TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Cylance Discloses Voting Machine Vulnerability

155 pointsby rsobersover 8 years ago

12 comments

Shankover 8 years ago
I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn&#x27;t pictured is the physical security performed with them.<p>Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the election, and no voter was ever permitted in the back of the access panel where the firmware update would take place.<p>Before the machine starts, it gives a &quot;zero&quot; report which is verified independently by poll watchers, and confirms candidate choices are in place as needed. When the polls are closed, we seal everything again before the machines are sent back for reporting (at which point the seals are checked and verified prior to dumping results).<p>If this was really a damaging hack, the protective counter &amp; live counters would show different numbers than what the machine read, but that didn&#x27;t happen. It very clearly was tampered with, which means these physical measures would counteract any unwanted firmware updates during an election. It&#x27;s preposterous to think that election judges aren&#x27;t actively verifying seals during election day and making sure nobody is tampering with them.
评论 #12883530 未加载
评论 #12883494 未加载
评论 #12883776 未加载
评论 #12883501 未加载
评论 #12883506 未加载
评论 #12884012 未加载
评论 #12893372 未加载
评论 #12883523 未加载
评论 #12886320 未加载
peterarmstrongover 8 years ago
Dear America,<p>This all sounds complicated and insecure.<p>Why can you not just do paper voting with simple ballots, like in Canada?<p>Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable.<p>We run elections and get accurate, verifiable results in the same day.<p>Ours aren&#x27;t as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot can be counted, as many times as needed. And since the thing which is counted is the same physical thing which can be audited, we can always verify the results if anything goes wrong.<p>You&#x27;ve had some problems with your ballots 16 years ago, and we&#x27;re not sure why you haven&#x27;t fixed this by now. After all, you&#x27;ve gotten people to the moon and robots to Mars--surely you&#x27;d want a fair, verifiable presidential election? (Especially when one of the two candidates is, frankly, terrifying to all your friends around the world.)<p>Love, Canada
评论 #12883908 未加载
评论 #12883902 未加载
评论 #12883779 未加载
评论 #12966554 未加载
评论 #12883907 未加载
评论 #12885276 未加载
评论 #12883954 未加载
评论 #12884813 未加载
alexandercrohdeover 8 years ago
I think it&#x27;s high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility.<p>Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I&#x27;d perhaps start at <a href="https:&#x2F;&#x2F;www.verifiedvoting.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.verifiedvoting.org&#x2F;</a>
评论 #12883596 未加载
评论 #12883553 未加载
评论 #12883707 未加载
评论 #12883830 未加载
评论 #12883862 未加载
mpweiherover 8 years ago
I really don&#x27;t see what problem these machines are solving, except for &quot;as an operative, I would like additional vectors to manipulate the election&quot;.<p>In Germany, we get<p>(a) a paper ballot<p>(b) a pen<p>Works perfectly. And quickly.
评论 #12883901 未加载
评论 #12884863 未加载
noir-yorkover 8 years ago
Democracy must not only be done, but also seen to be done. Trust in that most essential of democratic processes - vote counting - must be absolute.<p>Approaching vote counting as a mere technical problem that can be solved with enough technical safeguards misses the point. You cannot just ask a democracy to beta test vote counting and fix the bugs post-election - that will kill trust in the process.<p>Politics is polarised enough as is and you will find demagogues who will latch on to anything to reduce the legitimacy of an election.<p>It shouldn&#x27;t even be up for discussion that trust and legitimacy are the most important goals in vote counting. Stick to paper voting and only introduce e-voting in parallel and not as the authoritative and final vote counting solution.
sfifsover 8 years ago
I wonder why countries don&#x27;t use India&#x27;s simple and scalable electronic voting systems. The latest ones have voter verified paper audit trails. They even have pooling systems to prevent counts from any single voting booth become known to prevent voter intimidation.<p><a href="https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Electronic_voting_in_India" rel="nofollow">https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Electronic_voting_in_India</a>
评论 #12884178 未加载
jakeoghover 8 years ago
Why Electronic Voting is a BAD Idea - Computerphile: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=w3_0x6oaDmI" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=w3_0x6oaDmI</a>
godelskiover 8 years ago
Really what it seems is that we need more audits on machines. If democracy is to be a pivotal part of our election process we need to release the source code of these machines to ensure that we find and solve problems.
评论 #12883542 未加载
seanwilsonover 8 years ago
Is there any way you can prevent hacks like this that require physical access? I guess cryptographically signing the updates, adding tamper proof seals and requiring multiple people to approve updates would help. The general mantra however is that once a hacker has physical access to your machine all bets are off.<p>Also, what happens if there&#x27;s a random hardware&#x2F;software glitch where incrementing one vote actually increments 10 votes? Is this checked for? How much reliance is there on the software and hardware being error free?
评论 #12883540 未加载
imodeover 8 years ago
lovely! more paranoia about the upcoming competition for a single political position.<p>as if I needed more of a reason to say &quot;wow, this is rigged&quot;, now I see this!<p>I can&#x27;t imagine how well this will go. november is a cake walk. january is where the fun starts.
based2over 8 years ago
<a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2006&#x2F;11&#x2F;voting_technolo.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2006&#x2F;11&#x2F;voting_techno...</a>
top_postover 8 years ago
&quot;The decision to announce the research findings was intended to encourage increased sales and revenue for Q4 2016.&quot;
评论 #12883663 未加载