Live data from Hacker News

Colorado scrambles to change voting-system passwords after accidental leak

arstechnica.com

651–660 of 682 posts

Re: Colorado scrambles to change voting-system passwords after accidental leak

#651

Earlier quoted context omitted.

I would suggest that the solution is less voting. Ballots are insanely complicated and there’s absolutely zero knowledge the average person has about whether any of the people are good candidates. So then they turn to their favorite voting guides which just shifts the power to unaccountable political groups instead of making the single representative you elect responsible for figuring it out. And there’s too many ele…

If you’re talking about minor elected offices (Clerk of Deeds, etc.) be careful what you wish for. I lived in a country which did away with many of the small elections, only to have the positions filled by toxic empire-builders. We went back to elections, where a scandal was handled by electors, not union rules. Parliamentary democracies are usually accompanied by competent, autonomous civil services. That’s not some…

> accompanied by competent, autonomous civil services. That’s not something America has.

That's a bold claim. The federal system can be incompetent and isn't autonomous. But lower level local ones tend to be especially if far away from politically contentious topics until you get to counties that are really small. Representative elections are both about accountability and about representation so I don't have to worry about minutia. As long as rules are followed and you have systems that remove influence peddling (not so much appointments as above-board job interviews with many candidates), then you can let failing to follow such rules be a scandal that takes out the politician that tried to corrupt the system.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#652
post #562

Earlier quoted context omitted.

I would suggest that the solution is less voting. Ballots are insanely complicated and there’s absolutely zero knowledge the average person has about whether any of the people are good candidates. So then they turn to their favorite voting guides which just shifts the power to unaccountable political groups instead of making the single representative you elect responsible for figuring it out. And there’s too many ele…

Re: FPTP vs ranked choice/condorcet/instant runoff/etc In US elections, any alternative voting system would essentially require computers. With all the complexity, problems and mistrust that they bring. Also those alternative systems are subject to gamification as shown in recent elections in Alaska and France. No fraud or illegality, but the will of the people was arguably thwarted by introduction of confounding can…

I think getting rid of the Senate and increasing the number of seats in the house is an instant remedy to many ills in the political system.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#653
post #511

Earlier quoted context omitted.

Thank you for engaging point by point. Let’s look: 1) Easy to check by whom? With paper, it’s a bunch of people yelling to the news they saw discrepancies. In USA, we have probably the most expensive election in the world and we heard it all in 2020 from sour Republicans. To this day many people believe the election wasn’t secure and was “stolen”, including with physical ballots being shipped in, etc. On the one hand…

Ultimately none of these details matter given the elephant in the room: you're voting on some app using your private key, and using some app to check with your private key if the vote has been correctly registered. But you have 0 way of knowing if the system is using this data in the way it was presented. For all the info you have access to, the system can just as well work like this: 1. You cast your vote using the…

Just to be clear - even though I say “Merkle Tree”, I am not saying the unhashed votes themselves would not be stored in it. The hashes are just to quickly verify integrity of the underlying data leaves (the actual votes people cast).

The anonymity is done between registration and voting. There is a cryptographic mixer like Tornado Cash that is responsible for the unlinkability, by “tumbling” the tokens to anonymize them while still making sure that each person voting legitimately had registered. (Never mind for a moment that the IP address of the voter can be tied to their address, that can be fixed too.)

So yes, ALL the votes are stored and published in the Merkle tree, and ANYONE can challenge the election, not by hearsay allegations but actual PROOF that anyone can verify. Because the public keys of the UX vendors are published along with the Merkle Tree and are caught red-handed signing conflicting votes. Either the corrupt districts or the UX vendors would have to risk literally ANYONE producing a smoking gun. It is that chilling effect that keeps them all honest, and why we have checksums for things in general. Having everyone in the world see proof of fraud is very different than a bunch of villagers claiming to a journalist locally that they hadn’t even voted.

So given this description, tell me directly — doesn’t it ADD a lot of security and reduce the attack surface and make elections standardized, cheaper and far more trustworthy - don’t you see the value in that?

Think about it — this scheme alone allows some great integrity features for elections. The “election Luddites” are essentially claiming that this has ZERO VALUE and shouldn’t even be tried, shouldn’t even be ADDED TO the existing paper systems even if you lost nothing, because it adds NO SECURITY. That is quite a claim given the properties I listed!

