TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Experts Analyze the App That Broke Iowa

11 点作者 sutro超过 5 年前

2 条评论

jiveturkey超过 5 年前
&quot;Honestly, the biggest thing is—I don’t want to throw it under the bus—but the app was clearly done by someone following a tutorial.&quot;<p>HAR!
joveian超过 5 年前
So it sounds like for people able to use the app (maybe limited in part due to the use of TestFairy free tier (from a different vice article)), the app correctly got data into Google Cloud Functions, but a script used to transfer the data from there to the Iowa Democratic Party (not sure what they were using) didn&#x27;t work correctly (due to a &quot;data formatting error&quot;). Some people were confused by the three six digit numbers needed, a precinct id, PIN, and two-factor code (auth0, according to the other vice article with screenshots).<p>ProPublica also found there was a MITM vulnerability:<p><a href="https:&#x2F;&#x2F;www.propublica.org&#x2F;article&#x2F;the-iowa-caucuses-app-had-another-problem-it-could-have-been-hacked" rel="nofollow">https:&#x2F;&#x2F;www.propublica.org&#x2F;article&#x2F;the-iowa-caucuses-app-had...</a><p>However, even if the app didn&#x27;t mess up numbers there seem to be a bunch of issues with the numbers:<p><a href="https:&#x2F;&#x2F;www.nytimes.com&#x2F;2020&#x2F;02&#x2F;06&#x2F;upshot&#x2F;iowa-caucuses-errors-results.html" rel="nofollow">https:&#x2F;&#x2F;www.nytimes.com&#x2F;2020&#x2F;02&#x2F;06&#x2F;upshot&#x2F;iowa-caucuses-erro...</a>