4 ms·
I read and saw many assurances by IT experts that the election couldn't be hacked and wasn't hacked (said much too soon for them to know) but I never heard a co
by hackuser 10y ago
I read and saw many assurances by IT experts that the election couldn't be hacked and wasn't hacked (said much too soon for them to know) but I never heard a convincing argument or an indication of a serious analysis. Can anyone here provide one?
The only serious argument I heard was that it would be very complicated and expensive to hack so many local voting systems. However, certainly state-sponsored - and maybe other - attackers have the resources to do it, they can greatly reduce the cost by targeting only necessary systems (e.g. just a few voting systems in each swing state), they probably can find more ways to economize on a brute force attack, and most importantly: For them the massive return on investment - controlling who is the next President of the U.S., and possibly undermine confidence in U.S. political institutions - makes it worthwhile. It's arguably worth it to hack the machines, leave evidence, and not change the result
I worry that in their rush to refute Trump's allegations of rigging, the experts opened the door to attackers by preemptively blocking investigations; they are now politically very difficult, they will cost the experts' reputations, and they may cause more uncertainty among the public than they resolve.
The best security I can think of is deterrence: If they get caught, the attacker might be inviting a war with the U.S. But do Russia and China really feel threatened?
- umanwizard 10y agoWhat makes you think it would be Russia and China necessarily, as opposed to just internet trolls?
- hackuser 10y agoThat was a comment on the scenario the expert described, where such an operation would be "very complicated and expensive".
- dmurray 10y agoThat's one good argument against mass hacking: if it was as easy as it's being made out to be to manipulate the results, we should expect to see something obviously vandalized: a black county that voted 100% Trump, or a county where third party candidates get all the votes. > There’s no question that this is possible for technically sophisticated attackers. (If my Ph.D. students and I were criminals, I’m sure we could pull it off.) If anyone reasonably skilled is sufficiently motivated and willing to face the risk of getting caught, it’s happened already. Surely there's someone on 4chan who ticks those boxes. The motivation doesn't even have to be pure vandalism: it would be a very effective way to call attention to the vulnerabilities in the system.
- LoSboccacc 10y agowell, my to-go expert was writing about unreliability since unsuspecting times https://www.schneier.com/blog/archives/2004/11/the_problem_wit.html https://www.schneier.com/blog/archives/2004/11/the_problem_w... - don't know whom you listen to, but back in time when slashdot still had some content I recall a big fight between vendors and researches over source code auditing, which of curse after many lawsuites completed exposing many weakness in design, even before accounting for "honest" bugs, and even back then the whole business surrounding election automation was exceptionally shady.