TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Cylance Discloses Voting Machine Vulnerability

155 点作者 rsobers超过 8 年前

12 条评论

Shank超过 8 年前
I worked as an election judge in the 2012 general election in Arapahoe County, Colorado. We had these exact machines. What isn&#x27;t pictured is the physical security performed with them.<p>Typically, tamper seals that are identifiable as broken are placed on all access doors (including the power switch, data load slots, etc), access panels, and openings on the device. All seals were verified in tact before and after the election, and no voter was ever permitted in the back of the access panel where the firmware update would take place.<p>Before the machine starts, it gives a &quot;zero&quot; report which is verified independently by poll watchers, and confirms candidate choices are in place as needed. When the polls are closed, we seal everything again before the machines are sent back for reporting (at which point the seals are checked and verified prior to dumping results).<p>If this was really a damaging hack, the protective counter &amp; live counters would show different numbers than what the machine read, but that didn&#x27;t happen. It very clearly was tampered with, which means these physical measures would counteract any unwanted firmware updates during an election. It&#x27;s preposterous to think that election judges aren&#x27;t actively verifying seals during election day and making sure nobody is tampering with them.
评论 #12883530 未加载
评论 #12883494 未加载
评论 #12883776 未加载
评论 #12883501 未加载
评论 #12883506 未加载
评论 #12884012 未加载
评论 #12893372 未加载
评论 #12883523 未加载
评论 #12886320 未加载
peterarmstrong超过 8 年前
Dear America,<p>This all sounds complicated and insecure.<p>Why can you not just do paper voting with simple ballots, like in Canada?<p>Yes, you have 10x the people, but just get 10x the human counters and scrutineers. Counting is parallelizable.<p>We run elections and get accurate, verifiable results in the same day.<p>Ours aren&#x27;t as nasty as yours are, and we still have better anti-fraud than you do, since every paper ballot can be counted, as many times as needed. And since the thing which is counted is the same physical thing which can be audited, we can always verify the results if anything goes wrong.<p>You&#x27;ve had some problems with your ballots 16 years ago, and we&#x27;re not sure why you haven&#x27;t fixed this by now. After all, you&#x27;ve gotten people to the moon and robots to Mars--surely you&#x27;d want a fair, verifiable presidential election? (Especially when one of the two candidates is, frankly, terrifying to all your friends around the world.)<p>Love, Canada
评论 #12883908 未加载
评论 #12883902 未加载
评论 #12883779 未加载
评论 #12966554 未加载
评论 #12883907 未加载
评论 #12885276 未加载
评论 #12883954 未加载
评论 #12884813 未加载
alexandercrohde超过 8 年前
I think it&#x27;s high time we start taking these concerns seriously. If state actors can accomplish stuxnet, then hacking a voting system seems well within the realm of technical possibility.<p>Fortunately, there are pretty simple policies we can enact to prevent fraud and give faith in elections (both in America, as well as other countries). If you care, I&#x27;d perhaps start at <a href="https:&#x2F;&#x2F;www.verifiedvoting.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.verifiedvoting.org&#x2F;</a>
评论 #12883596 未加载
评论 #12883553 未加载
评论 #12883707 未加载
评论 #12883830 未加载
评论 #12883862 未加载
mpweiher超过 8 年前
I really don&#x27;t see what problem these machines are solving, except for &quot;as an operative, I would like additional vectors to manipulate the election&quot;.<p>In Germany, we get<p>(a) a paper ballot<p>(b) a pen<p>Works perfectly. And quickly.
评论 #12883901 未加载
评论 #12884863 未加载
noir-york超过 8 年前
Democracy must not only be done, but also seen to be done. Trust in that most essential of democratic processes - vote counting - must be absolute.<p>Approaching vote counting as a mere technical problem that can be solved with enough technical safeguards misses the point. You cannot just ask a democracy to beta test vote counting and fix the bugs post-election - that will kill trust in the process.<p>Politics is polarised enough as is and you will find demagogues who will latch on to anything to reduce the legitimacy of an election.<p>It shouldn&#x27;t even be up for discussion that trust and legitimacy are the most important goals in vote counting. Stick to paper voting and only introduce e-voting in parallel and not as the authoritative and final vote counting solution.
sfifs超过 8 年前
I wonder why countries don&#x27;t use India&#x27;s simple and scalable electronic voting systems. The latest ones have voter verified paper audit trails. They even have pooling systems to prevent counts from any single voting booth become known to prevent voter intimidation.<p><a href="https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Electronic_voting_in_India" rel="nofollow">https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Electronic_voting_in_India</a>
评论 #12884178 未加载
jakeogh超过 8 年前
Why Electronic Voting is a BAD Idea - Computerphile: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=w3_0x6oaDmI" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=w3_0x6oaDmI</a>
godelski超过 8 年前
Really what it seems is that we need more audits on machines. If democracy is to be a pivotal part of our election process we need to release the source code of these machines to ensure that we find and solve problems.
评论 #12883542 未加载
seanwilson超过 8 年前
Is there any way you can prevent hacks like this that require physical access? I guess cryptographically signing the updates, adding tamper proof seals and requiring multiple people to approve updates would help. The general mantra however is that once a hacker has physical access to your machine all bets are off.<p>Also, what happens if there&#x27;s a random hardware&#x2F;software glitch where incrementing one vote actually increments 10 votes? Is this checked for? How much reliance is there on the software and hardware being error free?
评论 #12883540 未加载
imode超过 8 年前
lovely! more paranoia about the upcoming competition for a single political position.<p>as if I needed more of a reason to say &quot;wow, this is rigged&quot;, now I see this!<p>I can&#x27;t imagine how well this will go. november is a cake walk. january is where the fun starts.
based2超过 8 年前
<a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2006&#x2F;11&#x2F;voting_technolo.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2006&#x2F;11&#x2F;voting_techno...</a>
top_post超过 8 年前
&quot;The decision to announce the research findings was intended to encourage increased sales and revenue for Q4 2016.&quot;
评论 #12883663 未加载