[HN Gopher] Colorado scrambles to change voting-system passwords...
       ___________________________________________________________________
        
       Colorado scrambles to change voting-system passwords after
       accidental leak
        
       Author : rbanffy
       Score  : 75 points
       Date   : 2024-10-31 22:42 UTC (2 days ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | grugagag wrote:
       | Is voting fraud at stake here or leak info over who voted? Is it
       | possible to infer who voted what from the leak?
        
         | wbl wrote:
         | No, because of the way CO runs elections. But it is possible to
         | gin up fraud claims and then resort to violence if the
         | candidate who did this before loses again.
        
           | skeeter2020 wrote:
           | That just seems so unlikely. What sort of out-of-touch ego
           | monster, bigger than Jesus, flaming asshole would do this?
        
         | hammock wrote:
         | If you broaden fraud to include interference, suppression, etc
         | yes absolutely
        
       | cushpush wrote:
       | Uh oh. Ignorance of computing showing. IF they need two passwords
       | to combine to make one, but sometimes have one of them, they just
       | need to brute the other open... I think it's a bigger problem
       | than the administration understands, unless the passwords are for
       | something inert like wattage delivered to the machine.
        
         | leereeves wrote:
         | Can you brute force a BIOS password without prolonged physical
         | access?
         | 
         | The leak does increase the risk of a single trusted insider
         | messing with the system, though.
        
       | laxmin wrote:
       | The Indian Voting Machines are the answer. No operating system,
       | no passwords, no connections, no bruteforcing anything, system on
       | a chip, so widely distributed devices that hacking even a few of
       | them is challenging, etc.
       | 
       | The US voting machines are just waiting to be hacked, just a
       | matter of when, not if.
        
         | db1234 wrote:
         | Regarding Indian voting machines, there is also randomization
         | involved at various levels during distribution making it
         | difficult to game the system but still I always wonder if there
         | is any way to hack the system. I hope people in charge have a
         | process to continuously evaluate the security procedures and
         | improve it.
        
           | recursivecaveat wrote:
           | I never understood the desire to have any kind of machine at
           | all. Paper ballots are a perfectly efficient and scalable
           | system used for many large elections. Even if complicated
           | machines are theoretically safe against malfeasance, keeping
           | it simple increases public confidence.
        
             | samarthr1 wrote:
             | Scale is a bit of an issue.
             | 
             | We need results in as short a time as possible, ws have
             | about 100 crore registered voters, of whom about 70% on
             | average vote, meaning that the ECI must process 70 Crore
             | votes, in under 10 hours.
             | 
             | Making that happen in a free and fair way is a logistical
             | challenge, one that we undertake every 5 years.
             | 
             | One more large advantage of EVMs is making booth capture
             | very expensive (because EVMs have a inbuilt rate limit, but
             | a ballot box does not).
             | 
             | At any rate, with VVPAT being there, it adds another layer
             | of security.
        
             | cafard wrote:
             | I should say, the speed of tabulation. An American election
             | can include ballot lines for president, senator, member of
             | congress, state senator, three state representatives, a
             | county councilmember or two, a member of the board of
             | education etc.
        
               | Am4TIfIsER0ppos wrote:
               | More bits of paper. The ballot papers around here are
               | bloated oversize monstrosities (picture A3 sized) due to
               | the number of parties and candidates but you get a
               | separate one for each election. Unfortunately not every
               | area is paper only.
        
               | Ekaros wrote:
               | Here we don't even put names on the ballot, instead there
               | is number assigned for each, this scales up to hundreds
               | of candidates. This does prevent write ins, but I see no
               | reason why you could not have own ballot for each purpose
               | and then say colour code them and append letter or two in
               | front of each candidate for each election.
        
               | anon291 wrote:
               | If the speed of tabulation is the main reason then why
               | are results no longer known by election night? They're
               | saying it might be days again. When we had paper ballots,
               | we knew that night. (For America)
        
               | gruez wrote:
               | >When we had paper ballots, we knew that night. (For
               | America)
               | 
               | You forgot about 2000. Also, the main reason for the
               | delays are mail-in ballots, which could be delayed for
               | days/weeks, depending on how lenient the deadlines are.
        
             | unethical_ban wrote:
             | Scalable? Not for same-day. I'd be fine waiting a few days
             | if needed, though. Heck, early voting means I wait for
             | weeks now.
             | 
             | Ranked choice voting is essentially doing multiple
             | elections at a time, having to recount portions of votes
             | every time a candidate drops out. That's a lot easier with
             | computers.
             | 
             | I think the totals from every precinct could be made public
             | in a way that they are verifiable from a central database,
             | where the numbers add up to the total for the state and
             | eventually federal count.
             | 
             | This is probably already happening, but people don't seem
             | to think so.
        
