Live data from Hacker News

Cylance Discloses Voting Machine Vulnerability

blog.cylance.com

71–80 of 127 posts

Re: Cylance Discloses Voting Machine Vulnerability

#71

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

Why can you not just do paper voting with simple ballots, like in Canada? As much as I like Canada's easily audited voting system, there's a good reason for the US to not use a simple way of counting votes: They don't have simple ballots . Rather than just voting for one MP, as we do, a typical American might be asked to vote for a President, a Senator, a Representative, yes/no on 17 state propositions, a State Senat…

How do you even come up with these weird convoluted non-arguments, we have many choices on a single ballot here too. It's called a list. You can put lists on paper.

Re: Cylance Discloses Voting Machine Vulnerability

#72
post #2

I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn't pictured is the physical security performed with them. Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the e…

What happens if they find tampering of the seals? Does all the votes of that particular machine become questionable? If someone were to tamper with the seals on many of the machines, and they target precincts that tilt heavily in favor of one party or the other, couldn't they theoretically invalidate a lot of ballots that are likely to help their opponents?

[deleted]

Re: Cylance Discloses Voting Machine Vulnerability

#73
post #58

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

The largest democracy India has e-voting. Works fine for them. Why are other countries not going the same way. There is a move in India to get all voting machines to print out your choice which the voter can drop into a ballot box. Not sure if that is implemented yet. Surely something like that will work fine.

>There is a move in India to get all voting machines to print out your choice which the voter can drop into a ballot box

Sounds like an expensive printer

Re: Cylance Discloses Voting Machine Vulnerability

#74

Earlier quoted context omitted.

It's much harder to undetectably destroy or alter large numbers of paper records than it is to do the same to digital records. It's also sometimes possible to do this to digital records without ever being physically present in their vicinity. Once again, this is much harder with paper.

It's very easy to forge paper records, though. I seem to recall reading about a rigged election in a questionable democracy where the ballot counters were given several file boxes full of fake ballots in addition to their local precinct ballots, with official anti-tampering seals intact.

So now you need a distribution network for fake boxes and people in the precincts that are in on the conspiracy. Such a large org is leak-prone.

Contrast that with a group of just 1-3 techies.

Re: Cylance Discloses Voting Machine Vulnerability

#75

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

Exactly, more people counting is not a problem. It's actually a good thing. Why not get more people involved in the electoral process? It's beyond me why anyone would want to undermine this. Plus, I don't get the mail in states. What's up with that? Why mess with a process that works?

I live in a mail-in state (WA) and in my opinion it's a pretty great system. I got my ballot almost two weeks ago and just sent it in last week. I was able to fill it out when I had free time and drop it in a ballot box (there's one about 5 minutes from where I live by foot, and I could always just mail it in if I wanted to). Lining up to vote at the polls would've been a lot more time-consuming because I would have to line up and I would've had to write down all my votes anyway, then move them onto an official ballot.

Re: Cylance Discloses Voting Machine Vulnerability

#76
post #40
post #2

I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn't pictured is the physical security performed with them. Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the e…

You mean I could void all the votes simply by tampering with the seal? Seams like an easy attack

The answer to many physical security questions is "it depends." I don't have my materials on me anymore, but in general, seal tampering means a lot of extra scrutiny on the people watching the machines and transporting them. The chain of custody will pin the blame on the last person who signed off, and things get investigated as needed.

The system doesn't have something in place typically that says "if (sealVoided) { throw out election }" it just means that additional precautions are taken to ensure everything is good. It's never a binary answer, unfortunately.

Re: Cylance Discloses Voting Machine Vulnerability

#77

I think it's high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility. Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I'd perhaps start at https://www.verifiedvoting.org/

They don't even need to throw the election. Two or three machines with absurd results in favor of Clinton or Trump would be enough to push the county into civil unrest.

Not saying there is any evidence this has happened or will happen, but:

If I were Russia, I would arrange something so one or two polling stations end up casting many fraudulent votes for Clinton, just to call the entire election into question and give more ammo to the Trump campaign. Even if those instances had no serious impact on the results, the uncertainty alone could definitely cause significant civil turmoil.

Re: Cylance Discloses Voting Machine Vulnerability

#78

Earlier quoted context omitted.

By hand.

Same in the UK. Anyone who can vote can also take part in "The Count", where groups of volunteers count the votes in regional centres.

Wouldn't that be easy to spoof numbers? Getting a few hundred people to add 10 or 15 to a candidate in a swing state could make a huge difference.

Re: Cylance Discloses Voting Machine Vulnerability

#79

Earlier quoted context omitted.

Same in the UK. Anyone who can vote can also take part in "The Count", where groups of volunteers count the votes in regional centres.

Wouldn't that be easy to spoof numbers? Getting a few hundred people to add 10 or 15 to a candidate in a swing state could make a huge difference.

Getting a few hundred people to do anything without it leaking is hard. Plus, the paper records are retained, so a recount could specifically identify the culprits.

Re: Cylance Discloses Voting Machine Vulnerability

#80
post #52

Earlier quoted context omitted.

> that's a risk you have to take Well, obviously. But the risk can be high or low, right? You could either let any random voter you don't know walk in and become a volunteer after filling out a form, or you could let maybe ~50 people that the party's head/nominee personally trust pick a set of volunteers nationally based on e.g. personal knowledge or some concrete evidences of their past contributions and allegiance…

let's take this a step further: two republicans, one falsely registered as a democrat, have been paired off at the polling station in Araphaoe County. the lie was bought, the fraud complete. now what?

The "real" Republican sees his "Democrat" counterpart attempt to tamper with the machine and saying "trust me, I'm doing it for the Republicans". They yell for assistance.
Post reply on HN