5 ms·
Lol honestly I don’t trust anyone who says their system is secure. The idea that some random company that built an android or iOS app with an aws backend magica
by mlazos 6y ago
Lol honestly I don’t trust anyone who says their system is secure. The idea that some random company that built an android or iOS app with an aws backend magically has no vulnerabilities is laughable, especially after they had hard coded credentials in their repo. The more the ceo says it the more he loses credibility. I might trust a big 5 company to implement this, might. But generally until our systems are secure by default I don’t think anyone could do this right, and there are so many resources going into hacking it it will take a lot of guarantees for me to start to feel better. Mail in voting is simpler and much less vulnerable to scalable hacking.
- philihp 6y agoAs you should, when these systems are closed sourced. Would you trust an open source system, though? https://github.com/microsoft/electionguard https://github.com/microsoft/electionguard
- nuker 6y agoWhat about voters' devices? Jessies WinXP, never updated, full of malware?
- rbecker 6y agoOpen source is not enough, since you have to trust the compiler and hardware the system is running on as well [1,2]. But from the page you linked, the key benefit of that system isn't that it's open source, but that the results are verifiable. I.e. you can check that the results are trustworthy, even if you don't trust the code or machines it's running on? [1] https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html [2] https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/Intel_Management_Engine
- mlazos 6y agoI’m definitely more likely to trust open source. Generally the more eyes on it the better, I still think even one vulnerability could potentially be catastrophic though. That microsoft link looks really interesting, I don’t understand automated theorem proving and crypto enough to see how it would work even with untrusted hardware (although it does say it can be run on any third party system)
- CM30 6y agoThis is probably a stupid question, but why is mail in voting seen as secure when online voting isn't? I mean, obviously the latter is less secure, since you don't know how the votes are counted and can more easily change the results en mass. But shouldn't both have the same issues with things like voter coercion? Did we suddenly decide that isn't a risk at all?