               | bpye wrote:
               | The UK manages to produce results within a few hours and
               | all ballots, at least for general elections, are hand
               | counted.
               | 
               | I agree that for voting systems other than FPTP it is
               | more work and may take longer - but it's not an
               | intractable problem.
        
               | wreckdropibex wrote:
               | Same-day? It is not a problem at all. For example Finland
               | calculates enough paper ballots in hours to give a
               | definitive result, I am sure there are other countries
               | that manage it as well. Your imagination is stuck in the
               | world of voting practices of your side of the pond.
        
             | jfengel wrote:
             | Tell me you're under 24 years old without telling me you're
             | under 24 years old.
             | 
             | The US 2000 election was a fiasco of the failures of paper
             | ballots. Officials spent weeks scrutinizing ballots and to
             | this day nobody thinks they got it correct to within the
             | margin of error.
             | 
             | That's when electronic machines came in. They are not
             | necessarily better, but nobody who lived through that
             | nightmare thinks fondly of the clarity of paper ballots.
        
         | albert_e wrote:
         | Curious to know more. Is there a good source of information on
         | the security of the hardware and software used for elections
         | India.
         | 
         | As an Indian citizen I see the casual lack of security mindset
         | in large swathe of things implemented by both public and
         | private actors. Many things get better only though iterative
         | failures and corresponding reactive fixes.
         | 
         | What type of failures and improvements have happened here, or
         | instances of demonstrated hardness against those with
         | motivation and access to machinery.
        
           | samarthr1 wrote:
           | IIRC it uses tamper evident hardware.
           | 
           | There was an interview with one of the Profs who designed the
           | EVMs here.
        
         | brandonmenc wrote:
         | > The US voting machines are just waiting to be hacked
         | 
         | Feature, not a bug?
        
         | Molitor5901 wrote:
         | I think random, serialized paper ballots are the way to go.
         | When the polls close you know the serial numbers of every vote
         | cast, so no new serial numbers should be added to that unless a
         | very good reason. Keep them or destroy them afterwards is
         | another issue, but it's a step in the right direction.
         | 
         | I have some distrust in the American voting system, first with
         | the computerized systems, but also that federal elections are
         | run at the state level. With so many states and jurisdictions,
         | I can't help but feel that fraud is happening. If the federal
         | elections process was truly federalized, and funded if it is
         | not already, managed and controlled by the federal government,
         | then I think there could be greater control and security.
        
           | zie wrote:
           | Go be a poll worker in your local election. See if you change
           | your mind.
        
           | saxonww wrote:
           | What do you do when duplicate serial numbers start showing
           | up? I'm assuming you won't know who was issued which serial
           | number, and if it's truly randomized you wouldn't even know
           | where they were sent.
        
           | ForHackernews wrote:
           | https://www.cpr.org/2024/10/08/vg-2024-how-your-vote-gets-
           | co...
           | 
           | Colorado ballot envelopes already have a bar code -
           | essentially your "serial number".
           | 
           | I feel like I'm taking crazy pills because everyone who
           | thinks there's widespread election fraud seems to not know
           | anything about how elections work.
        
         | readthenotes1 wrote:
         | It's a matter of when, if, and, if we will ever know
        
         | endgame wrote:
         | Just use paper, and count by hand on the day.
         | 
         | You need to present an election system that will convince Joe
         | Q. Public, who is almost certainly not as tech-literate as this
         | forum, is probably not even white-collar or university
         | educated, and likely also suspicious of globalisation. "Tamper-
         | proof Indian system-on-a-chip" does not have that property.
         | Otherwise you get increasingly unhinged arguments over the
         | election results until something breaks.
        
           | CaliforniaKarl wrote:
           | Unfortunately, hand-counting causes more errors than
           | electronic counting, except in very small communities.
           | 
           | Ref.: https://www.brennancenter.org/our-work/research-
           | reports/hand...
        
         | kkielhofner wrote:
         | > The US voting machines are just waiting to be hacked, just a
         | matter of when, not if.
         | 
         | The US election system is very distributed and fragmented -
         | there is virtually no standardization.
         | 
         | Even in the tightest margins for something like President you'd
         | need to have seriously good data to figure out which random
         | municipality voting system(s) you'd need to target to actually
         | affect the outcome.
        
           | ForHackernews wrote:
           | Ironically America's fragmentary and incoherent electoral
           | system makes it extremely hard to steal an election there.
        
