Live data from Hacker News

Cylance Discloses Voting Machine Vulnerability

blog.cylance.com

91–100 of 127 posts

Re: Cylance Discloses Voting Machine Vulnerability

#91
post #28
post #22

Earlier quoted context omitted.

I have no experience with non-DRE seal checking. Our seals had the machine serial numbers on them, with watermarks, etc. If a seal was mysteriously broken, it was in our best interest to take it out of service anyway, because suddenly the legitimate votes on that machine come into question.

In Alameda County, CA we use what look superficially to be the same machines, and have similar physical security measures - there are seals on all access points (e.g. on the cover protecting the power switch), and whenever we access one of them we save the seal's tag, log its ID, and log the ID of the replacement. At the end of the day you end up with basically a series of tags on a form that show chain of custody (t…

So someone could spoil all the votes by breaking the seals?

Re: Cylance Discloses Voting Machine Vulnerability

#92
post #5
post #2

I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn't pictured is the physical security performed with them. Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the e…

Exactly. You could tamper with most systems if you had that much physical access, including paper counts. Which is why there are procedures in place to minimize that potential. Plus an attack like this would be isolated to the single machine (not that it wouldn't be bad, but it wouldn't be applied in a distributed fashion).

With paper counts, it's easy to verify that the box is empty when it's initially sealed. With voting machines not so much.

Re: Cylance Discloses Voting Machine Vulnerability

#93
post #29

Earlier quoted context omitted.

Ugh.

not sure are aware, but the actual quote is "The decision to announce the research findings was intended to encourage remediation of the vulnerabilities prior to Election Day".

3 days before the election.... sure it was...

Re: Cylance Discloses Voting Machine Vulnerability

#94
post #58

Earlier quoted context omitted.

The largest democracy India has e-voting. Works fine for them. Why are other countries not going the same way. There is a move in India to get all voting machines to print out your choice which the voter can drop into a ballot box. Not sure if that is implemented yet. Surely something like that will work fine.

>There is a move in India to get all voting machines to print out your choice which the voter can drop into a ballot box Sounds like an expensive printer

I doubt it's going to be an inkjet, the "printer" could be simplified to punching holes on the ballot, which should be cheap.

Re: Cylance Discloses Voting Machine Vulnerability

#95
post #6

Earlier quoted context omitted.

At least in Arapahoe County, everything we did was in pairs of republicans and democrats, to ensure that it was a fair election as far as we could. This included seal checking, logging the zero counts, etc. Everything had a paper audit trail for who interacted with what, who signed off on what, and what was going on. I don't know how it worked when the machines were picked up for counting, but I assume similar measur…

Did third parties get representation?

Not sure about elsewhere, but in Canada, any candidate on the ballot is usually allowed to appoint up to two agents or scrutineers per ballot box, usually to spell each other off (it can be a very long day)

Re: Cylance Discloses Voting Machine Vulnerability

#96

Earlier quoted context omitted.

Same in the UK. Anyone who can vote can also take part in "The Count", where groups of volunteers count the votes in regional centres.

Wouldn't that be easy to spoof numbers? Getting a few hundred people to add 10 or 15 to a candidate in a swing state could make a huge difference.

It's not easy, candidates have the right to appoint agents to verify the voting process, the ballot counts, the correctness of the markings and to certify the count and confirm the ballots are properly sealed in case of a judicial recount.

Re: Cylance Discloses Voting Machine Vulnerability

#97

Earlier quoted context omitted.

How do you even come up with these weird convoluted non-arguments, we have many choices on a single ballot here too. It's called a list. You can put lists on paper.

In Canadian federal elections, the vote counting process is: 1. Open the box. 2. Dump the ballots onto the table. 3. Make sure the box is empty. 4. Pick up ballots one by one, say "this looks like a vote for "Mr. X", and place into the appropriate pile. 5. Count how many ballots are in each pile. This particular process doesn't work if you have multiple choices on one ballot. I'm not saying that you can't use paper b…

Where I live, the ballots we use are cut into one piece per question. Then the pieces are counted separately.

There was a court argument over the use of scales by some municipalities. The scales are used to weigh piles of votes to determine vote count. So ballots with multiple question are cut, sorted, then weighed. I'm looking into lead pens to give my vote more weight :-)

Re: Cylance Discloses Voting Machine Vulnerability

#98
post #91
post #28

Earlier quoted context omitted.

In Alameda County, CA we use what look superficially to be the same machines, and have similar physical security measures - there are seals on all access points (e.g. on the cover protecting the power switch), and whenever we access one of them we save the seal's tag, log its ID, and log the ID of the replacement. At the end of the day you end up with basically a series of tags on a form that show chain of custody (t…

So someone could spoil all the votes by breaking the seals?

You would have to assume so...

Re: Cylance Discloses Voting Machine Vulnerability

#99
post #91
post #28

Earlier quoted context omitted.

In Alameda County, CA we use what look superficially to be the same machines, and have similar physical security measures - there are seals on all access points (e.g. on the cover protecting the power switch), and whenever we access one of them we save the seal's tag, log its ID, and log the ID of the replacement. At the end of the day you end up with basically a series of tags on a form that show chain of custody (t…

So someone could spoil all the votes by breaking the seals?

Sure. And they could also spoil all the votes with an armed robbery - at many polling stations, there's no actual police presence until/unless someone calls them in.

The main intent of all the security measures is that any such tampering be obvious, and that it be clear whose votes (or at least, which precincts' votes) were compromised.

Re: Cylance Discloses Voting Machine Vulnerability

#100

Dear America, This all sounds complicated and insecure. Why can you not just do paper voting with simple ballots, like in Canada? Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable. We run elections and get accurate, verifiable results in the same day. Ours aren't as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot…

But how are we going to disrupt voting?
Post reply on HN