6 ms·
The conclusion: Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles: 1. It is important t
by texuf 8y ago
The conclusion:
Over the last 26 years, DEF CON, and for the last two years, the Voting Village, have operated under two core principles:
1. It is important to derive facts through reason and inquiry rather than blind faith.
2. When we discover new facts, it’s important we share this information with the general public so individuals can decide how best to use the information.
We did not make these principles up ourselves. Rather, these principles are the foundation of the Enlightenment, which has guided modern science to achieve the medical, engineering, and IT advances, among others, that underpin the modern world. Since these principles have largely guided the human race toward progress for the last 500 years, we plan to continue to follow them.
These principles matter most when we put them into practice. Therefore, it is relevant to ask what new facts all the poking and inquiring into our voting systems has identified since the Voting VIllage was established.
Among the dozens of vulnerabilities identified in the last two years, four key DEF CON Voting Village findings are grave and undeniable:
1. Supply Chain Insecurity: The voting machine parts supply chain is global and has essentially no security procedures to determine whether the machine parts are trustworthy or pre-hacked before the machine is assembled. Thus if an adversary compromised chips through the supply chain, they could hack whole classes of machines across the U.S., remotely, all at once.
2. Remote Attacks Proven: Despite insistence the fact that machines are “air gapped” from the Internet protects against all remote attacks, both DEF CON 25 and 26 found exploits to hack machines remotely, requiring physical access to the machine.
3. Hacking Faster Than Voting: This year DEF CON also demonstrated that while, on average, it takes about six minutes to vote, machines in at least 15 states can be hacked with a pen in two minutes. It is thus possible for someone to hack a machine while voting in a polling place on Election Day.
4. Hacks Don’t Get Fixed: Finally, we discovered that even when vendors are told about serious flaws in machines by their customers, those flaws go unfixed.
- ragebol 8y ago> it takes about six minutes to vote Why does voting take 6 minutes? I think I used a voting machine maybe once in my life (in the Netherlands and apparently young enough to not have used those more often). Casting a vote on paper is usually checking a box with a red pencil, takes maybe a minute of dealing with the huge sheet of paper with all the candidates. Just curious.
- mikejb 8y agoI think this is measured on average, and it's possible that people are undecided, or look through everything and take their time making sure to do it right.
- flatline 8y agoWhen you are voting for a dozen candidates and a dozen ballot measures, it takes time to read through all of them and make sure you are marking the correct boxes, even when you know how you will vote in advance.
- blacksmith_tb 8y agoThis is another reason (along with preventing remote hacks etc.) that vote-by-mail[1] is much more reasonable. It provides you with as much time as you need to look up candidates and issues. 1: https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon https://en.wikipedia.org/wiki/Vote-by-mail_in_Oregon
- tolas 8y agoCan confirm from Colorado. They send everyone a vote by mail application whether you ask for it or not.
- int_19h 8y agoI don't know about Oregon, but in Washington you also get a thick voter pamphlet that goes over all the candidates and issues in great detail, including candidates' statements about themselves. For initiatives (referendums), it even has statements by pro and con groups, and rebuttals of each others' statements. And you get that way in advance of the election, too, so there's plenty of time to go over it and do any additional research you feel necessary. Here's an example from this year. https://www.kingcounty.gov/~/media/depts/elections/how-to-vote/voters-pamphlet/2018/08/edition-2-en.ashx?la=en https://www.kingcounty.gov/~/media/depts/elections/how-to-vo...
- russdpale 8y ago
- crankylinuxuser 8y agoOk. So, those are powerful findings of fact. From this, what has been done thus far regarding: State election boards State House/Senate committees on elections Local election judges and boards Federal House/Senate committees on elections I would assume that these allegations must be verified. However, since all the procedures and observations are being made in the open, they should be relatively easy to confirm. But, what are our legislators and boards doing to prevent hacking and malfeasance like this?
- michaelmrose 8y agoNothing there was a measure to spend money improving security of voting systems but Republican's defeated it. Meanwhile one of the largest manufacturer of voting machines openly came out for bringing in the votes for the Republicans and at least one developer has openly asserted that he was asked to enable fudging the vote.
- empath75 8y agoThey intentionally made the machines hackable because they intend to cheat. It’s really that simple.
- jiveturkey 8y ago> 2. Remote Attacks Proven: Despite insistence the fact that machines are “air gapped” from the Internet protects against all remote attacks, both DEF CON 25 and 26 found exploits to hack machines remotely, requiring physical access to the machine. Did you leave out a word?
- hammock 8y agowithout
- everdev 8y agoConversely, is it possible to physically or remotely access one of these machines and determine if they've been hacked (or pre-hacked?) and how long would that take? Also, does the hack simply modify the results for that machine, it does it grant access to manipulating the entire county vote?