             | CaliforniaKarl wrote:
             | You say "fragmentary and incoherent", I say
             | "decentralized".
        
       | tupolef wrote:
       | The only way to get an honest electronic vote is by giving
       | realtime visibility on who voted what and where publicly.
       | 
       | Everything else is a scam.
       | 
       | It would mean no secrecy of vote, but I think that secrecy of
       | vote is for places that are new to democracy.
       | 
       | It could be anonymised to a point a clever system of personal
       | certificats, but the idea is that in a 100 people district, the
       | citizens should be able to count themselves and check if their
       | real votes are correctly registred.
       | 
       | If the list is public, everyone got a proof of vote and can
       | confirm that the global list is correct localy, then there is no
       | way to hide cheating.
        
         | stuaxo wrote:
         | There are ways of doing this using encryption so that the
         | person will know what their own vote is in a way that others
         | don't.
        
           | tupolef wrote:
           | But, there is still someone somewhere that distribute the
           | certificats and can link you to your vote so why try to hide
           | something that can leak. It will leak.
        
           | mFixman wrote:
           | "Prove that you voted for Putin or you are out of a job".
        
             | InvaderFizz wrote:
             | Which is what troubles me about making auditable digital
             | voting systems. I'm not sure how you could do it while
             | preserving the secret ballot.
             | 
             | About the best I can come up with is a QR code displayed on
             | the screen and on a printout that you can compare with a
             | third party phone app. Machine results are tabulated, and
             | the QR code sheet is put in a lock box separately. This at
             | least provides some way to compare what the computer says
             | you voted versus the QR backup ballot for audits. I'm sure
             | there are holes in my idea.
        
               | gruez wrote:
               | >About the best I can come up with is a QR code displayed
               | on the screen and on a printout that you can compare with
               | a third party phone app.
               | 
               | That's definitely not secret. If you can audit it on your
               | phone, baddies can force you to show your phone to verify
               | that you voted "correctly".
        
         | myth2018 wrote:
         | > The only way to get an honest electronic vote is by giving
         | realtime visibility on who voted what and where publicly.
         | 
         | The secrecy on individual votes has a good reason to exist.
         | Votes are already bought based on per-section public results,
         | imagine what would happen if individual votes were public.
         | 
         | Moreover, people under any sort of threat (communities
         | dominated by drug dealers, employees of a dishonest,
         | politically engaged business owner) would be in big trouble.
        
       | aftbit wrote:
       | I hate the narratives around voting security in the US. One side
       | says that it is totally secure, basically 0 fraud, most secure
       | election in history, etc etc. The other side claims that the
       | election was completely stolen from them by voting machines.
       | 
       | Neither of these claims is right. Personally, I doubt the
       | election was stolen. I know of a handful of cases of voter fraud
       | both anecdotally ("My mom [in a retirement home] told me to vote
       | for McCain, but I know she really wanted to vote for Obama, so
       | that's what I put.") and numerically[1].
       | 
       | I would not be surprised if one or two of the very razor thin
       | House district elections in 2020 experienced enough fraud to flip
       | the decision. This doesn't mean that I believe all of the
       | Dominion voting system hack nonsense or anything like that. I
       | just think only a Sith deals in absolutes.
       | 
       | 1: https://apnews.com/article/ohio-voters-citizenship-
       | referrals...
        
         | Spivak wrote:
         | This is a wild amount of both-sidesing in a case where one side
         | has evidence and the other is literally an unsubstantiated
         | conspiracy theory at a scale where you could not keep the
         | secret.
         | 
         | Most secure in history is (in my state) is correct. There are
         | more pointless safeguards than have ever existed. If you were
         | willing to go with the results of any election pre 2020 then
         | you should be overjoyed at how much more "secure" the process
         | is. That's the point that's being made, the amount of provable
         | voter fraud that bypasses the checks and is only discovered
         | after the fact is nil
         | 
         | The article you cited is literally the system working. There's
         | 11 million people in Ohio, the number of illegal registrations
         | is several orders of magnitude less than the lizardman constant
         | and they were nonetheless caught.
        
           | anon291 wrote:
           | Including the safeguards where observers are safely kept away
           | from the counting! There were a lot of irregularities in
           | 2020. The supreme Court recently said Pennsylvania should not
           | have counted some of the ballots it did in 2020 (policy
           | change by secretary of state vs legislature).
        
             | gruez wrote:
             | >There were a lot of irregularities in 2020.
             | 
             | Source? I thought all the election fraud
             | lawsuits/investigations for the 2020 election basically
             | went nowhere?
        
