Live data from Hacker News

DEF CON report on vulnerabilities in US election infrastructure [pdf]

defcon.org

91–100 of 145 posts

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#91
post #3

The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important to derive facts through reason and inquiry rather than blind faith. 2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information. We did not make these principles up ours…

Ok. So, those are powerful findings of fact. From this, what has been done thus far regarding: State election boards State House/Senate committees on elections Local election judges and boards Federal House/Senate committees on elections I would assume that these allegations must be verified. However, since all the procedures and observations are being made in the open, they should be relatively easy to confirm. But,…

They intentionally made the machines hackable because they intend to cheat. It’s really that simple.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#92

Earlier quoted context omitted.

When you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.

This is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues. 1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon

Sure, but you lose vote secrecy.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#93
post #62
post #10

There are a lot of words in this document. What we need is some infographics that boil it down into something people without the time to read and parse all of those findings can understand easily. A map showing vulnerable states, some pictures showing how easy it is to circumvent a particular system. Something that shows what percentage of machines are vulnerable and an easy way to know if the machines in my district…

You should bring this to the attention of USAFActs. Even if you're not a Ballmer fan, they do have the necessary resources for this sort of work and it seems like it would align with their mission. https://usafacts.org/ Maybe we could start tweeting them? https://twitter.com/usafacts/

Good idea. I tweeted at them.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#94

This is terrifying. Full stop.

Every electronic device is hackable with physical access. Every process that has humans involved is exploitable. I'm more alarmed at the number of people willing to complain and moan about change, yet refuse to volunteer at their local polling station. If awareness is important, we have to start somewhere, yet the vast majority of people complaining expect it to just solve itself. Sometimes to fix a broken system you…

> Every electronic device is hackable with physical access. Every process that has humans involved is exploitable.

This is a useless statement. Security is a continuum, and it's perfectly valid to point out voting machines suck on that continuum.

I store my private key on a yubikey, and sure if you had physical access and spent about $300k you could decap it and recover the private key (with a success rate of maybe 10%, an expensive hardware lab, and expertise only a handful of people have).

That's a whole different ballpark from voting machines which don't use a hardware TPM [0] to attest votes, but instead store them in csvs while running windows CE such that an attacker with a jumpdrive can plug it in and alter records using exploits which have been public for years and years.

> Sometimes to fix a broken system you have to become a part of it and change from the inside.

Unfortunately, various people have tried to change it with no success. The voting machine companies have contracts with the government that preclude new entrants to the business.

Security researchers who contact voting machine companies have no impact.

Technology such as TPMs exist, but the voting machine vendors have little apparent interest in these new ideas and technologies.

I don't think it's fair to discount other commentors from providing information and discussing their views just because they're unwilling to go into politics to attempt to fix this silly government contracts (with a low chance of succeeding)

[0]: https://en.wikipedia.org/wiki/Trusted_Platform_Module

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#95
post #88

Earlier quoted context omitted.

The surprising part of most of these vulnerabilities is they are hardware attacks. I had a talk with someone the other day that said she heard people were hacking votes from iPhones. The over simplification of the topic is doing just as much harm as good. I don't know any security professional that would tell you physical access isn't equal to the ability to hack a device. The reality is subversion of people managing…

The first new attack described in last year's report was that you could DoS a machine by removing its CPU. Which, sure, is something to think about. But it's not what I think people are imagining when you say "voting machine hacking."

Right!! It's like saying you could DoS a car by removing it's spark plugs.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#96
post #94

Earlier quoted context omitted.

Every electronic device is hackable with physical access. Every process that has humans involved is exploitable. I'm more alarmed at the number of people willing to complain and moan about change, yet refuse to volunteer at their local polling station. If awareness is important, we have to start somewhere, yet the vast majority of people complaining expect it to just solve itself. Sometimes to fix a broken system you…

> Every electronic device is hackable with physical access. Every process that has humans involved is exploitable. This is a useless statement. Security is a continuum, and it's perfectly valid to point out voting machines suck on that continuum. I store my private key on a yubikey, and sure if you had physical access and spent about $300k you could decap it and recover the private key (with a success rate of maybe 1…

"That's a whole different ballpark from voting machines which don't use a hardware TPM [0] to attest votes, but instead store them in csvs while running windows CE such that an attacker with a jumpdrive can plug it in and alter records."

you're not getting any of these access with out modifying hardware at the poling station. If poll monitoring is being performed, they're going to notice someone taking apart a voting machine.

I was at the Voter Village, Two years in a row I spent time disassembling the machines. They're not as easy as you're making it out.

Being a part of monitoring of these systems is not something stopped by big business. That's a cop out.

TPM should be a part of medical devices, but it's not. I would argue that's even more important than a voting machine. Unless you work for a manufacturer or are building a voting machine with these systems, sitting around and saying you could do X or Y doesn't solve a damn thing.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#97

From the "Next Steps" section in the report: >Congress Must Fund Election Security:​ National defense is not the role of state and local government. Further, no state or local government will ever be able to raise enough capital to defend itself from a determined nation state. Thus, having codified the basic security standards developed by local election officials above, Congress must finance the implementation of th…

I was just going to post that. I'm concerned that since election security is not (just) a technological problem, that very little will be done to improve it in the foreseeable future. I'm from Idaho which is currently conservative by close to a 2/3 majority, but remember growing up that we had many liberal elected officials like Cecil Andrus and Frank Church. From my perspective, democrats are working to improve elec…

> From my perspective, democrats are working to improve election security while republicans are not.

Does voter ID improve election security?

Which party opposes voter ID laws?

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#98
post #8

Earlier quoted context omitted.

And IMO they should do away with "optical ballot scanning", and should move to regular humans counting them with their own eyes. An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. Instead, have everyone mark their ballots like normal, then get a bunch of people in a room who all don't trust one another and have them count/tally votes together. Just about every…

>An electronic scanning system could easily be vulnerable to many of the same issues that are presented here. While in school in the 80's I learned that the standardized tests the school were administering didn't mean anything. They had no barring on my ability to graduate or go to college so I stopped caring about them. This opened up the freedom to do things like fill out multiple bubbles per line and otherwise get…

Sounds like an awful school administration handling their poorly built systems issues with the least grace possible.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#99

From the "Next Steps" section in the report: >Congress Must Fund Election Security:​ National defense is not the role of state and local government. Further, no state or local government will ever be able to raise enough capital to defend itself from a determined nation state. Thus, having codified the basic security standards developed by local election officials above, Congress must finance the implementation of th…

Elections are not national defense.

State and local governments have been handling their own elections since before the country was founded. This is a good thing, because it keeps elections close to the people, accountable to the people.

The last thing we need is nationalized elections. That would make all of our elections vulnerable together. And that includes federal funding for state and local elections, because federal funding always comes with extensive rules and regulations, which would effectively put elections under federal control.

We need to move more government and accountability closer to the people, not to Washington, D.C.

Re: DEF CON report on vulnerabilities in US election infrastructure [pdf]

#100

Earlier quoted context omitted.

I was just going to post that. I'm concerned that since election security is not (just) a technological problem, that very little will be done to improve it in the foreseeable future. I'm from Idaho which is currently conservative by close to a 2/3 majority, but remember growing up that we had many liberal elected officials like Cecil Andrus and Frank Church. From my perspective, democrats are working to improve elec…

> From my perspective, democrats are working to improve election security while republicans are not. Does voter ID improve election security? Which party opposes voter ID laws?

>Does voter ID improve election security?

It does not.

Post reply on HN