More generally, this is how Smart Contracts work and why they are valuable. Thousands of independently run nodes get to check the data and operations, which are public. The entire community benefits, and in fact the results of voting (eg how much UBI to give out) can be used on-chain. By lowering the cost of collective decision-making, blockchain technology enables a whole new level of efficiency (much like red lights enable better traffic flow), making things like elections or large marketplaces available to everyone without “offchain” corruption-peone mechanisms like surety bonds and reliability ratings (remember Lehman Brothers?)

Check out https://intercoin.org/applications — I would love to hear your thoughts on the other applications too.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#654

Earlier quoted context omitted.

You can already do that today by having people take a photo of their ballot. Or just buy their signed but otherwise blank mail-in ballot and complete it at gangster HQ. Or give them the money and don't require proof at all, because most people will just do what they agreed to do. This doesn't happen today because it isn't scalable and is easy to get caught and prosecuted. Electronic manipulation is more appealing bec…

Taking a photo of the ballot is illegal. Also, one can just always strike the ballot before putting it in the machine after having the completed ballot. In some places of mail in ballots it's possible to cancel the mail in ballots and vote in person after.

And bribing people to vote is already illegal in the first place. Do things being illegal stop the behavior or not? You're arguing both sides of the coin at this point.

Most people aren't going to try too hard to undermine or outsmart the gangster. Which is why, again, the perpetrator doesn't even need validation of how people actually voted. Vague threats will work just fine. In fact the gangster will still beat up a random sampling of the voters anyway.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#655

Earlier quoted context omitted.

Taking a photo of the ballot is illegal. Also, one can just always strike the ballot before putting it in the machine after having the completed ballot. In some places of mail in ballots it's possible to cancel the mail in ballots and vote in person after.

And bribing people to vote is already illegal in the first place. Do things being illegal stop the behavior or not? You're arguing both sides of the coin at this point. Most people aren't going to try too hard to undermine or outsmart the gangster. Which is why, again, the perpetrator doesn't even need validation of how people actually voted. Vague threats will work just fine. In fact the gangster will still beat up…

There's far less incentive to actually pay bribes or hurt specific people if there's no reliable proof of the vote. Even with people taking a photo of a ballot, one can still just strike that ballot and vote again after taking a photo. It's an immense risk that will likely not do you any good, because there's no way to actually know those people voted. The people you're paying and who voted for you would have likely voted for you anyways and you're just otherwise paying people to not bother voting at all or voting against you, while you face immense risk.

If the gangster is just going to hurt a random sampling of people anyways, you might as well just vote however you want to vote. They may or may not commit violence against you regardless of how you vote, its completely disconnected. If you know they can validate it, you're probably going to be less brave.

Just put yourself in those two situations. One where the ballot is absolutely secret, and one where it can be trivially looked up. Someone says you better vote for X or I'll hurt you. You really don't want to vote for X. In the first instance, do you vote for X? In the second, do you still vote for X knowing the thug will be able to know for sure how you voted?

I'm not suggesting nobody would do an illegal thing, obviously I acknowledge people would do illegal things. I'm just pointing to that as why taking a photo of a ballot is illegal in many areas.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#656
post #542

Earlier quoted context omitted.

NATO member countries didn’t really want Ukraine, Ukrainian citizens really didn’t want NATO, but in 2008 Bush vowed to press for both Ukraine and Georgia to join NATO. https://www.reuters.com/article/world/bush-to-press-for-ukra... Saakashvili of Georgia (who is now in jail for corruption) also had two breakaway republics at the time — Ossetia and Abhazia — and he engaged in a war with them and kept hoping NATO woul…

Right - Bush "pressed for" Ukraine's membership, but he wasn't successful . And in fact Putin had executed (what he should have seen as) a successful containment strategy by that date, via purely diplomatic means. Sanity prevailed, reason prevailed -- but Putin invaded anyway. That's the key takeaway here. As to the other tangents, briefly: (1) No, the Georgia conflict was not "the same exact war". It bears a certain…

I am making that analogy, there are so many elements in common, and the analogy to other proxy wars like Yemen too.