               | anon291 wrote:
               | For lack of standing or lack of ability to relieve yes.
               | Courts aren't going to question a presidential election.
               | That doesn't mean we can't look at the videos of
               | observers being banned, the facts of now-declared-illegal
               | extra-legislative policy changes, the timings of various
               | ballot drops etc.
               | 
               | Opinions aren't formed on court cases. That's why in
               | 2020, more than half of Democrats thought the election
               | was irregular. It's remarkable to me because this is one
               | of those issues where polling says voters of both parties
               | agree, but the media insists that there's nothing there.
               | That's crazy
        
               | gruez wrote:
               | >For lack of standing or lack of ability to relieve yes.
               | Courts aren't going to question a presidential election.
               | 
               | ???
               | 
               | https://en.wikipedia.org/wiki/Bush_v._Gore
               | 
               | >That doesn't mean we can't look at the videos of
               | observers being banned, the facts of now-declared-illegal
               | extra-legislative policy changes, the timings of various
               | ballot drops etc.
               | 
               | My impression is that there were a bunch of "this seems
               | sus" allegations, but all the popular ones have been
               | discredited. What are the most credible examples (ie. of
               | actual malfeasance going on, rather than merely "this
               | seems sus") that you can provide?
        
               | mikeyouse wrote:
               | Yeah it's just a polite retelling of the crazy Trump
               | nonsense that was laughed out of court by every judge who
               | looked at it and the rest is just misunderstandings from
               | casual election observers who refuse to do one iota of
               | research about how things work.
        
           | mythrwy wrote:
           | Yes drop boxes and mail in ballots with no signature
           | verification and the counting done largely by one side of the
           | partisan divide (county/state employees) is totally 100%
           | secure what could go wrong? Those conspiracy nuts just don't
           | get it.
        
             | anigbrowl wrote:
             | They had a very long audit hand-counted ballot audit of the
             | 2020 election in Arizona in 2021, and after (iirc) a few
             | _months_ of double and triple checking they were unable to
             | find any irregularities.
        
         | brandonmenc wrote:
         | > One side says that it is totally secure, basically 0 fraud,
         | most secure election in history
         | 
         | Additionally, the sides have completely flipped. Utterly
         | bizarre.
        
           | AnimalMuppet wrote:
           | Not bizarre at all. It's BS, but it's not bizarre.
           | 
           | Politics has become trench warfare. Everything is a battle to
           | the death to keep the other side from gaining an inch
           | anywhere. And, as is often the case in warfare, truth is a
           | casualty. Both sides will say absolutely anything to keep
           | anyone from thinking that the other side has a valid point.
           | 
           | It's advertising, but without any truth-in-advertising laws.
           | Or, if you prefer, it's propaganda. Any relationship to the
           | truth is purely accidental.
        
             | MichaelZuo wrote:
             | The true casualty is America's credibility abroad. In
             | pretty much every capital, embassy, boardroom, etc... it
             | noticeably declines year on year.
             | 
             | Even the Brits don't take anything at face value anymore.
        
               | anon291 wrote:
               | Our credibility has been suddenly made synonymous with
               | how willing we are to go to war on behalf of other
               | countries . We are not
               | 
               | But I think any attack on an American force will get you
               | a quick lesson on our credibility, which, as an American,
               | is all I really care about.
               | 
               | Similarly economically, good luck not participating in
               | the American markets.
        
               | MichaelZuo wrote:
               | I really don't want to burst your bubble... but do you
               | not realize this is seen as a joke abroad?
               | 
               | e.g. In Hanoi, American officials, diplomats, and
               | executives are rushing to wine and dine people who
               | literally celebrate the defeat of 'American force' in
               | public, on the record, every year.
               | 
               | They treat even a random third secretary for some party
               | committee 100km from Hanoi much much better than the 90th
               | percentile upper middle class American household in the
               | Bay Area...
               | 
               | Edit: And I'm not even going to talk about Eastern Europe
               | or the Middle East, it's really too harsh to put into
               | writing.
        
           | willcipriano wrote:
           | Notice the Cheneys and John Boltons of the world also have
           | seemed to flipped with them.
        
             | anon291 wrote:
             | I am happy to say, I've never been on the side of a Cheney.
             | Go me!
        
           | unethical_ban wrote:
           | Good thing we fixed the hanging chad issue.
           | 
           | Did Republicans anywhere try to "secure elections" in a way
           | that didn't involve curtailing voting rights? Improving
           | voting machines, systems, counting, etc. in a way that
           | partisan leadership couldn't mess with?
           | 
           | Georgia, I predict, will be a shitshow this year.
        
