to do is toss them all in the trash, and go back to inked paper.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#62
post #10

There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…

You should bring this to the attention of USAFActs. Even if you're not a Ballmer fan, they do have the necessary resources for this sort of work and it seems like it would align with their mission.

https://usafacts.org/

Maybe we could start tweeting them? https://twitter.com/usafacts/

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#63
post #21
post #10

There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…

Specifically, this makes the job much easier for non-tech journalists to report on the findings. Consider that Heartbleed practically became a meme due to the discoverers’ creation of a logo and website. If you want to stop the hack, social-hack the fix.

>If you want to stop the hack, social-hack the fix.

It's a little tangential, but I think this comment is evidence that the verb "hack" has finally completed its evolution into a synonym for "do."

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#64

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Oh wow, did they really call it that? I mean it's not wrong, the net neutrality debate is about deregulating the internet by the government so that the ISPs can regulate it. But you have to know what more freedom for ISPs can entail. I mean if it was called Unlimited Gun Use Freedom it could be a name for legalized murder.

It wasn't far from what the FCC called the repeal to net-neutrality: "Restoring Internet Freedom" Order - https://www.fcc.gov/document/fcc-releases-restoring-internet...

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#65

Really don't like how political and advocative DefCon has gotten. Finding and publishing vulnerabilities is fine. But DefCon shouldn't be advocating policy or fixes. That should be left to the government, businesses, etc. The more defcon mixes with authorities, the better.

If [the government, businesses, etc.] could not (or did not) find these vulnerabilities, most of which seem like things your average techie might have checked for, what evidence is there to suggest that [the government, businesses, etc.] know how to fix them either?

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#67
post #7

Earlier quoted context omitted.

> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.

When you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.

This is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues.

1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#68
This is a lot like consumer cryptography - yes, technical exploits are a problem, but they're overshadowed by social engineering.

In the case of US elections - even with secure infrastructure, the election will be determined by billionaire-sponsored campaign budgets and policies that entrench the 2 party system.

After the DNC email leak, I'm amazed how little attention was placed on hard evidence that the Democratic Party methodically sabotaged candidates in the primaries. Shifting public focus to the "Russian Hacking" was amazing PR work.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#69
> A second critical vulnerability in the same machine was disclosed to the vendor a decade ago​, yet that machine, which was used into 2016, still contains the flaw.

Sometimes I wonder how some people manage to keep their jobs, and how companies manage to keep their contracts. This is gross negligence.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#70

That's why you research and read before you go. Otherwise you'll wind up voting yes to "Proposition B: Unlimited Internet Freedom" which does something possibly disastrous despite the title. Because that's how Republicans roll.

Did you even read the comment you're replying to?

My fault, I missed

> even when you know how you will vote in advance.

Post reply on HN