You could argue Brzezinski and CIA arming the mujahideen was also “purely defensive”, or Soviets arming the PLO a decade earlier was “purely defensive”. Both are nonsense, of course!

https://washingtonmonthly.com/2021/09/01/how-jimmy-carter-st...

https://www.counterpunch.org/1998/01/15/how-jimmy-carter-and...

And of course, after Yugoslavia and Libya we know that NATO isn’t a “purely defensive” organization, and its member states like USA sometimes form coalitions to go invade other countries, like Iraq or Afghanistan, and occupy them for years just like the Soviets.

You must not know the history of cold war proxy wars very well to ignore all the parallels and the patterns that repeat and repeat.

Isn’t it a bit silly to just say “period, end of story” and just deny it? This is how people solve problems — by looking at similar situations around the world. You don’t fix a refrigerator by refusing to look at every other refrigerator and treating it as a special snowflake. Same here.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#657
post #653

Earlier quoted context omitted.

Ultimately none of these details matter given the elephant in the room: you're voting on some app using your private key, and using some app to check with your private key if the vote has been correctly registered. But you have 0 way of knowing if the system is using this data in the way it was presented. For all the info you have access to, the system can just as well work like this: 1. You cast your vote using the…

Just to be clear - even though I say “Merkle Tree”, I am not saying the unhashed votes themselves would not be stored in it. The hashes are just to quickly verify integrity of the underlying data leaves (the actual votes people cast). The anonymity is done between registration and voting. There is a cryptographic mixer like Tornado Cash that is responsible for the unlinkability, by “tumbling” the tokens to anonymize…

> There is a cryptographic mixer like Tornado Cash that is responsible for the unlinkability, by “tumbling” the tokens to anonymize them while still making sure that each person voting legitimately had registered.

This is not anonymity, it is pseudonimity, if the system then records "person in control of key K voted for X". Sure, it may be impossible to tell who is that person, unless they come out. But that person can prove to anyone they want that they voted for X (assuming the system were trusted, see more on that below), so they can be forced to show someone who they voted for, either through direct coercion or as a condition for receiving money for their vote. In contrast, once you put a paper ballot in the urn, it is impossible for anyone to tell who you voted for.

> So given this description, tell me directly — doesn’t it ADD a lot of security and reduce the attack surface and make elections standardized, cheaper and far more trustworthy - don’t you see the value in that?

No, it only gives a false sense of security, which is worse. Everything you are describing relies on trust in the people that build these systems, trust in the people that invent the algorithms, trust in the people that invent the maths, trust in the chosen parameters of the cryptographic systems, and so on. Literally none of what you are describing works if you don't trust in all of these people to be (a) honest, and (b) really really good at what they're doing.

It's infamously easy to screw up an encryption implementation, even given a well known and accepted algorithm. It's even easier to screw up a market system and end up with perverse incentives which were not apparent when the system was put in place (like the infamous, though possibly apocryphal, cobra farms).

I asked you before as well: would you be happy to issue your vote from a PC that you know is infested with malware the CIA/FSB/etc controls? If not, then you must admit that the cryptographic guarantees are only a small part of the security of the process, and the whole thing, from client to network to server, needs to be perfectly secure or the election can be stolen.

And you are proposing to add this to a paper based ballot system that is (a) dead simple; (b) almost universally used; (c) proven secure enough in many thousands of elections.

I'll also note that, as always, the blockchain part is not adding anything to all of this. You can just as well have the encryption guarantees and an open protocol with government-run servers, WWW style; that would have all the same problems, but at least it wouldn't also require some bizarre proof-of-stake (what would even be the stake here???) or wasteful proof-of-work scheme to depend on for security.

Finally, I'll come back to this point:

> not by hearsay allegations but actual PROOF that anyone can verify

Nothing you are describing can prove anything. It all still relies on your claim that you were trying to vote X, but the system registered you as voting Y. It's your word against the system. You can be convinced yourself, but you can't 100% convince anyone else.

Edit: note, I am the same person as tsimiones, just posting from a different account from my work computer; not trying to make it seem like multiple people are taking my position or anything like that.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#658
post #508

Earlier quoted context omitted.

>watch the entire process. "Entire" is the keyword here. Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. Anyone and everyone can watch someone count paper ballots, noone can watch a computer count electronic ballots.