           | tzs wrote:
           | Before 2020 the only allegations of significant fraud or
           | other shenanigans I remember were immediately after elections
           | and were dropped shortly afterwards when no evidence could be
           | found for them.
           | 
           | Note that the Bush/Gore election issues were _not_
           | allegations of fraud or any intentional shenanigans. The
           | issue there was a badly designed ballots and /or badly
           | designed voting machines that let to a large number of
           | spoiled ballots due to people voting for more than one
           | candidate or not marking any candidate, and in one major
           | county led many voters to mark a candidate other than the one
           | they intended to mark.
           | 
           | All the controversy there after the election was how to
           | resolve those problems. Some, like the infamous "hanging
           | chads" could in some cases be resolved by hand examination of
           | the ballot, but there would often be some ambiguity so that
           | would not be without controversy.
           | 
           | Others, like the "butterfly ballot" in Palm Beach County did
           | not lead to any physical problem with the ballot but the
           | design of the ballot led many voters to vote for a candidate
           | other than the one they intended to vote for. That was a
           | completely novel failure mode and the system had no procedure
           | for dealing with it.
        
         | Molitor5901 wrote:
         | Each side uses the argument most expedient to them at the time.
         | For the 2020 election I recall it was concern over mail in
         | ballots.
        
       | efm wrote:
       | No one has mentioned 2FA. I suspect the passwords are not all
       | that is needed.
        
         | orev wrote:
         | I've never seen or heard of 2FA being needed for BIOS access.
         | However maybe we could consider "physical presence" as one type
         | of factor, which does reduce the risk a lot.
        
           | CaliforniaKarl wrote:
           | Also, the article mentioned "partial passwords". I take that
           | to mean the BIOS password was two parts, and only one part of
           | the password was exposed.
        
       | rsync wrote:
       | Paper ballots have very boring failure modes and need no
       | explanation or technical support.
       | 
       | When you see a system more complex than paper ballots, know that
       | the additions _are not there on your behalf_.
        
         | Sparkle-san wrote:
         | Colorado uses paper ballots. It's an all-mail voting state so
         | every voter is mailed a paper ballot which is then dropped off
         | or mailed back.
        
           | pessimizer wrote:
           | Mail-in ballots are worst of all, and the people who advocate
           | for their expansion will regret it when they see entire
           | church memberships filling out their ballots together,
           | checking each other to make sure they voted correctly, and
           | shunning, expelling, or firing people who don't participate.
           | 
           | There are currently many heads of household voting for their
           | entire families, and even aside from mail-in ballots, there
           | are people watching and photographing other family members
           | voting _within polling places,_ and uploading the photographs
           | to social media with parental pride. In many places, this is
           | not even criminal anymore.
           | 
           | Paper ballots, with voters having no method to prove who they
           | voted for (no-receipt), in a private booth.
        
             | Sparkle-san wrote:
             | It's been the method of voting in Oregon for 25 years and
             | Colorado for 10 years, when does the regret start? The
             | current states that have all mail voting are also some of
             | the least religious states in the country, you'd think the
             | religious states would be pushing for it given the scenario
             | you laid out. Colorado also had the second highest voter
             | turn out nationwide in 2020 which supports the claim that
             | all mail voting is good for increasing access to voting.
        
               | wannacboatmovie wrote:
               | Oregon should never be the gold standard for how to do
               | anything, ever. Can they even pump their own gas yet?
        
               | jeffmcjunkin wrote:
               | Recently, yes :)
               | 
               | https://www.cnn.com/2023/08/06/us/oregon-drivers-pump-
               | own-fu...
        
         | CaliforniaKarl wrote:
         | I disagree. I believe there are people who want results sooner
         | rather than later. The greater the delay, the more annoyed
         | folks become. Recording votes in _both_ paper and electronic
         | form allows for the auditability of paper and the speed of
         | electronic calculations.
         | 
         | (Side note: I also believe that hand-counting of ballots can be
         | tedious, and humans performing tedious, repetitive tasks are
         | prone to error. See [1].)
         | 
         | [1]: https://www.brennancenter.org/our-work/research-
         | reports/hand...
        
