TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Berkeley HS student tried to rig his own election, exposing cybersecurity flaws

145 pointsby incompleteabout 6 years ago

18 comments

nkriscabout 6 years ago
The perpetrators should be punished by being made to give a presentation on how they automated the process, what poor security practices allowed them to pull it off, and recommendations for preventing a similar incident in the future.
评论 #19618578 未加载
评论 #19618201 未加载
评论 #19618837 未加载
评论 #19618288 未加载
Someone1234about 6 years ago
&gt; “It just shows that people don’t make healthy cybersecurity decisions,” said Stern.<p>You mean like the administrators of the school? You can set a temp password to immediately expire. What&#x27;s notable is that even after this incident they still didn&#x27;t do so, just encouraged students to change the default password during orientation.
评论 #19618580 未加载
thaumasiotesabout 6 years ago
&gt; Students were casting ranked-choice ballots via a Google Form accessed through district-provided Gmail accounts<p>&gt; The investigators were also able to determine that the false votes were cast from a computer<p>I bet the real votes were cast from a computer too.
评论 #19618172 未加载
评论 #19618569 未加载
mountainofdeathabout 6 years ago
I did something very similar to this for my high school&#x27;s prom queen vote who I wanted to win for teenager reasons. The voting system was just a bunch of laptops in front of the lunch room running a web app and all that was needed to vote was to know a student id. A few hours and some javascript later, I voted more than the entire senior class. It was only discovered after the event.
评论 #19620162 未加载
RandomBaconabout 6 years ago
Ah, computerized highschool class elections.<p>I could have rigged the vote to win at my school too, except that I wasn&#x27;t in the right cliques. It would have been very suspicious if I won, and everyone knew I was &quot;good with computers&quot;.<p>Our program actually saved who voted for who in plaintext. At least I got to see who voted for me.
评论 #19618360 未加载
bowmessageabout 6 years ago
My HS used birthdate as account password, for both students and teachers, with no option to change! I hope they&#x27;ve updated since.
评论 #19617970 未加载
dontbenebbyabout 6 years ago
So default password was student ID? Who wants to bet there was a list of names and student IDs available somewhere that made this trivial to automate?<p>(Or they were sequential with blocks for each class)
评论 #19618536 未加载
jlrubinabout 6 years ago
I&#x27;m glad to see that it seems the student in question was afforded a measure of process and admitted guilt -- I could easily see the story ending where the weaker opponent casts fake votes for their competition to get them eliminated!
ggmabout 6 years ago
The number of responses which go to &quot;...I did this too&quot; are fascinating. I also did stupid things in my past which nowadays would incur severe penalty, as hacking. They felt mild right up to the point I was caught (this is 35 years ago) and then they stopped feeling mild very quickly.<p>I feel very sorry for people in todays world who don&#x27;t get the &quot;everybody gets one free pass&quot; on these things we did back in the day. I think we need a clear statute of limitations on some stuff done by minors and near-minors, regarding their future lives. Nobody is going to be eligible for election to senate or the law courts, or to work in federal or state bodies if we don&#x27;t work out how to deal with this kind of thing.<p>That said, I am pretty sure rigging an election is a good indication you have need of some ethics. Amusing, but also not a good idea.<p>This ranks (in my books) with the recurring &quot;we thought we&#x27;d make a film about a bank robbery without informing the bank or the shopping mall about it&quot; type cock-up: Actions have (unforseen) consequences.
ryanmjacobsabout 6 years ago
Gosh, I did this back in my high school as a Senior, two years ago. Got myself suspended for two days and ruined my perfect attendance, oh well. It scared the shit out of me when two police officers barged into my U.S. History class and pulled me out.<p>The usernames of our voting system were our 5 digit student IDs. And the passwords... same as the usernames. I wrote a puppeteer script that looped through 2000 IDs and voted for everyone. They tracked me down through my home IP address -- if there is a next time, I&#x27;ll definitely use Tor haha.<p>EDIT: Yeah, the school&#x27;s VP picked up on it because normally about 40% of the student body actually votes -- but this time it was 100%; plus when student&#x27;s started signing into their voting accounts, it claimed they already voted. Not my brightest moment.
zarothabout 6 years ago
Besides the fact that this &quot;online voting&quot; was immediately hacked, I wasn&#x27;t fond of the notion that the votes had everyone&#x27;s name attached.
stcredzeroabout 6 years ago
<i>“When we spotted it, it was incredibly obvious,” said Stern, 17. “There were just massive alphabetical votes at random hours.”</i><p>Reminds me of an interview question: How would you do a reasonably good job of randomizing an incoming stream of items, while minimizing auxiliary storage?
评论 #19619024 未加载
dangroverabout 6 years ago
&gt; Schweng said the culture around this election, from the outset, was different than what she’d seen in the past. There were more reports of students taking down candidates’ posters, and more activity on social media. Some students suggested to the principal that the stakes felt higher because colleges are becoming increasingly more selective, and extracurriculars like student government are consequently more important.<p>This part was the most interesting revelation in the article to me! It never would have occurred to me as a HS student to &quot;cheat on extracurriculars&quot;! I just did the stuff that was interesting.
bhsalumni123about 6 years ago
Nowhere in the article is it mentioned where the student gained access to a mapping of student IDs to student first and last names. As a recent BHS alumni, these ID numbers are not obviously derivable from a student&#x27;s name (but I do think they are allocated sequentially). Getting access to this list implies some sort of social engineering or threat vector elsewhere.
OliverJonesabout 6 years ago
Internet voting. What could go wrong?<p>In my opinion these two have done us all a service by showing what could go wrong.
MagicPropmakerabout 6 years ago
He didn&#x27;t expose flaws. They caught him.
评论 #19619895 未加载
anbopabout 6 years ago
LOL. Reminds me of LBJ’s Senate election in 1948.
QuamStiverabout 6 years ago
This kid is going to be fighting off job offers.