> Any programmer worth their salt knows that it's practically impossible to vet that what is executing is 1:1 the code that someone at some point in time audited somewhere, or that the code is worthy of trust from the commons in the first place. What? There are entire systems built around doing exactly that. Embedded, military, high-trust. It's never state of the art performance or mass deployed, because most people…

> There are entire systems built around doing exactly that. Embedded, military, high-trust.

This is a completely different thing. In those systems, the organization doing the vetting is the one that protects itself through those systems; the good of the organization is presumed to be aligned with the good of the end-users by the threat model. That is, the threat model is purely external to the organization: we are protecting the army's computers from an enemy army or a rogue soldier. An end-user of such a system (say, a low rank soldier sitting in a tank that includes remote-controlled components) can't really trust that those things are used in their best interest. For all they know, the devices are listening to every conversation looking for signs of treason/incompetence - this is still perfectly allowed by an embedded, military, high-trust system. It's the generals that trust the system, as it were, not the individual soldiers.

In contrast, in an election, what we care about is not that the sitting president trusts the results; we care that every individual voter trusts them. And the individual voters are not the ones that have the power to control the way procurement, hiring, vetting, verification, and everything else is done. In fact, the relationship between the electorate and the voting organizers is normally modeled as partly adversarial. The true test of a democracy is whether the populace can easily vote down the people currently in power, the ones that are organizing the election, when they would like to maintain their power.

So yes, I agree that if I am building a system that I want to trust with voting, and I have enough money, I can build an electronic system that I can trust. And you can build one that you can trust. But I can't build one that you can trust, unless you already trust me.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#659
post #631

Earlier quoted context omitted.

Ironically in the US the current nonsense about election fraud might push electronic ballots further. If you're going to cry wolf over paper ballots then you might as well do whatever you want, literally nothing will ever satisfy them. There's no sense even trying to appease.

"nonsense about election fraud"... the very real election fraud happening all over the place, just as it did last election (in which the legal truths are just being made public)?

Look, I don't know who you are or what has led you to this position, but it's worth I think giving an appeal a chance. You are being tricked and manipulated for someone else's political gain. I know it sucks to hear and every human's response to shut down the thoughts, because admitting to yourself that you've been had is an uncomfortable thought. But I'm asking you to at least entertain the possibility.

We talk a lot on HN about people's beliefs being a reflection of the systems they're placed under— you show me the incentives I'll show you the outcome— and the incentives are clear as day. Democratic voters have two nice properties that are being exploited, Democrats are generally concentrated in major metro areas, and Democrats vote early and by mail. Being concentrated makes those counties easy targets for lawsuits hoping to tie up the process with vague nothingness and rule-lawyering to try and turn away voters. Attacking mail in voting very cleanly affects almost entirely Democrats. And pre-undermining the election results act as a hedge to explain away a loss. Because this is a must-win election for Trump's GOP, two losses in a two risks pushing the "MAGA" faction of the party into irrelevancy.

And so that's what you see, it's a narrative that has been pushed hard designed specifically to carry out the exploit. It's genuinely clever and once it reaches critical mass the people who are tricked into actually believing it outnumber the original concern-trolls so it's naturally self-perpetuating.

So look, I have no expectation that you'll change your stance, I just hope at least that if you really bought into it that going forward you'll at least do it on purpose and be in on the game.

Re: Colorado scrambles to change voting-system passwords after accidental leak

#660

Earlier quoted context omitted.

Almost every democratic country on Earth today does it like that, and all democratic countries have done it like that for the last 100-200 years. Counting paper ballots is just not that hard. Machines are infinitely more complex and exploitable. Plus, you have the extra layer of public perception: it's much easier to convince a chunk of the public that all the machines in some area are miscounting, than it is to conv…

Human counters can be biased, and they're definitely more inaccurate. Machines, unless actively exploited by a third party, will always do the same thing, time after time. I don't believe it's worth the extra expenditure to hire tens of thousands of counters (again, human counters adds manual counting into the process, meaning another place for it to go wrong/be manipulated) when machines do the same thing with no fu…

> Machines, unless actively exploited by a third party, will always do the same thing, time after time.

That "unless" is the whole problem. And it's not just if a third party gets involved, it can well be from the builders or the current operators of the machine who are the ones actively exploiting it as well.

Post reply on HN