       | coolhand2120 wrote:
       | Please correct me where I'm mistaken.
       | 
       | * This password list has been public for a long time, and is easy
       | to access: hidden excel column on a public spreadsheet.
       | 
       | * BIOS access means the intruder can change boot devices, boot
       | their own OS, infect the BIOS with a virus, change boot devices
       | back, compromise the vote host OS.
       | 
       | * Keycard security isn't tight security. Any amature physical
       | penetration tester would just use a primitive attack on the door
       | to get around it. E.g.: Grab the handle from under the door with
       | a wire. Youtube has a ton of examples.
       | 
       | * This could have been done months ago, and over a long period of
       | time.
       | 
       | * The intruder could clean up logs and any other traces of their
       | actions.
       | 
       | Where am I technically wrong here? I'm sure I'm missing something
       | obvious. It sounds like what you would do with BIOS passwords if
       | you wanted to do something nasty. I haven't seen these questions
       | addressed anywhere.
       | 
       | I hear some people say "but we use paper ballots". Then why do
       | you have a BIOS password? If it's all paper where does the
       | computer fit in? All of this is honest curiosity, I'm not sure
       | how the voting system works.
        
         | gruez wrote:
         | >I hear some people say "but we use paper ballots". Then why do
         | you have a BIOS password? If it's all paper where does the
         | computer fit in? All of this is honest curiosity, I'm not sure
         | how the voting system works.
         | 
         | Not sure about Colorado specifically, but in many jurisdictions
         | voters mark paper ballots, which go into a machine to be
         | tabulated, and are finally deposited into a box for safe
         | keeping/future recounts.
        
           | quercusa wrote:
           | You get to feed the ballot into the (literal) black box
           | yourself, it beeps and tells you your vote has been recorded.
           | What did it record? Who knows?
        
             | gruez wrote:
             | > What did it record? Who knows?
             | 
             | How is it any different than traditional voting, where you
             | drop your ballot into a black box and trust the poll
             | workers would count it correctly?
             | 
             | You can do random spot checks select boxes to make sure the
             | machine is tabulating correctly. If they're all correct,
             | you can be reasonably sure the others are correct as well,
             | unless your adversary has incredible luck.
        
             | treyd wrote:
             | The idea is that the machine just provides a preliminary
             | count, a official manual count happens over the following
             | several hours. If there's a discrepancy then the only the
             | manual count counts and the machine can be identified as
             | problematic.
        
               | sgerenser wrote:
               | No manual count happens unless the results of the
               | election are in question (very close race, evidence of
               | impropriety, etc.)
        
         | liquidise wrote:
         | CO resident here.
         | 
         | CO mails paper ballots to everyone* about a month before
         | election day. You can choose to vote in person, or mail in/drop
         | off your paper ballot anytime prior to election night.
         | 
         | My understanding is what while the ballots are paper, many
         | (all?) are tabulated digitally. It certainly appears to be laid
         | out in a way that benefits digital reading, and i believe that
         | is what the machines in question are responsible for.
         | 
         | * for some definition of "everyone"
        
           | wannacboatmovie wrote:
           | Mail in voting is a joke that enables fraud through wide
           | scale incompetency in its process. These flaws cannot be
           | fixed. Voting for others, ballot harvesting where activists
           | collect ballots at nursing homes, ballot box stuffing, etc.
           | E.g.:
           | 
           | https://www.msn.com/en-us/news/us/woman-says-she-
           | got-16-ball...
           | 
           | If the county can't detect an obvious error such as sending
           | 16 ballots to unrelated people in a single apartment, what
           | else are they missing? You would think AI/ML could help with
           | fraud detection.
        
             | ForHackernews wrote:
             | Another example of "Everything looks suspicious when you
             | don't know how anything works."[0]
             | 
             | Mailed ballots are verified against voter registrations and
             | signatures are checked against the signature on file. This
             | woman with a bunch of ballots for former residents of her
             | apartment would gain essentially nothing and open herself
             | to serious criminal penalties if she tried to vote as
             | anyone except herself.
             | 
             | [0] https://www.msnbc.com/opinion/msnbc-opinion/elon-musk-
             | electi...
        
               | bhk wrote:
               | The article you cite says nothing in direct response to
               | the parent comment (ballot harvesting, etc.).
               | 
               | It also includes some misinformation, saying " signature
               | verification is a critical part of ensuring that only
               | valid ballots from eligible voters get counted" ... while
               | many states, including Pennsylvania, Wisconsin, North
               | Carolina, and Georgia, do not verify signatures.
               | 
               | https://www.ncsl.org/elections-and-
               | campaigns/table-14-how-st...
               | 
               | Another example of "Nothing looks suspicious when your
               | eyes are closed"?
        
               | wannacboatmovie wrote:
               | > Another example of "Everything looks suspicious when
               | you don't know how anything works."[0]
               | 
               | Typical smug HN reply. I've voted by mail. I know the
               | process inside and out. The system sucks and is full of
               | holes. Holes which are frequently excused for various
               | reasons including laziness.
               | 
               | Taking days or weeks to determine the winner of an
               | election (as frequently happens in WA and OR) in 2024 is
               | laughable.
        
             | CaliforniaKarl wrote:
             | > You would think AI/ML could help with fraud detection.
             | 
             | I think that's a very big leap to make, that the ballots
             | are going to where they're going because of fraud. Hanlon's
             | razor applies.
             | 
             | > ballot box stuffing
             | 
             | Ballot-box stuffing happens when more ballots are cast than
             | there are people who voted. This is difficult to do when
             | voting by mail. Indeed, from the article:
             | 
             | > LeVan Hodson told KING 5, "Even if someone gets a second
             | ballot (or more), whether under their name or someone
             | else's, we'll only ever count one ballot per registered
             | voter with their matching signature."
             | 
             | When you receive the envelope, you check the signature
             | against what's on file. You also check records to see if
             | the voter had voted elsewhere (such as at an early-voting
             | location). You can check to see if the voter reported not
             | receiving their mail-in ballot. You can do all these checks
             | before opening the envelope. And once you do open the
             | envelope, it's easy to see if multiple ballots had been
             | included in the envelope.
        
             | crooked-v wrote:
             | Once you look past individual anecdotes, the actual rate of
             | voter fraud with mail voting is tiny compared to the voting
             | population.
             | https://www.washingtonpost.com/politics/minuscule-number-
             | of-...
        
               | gruez wrote:
               | >Once you look past individual anecdotes, the actual rate
               | of voter fraud with mail voting is tiny compared to the
               | voting population.
               | https://www.washingtonpost.com/politics/minuscule-number-
               | of-...
               | 
               | that's hardly reassuring given how close this election is
               | going predicted to be.
               | 
               | >The median scenario from our forecast has Ms Harris
               | winning her pivotal 270th electoral-college vote by less
               | than half a percentage point.
               | 
               | https://archive.is/uk388
               | 
               | https://www.economist.com/united-states/2024/10/31/what-
               | to-w...
        
               | crooked-v wrote:
               | Half a percentage point is orders of magnitude bigger
               | than a 0.0025% fraud rate.
        
         | wannacboatmovie wrote:
         | > I'm sure I'm missing something obvious.
         | 
         | You forgot the voting machines with uncalibrated resistive
         | touchscreens that resulted in people pushing Trump and the
         | input being rejected, or worse, Harris was being selected
         | instead. Videos of this went viral on socials the last few
         | days.
        
           | nkrisc wrote:
           | > Videos of this went viral on socials the last few days.
           | 
           | Sounds super credible.
        
             | wannacboatmovie wrote:
             | Are implying the videos were all faked because this is the
             | most secure election in history (surpassing the previous
             | most secure in history)?
        
               | gruez wrote:
               | There's a pretty wide range of possibilities between
               | "videos were all faked because this is the most secure
               | election in history" and "let's not take the video at
               | face value and await further verification because it's
               | election season and there's plenty of bad actors trying
               | to sow distrust in the election system by posting
               | misleading/manipulated videos".
        
               | wannacboatmovie wrote:
               | The implication of the videos was that this was malice
               | (and that generates clicks) yet if you read between the
               | lines, it's simply incompetency - uncalibrated
               | touchscreens.
               | 
               | My point is local jurisdictions do not have the knowledge
               | or resources to properly maintain or deal with electronic
               | voting machines (of which there appears to be no national
               | standard) and maintain integrity. If they can't remember
               | to perform basic maintenance like calibrate the screens,
               | what other steps are missed or ignored?
        
               | ForHackernews wrote:
               | Which do you suppose is more likely...
               | 
               | A) There was a voting machine that had a miscalibrated
               | touchscreen that will be corrected before election day.
               | 
               | B) An evil democrat conspiracy is going to steal the
               | election in Kentucky
        
               | wannacboatmovie wrote:
               | Are you saying the video was made by an election worker
               | prepping machines in a back room?
               | 
               | These were deployed machines used in early voting. The
               | amount of willingness to excuse incompetency here is
               | unbelievable.
        
               | ForHackernews wrote:
               | Incompetence is not malice. I just googled for more info:
               | https://eu.usatoday.com/story/news/politics/elections/202
               | 4/1...
               | 
               | > Laurel County Clerk Tony Brown addressed the issue in a
               | statement, saying the machine was temporarily taken out
               | of service while an investigator from the Attorney
               | General's Office was called to inspect the machine.
               | Investigators tried to recreate the anomaly and were able
               | to do so after spending few minutes tapping in the area
               | of the screen between the Trump and Harris field, Brown
               | said.
               | 
               | > Despite additional attempts, Brown said investigators
               | weren't able to recreate it a second time.
               | 
               | > "The Kentucky Attorney General's Department of Criminal
               | Investigations quickly responded to the complaint from
               | Laurel County. Detectives have been in touch with the
               | county clerk and recommended they change out the voting
               | machine," Kentucky Attorney General Russell Coleman said
               | in a statement. "All Kentucky voters can have confidence
               | that our elections are secure and any potential issues
               | will be addressed quickly."
               | 
               | > In a statement Friday, officials from the Kentucky
               | State Board of Elections said the voting machine
               | registered the selection for Harris because the voter was
               | touching two boxes simultaneously.
               | 
               | > Initially, the voter used their finger to "jab" the
               | small box in the top-left corner of the Trump field on
               | the touchscreen. After a few failed attempts, a second
               | hand enters the frame and is seen attempting to
               | "simultaneously click the large Trump field with an index
               | finger and the large Robert F. Kennedy field with a
               | thumb, leaving the Harris box highlighted," officials
               | said.
               | 
               | > Michon Lindstrom, spokesperson for Kentucky Secretary
               | of State Michael Adams, also dismissed the incident as
               | "voter error."
               | 
               | > Brown emphasized that the issue occurred on a ballot-
               | marking machine, which does not process votes. Marking
               | machines allow voters to make their selections for their
               | ballot and then physically print them to be cast and
               | counted.
               | 
               | > If the machine prints a faulty ballot, voters are able
               | to discard it and print a corrected one, Brown said.
        
               | CaliforniaKarl wrote:
               | I would just like to say, thank you for doing the work of
               | locating a news post about the situation. That really
               | helps ensure we are talking about the same thing. And it
               | allows us to review the situation ourselves.
        
               | nkrisc wrote:
               | My point is "video of thing happening on social" media is
               | worth essentially nothing these days
        
               | Cthulhu_ wrote:
               | [delayed]
        
           | dingnuts wrote:
           | if you don't have a pile of links providing absolute proof of
           | this sort of claim, please, for the love of peace and your
           | countrymen, shut the fuck up and stop spreading fear,
           | uncertainty, and doubt. Rumors like this are how wars start.
           | Go watch A24's Civil War and think about the kind of rumors
           | you're spreading. Or provide proof. "viral on social media"
           | is anything but proof.
        
             | wannacboatmovie wrote:
             | > shut the fuck up
             | 
             | This isn't Reddit. We argue like adults here.
        
         | CaliforniaKarl wrote:
         | > Where am I technically wrong here? I'm sure I'm missing
         | something obvious.
         | 
         | As I understand that article, BIOS access requires two
         | passwords, and the list only provides one of the two passwords.
         | So, instead of "password list" I would say "partial-password
         | list".
         | 
         | The list also misses "There is 24/7 video camera recording on
         | all election equipment." Of course, you can raise concerns and
         | failure modes about video recordings, but that all brings up
         | the question "Were those recordings compromised?" You should
         | not assume that they were.
        
       | anigbrowl wrote:
       | Interestingly, a website set up to document voter fraud by Mike
       | 'My Pillow' Lindell has collected hundreds of election law
       | violations, many in Colorado. For some reason they are all dated
       | for the future though. Might be a warning signla about not
       | populating your database where the public can watch you doing it.
       | 
       | https://archive.ph/smlSQ (capture of https://electionnexus.com
       | from earlier today)
        
         | WorkerBee28474 wrote:
         | More likely something like hand-rolling timezone conversion
         | code.
        
           | gruez wrote:
           | I think the timestamp column is straight up broken. I checked
           | the first and last few pages and they all have the same
           | timestamp.
        
           | Jtsummers wrote:
           | No, it's weirder than that. All the samples I pulled up had
           | the same date and time without showing any time zone
           | information: 2024-11-03 01:43:25
        
         | gruez wrote:
         | Is the site satire? There's basically no information of each
         | "incident" aside from the state and a bunch of hashtags.
        
         | Sparkle-san wrote:
         | That would support Colorado having a robust system then and we
         | shouldn't be concerned just like the SoS says. If their system
         | was bad, they wouldn't be catching the voter fraud.
        
       | CaliforniaKarl wrote:
       | I think all US folks reading this should volunteer at their
       | county's Registrar of Voters (or equivalent agency for their
       | county). Spend one election working at a polling place, and
       | another election working at the RoV HQ. See what it's like to go
       | through the training, and what things are like on Election Day,
       | and in the days leading up (for places that allow early voting,
       | drop-off, etc.).
        
       ___________________________________________________________________
       (page generated 2024-11-02 23:00 UTC)