5 ms·
TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy. It makes me wonder how
by nmlnn 6y ago
TIL, electronic voting machines are CLOSED SOURCE (hardware and software) - that should be completely unacceptable in an open democracy.
It makes me wonder how a statement like this can be proved.
> There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised
When it comes to something as important as elections the mantra should be: don't trust. verify.
- kube-system 6y agoI don’t see security flaws with closed source software that prints backup paper ballots. If anything, it’s better than an open source machine that doesn’t print a paper backup. Those paper backups can be even audited by the voter at the moment they vote. You’re not going to be dumping the source code from a voting machine that is in use.
- noworriesnate 6y agoThere’s no need to compromise. When it comes to making elections trustworthy, we should pull out all the stops, even if it’s slightly inconvenient to make the software open source.
- kube-system 6y agoDoes any company offer a competitive voting machine with open source software?
- callinOutLiars 6y agoSecurity through obscurity is a horrible way to secure anything, but especially voting machines.
- dllthomas 6y ago> I don’t see security flaws with closed source software that prints backup paper ballots. There's room for asymmetric errors in input, in the direction of a favored candidate. Still way better than the kinds that are electronic only, but not as good as paper-first.
- Someone1234 6y agoFully agreed. The key thing with closed Vs. open source isn't simply the ability to find defects (design & bugs), but also right now election officials/security experts in some cases aren't allowed to verify election software per the software licenses! That's an untenable position to be in. Open source isn't some panacea, but it puts you into that position where "verify" is even conceptually possible. I still believe we need paper backups and random audits, but we can do multiple things at once and should.
- ghettoimp 6y agoI'm a free software fan, but I don't see that open source matters here. How do you know the machine is running the program whose source code you're looking at, instead of some other program that looks superficially like it? If a machine produces convincing evidence of what it has done, e.g., a print-out that (1) the voter can meaningfully check before depositing, and that (2) is audited with at least spot checks or formal recounts later, why does it matter whether it is open or closed source?
- monoideism 6y agoNot only that. Vendors can deploy unknown, unapproved firmware updates: https://www.politico.com/news/2020/11/04/georgia-election-machine-glitch-434065 https://www.politico.com/news/2020/11/04/georgia-election-ma...
- 0xy 6y agoThey deployed a mystery closed-source software update right before the election. No matter which way you slice this, it's sheer incompetence and smells fishy (even if it isn't fraud). If you want to project security, you don't do this kind of thing. It's insane. It's like the plot of a Hollywood movie.
- vga805 6y agodo you have a source for this? i don't doubt it's true, i am compiling evidence for claims like this
- 0xy 6y agoSure, here's the source. [1] [1] https://www.wsbtv.com/news/local/spalding-county-experiencing-county-wide-glitch-bringing-down-voting-machines/EPCV6RSBRFBLTJUVQXJZAIFO2U/ https://www.wsbtv.com/news/local/spalding-county-experiencin... "vendor for the machines notified them at 7:05 a.m. that there was a problem with an overnight update to the system" "They just said it was a glitch in the system"
- jlgaddis 6y agoI can't speak to this particular situation but it's worth noting that last-minute-just-before-polling-begins updates are the norm and happen pretty much every election. In/around my hometown, for example, the voting machines are "securely" stored in between elections, until just before an election, when they get 'em out to set them up, test them, etc. Whether they installed updates an hour before an electiion or two weeks before an election, it can still be made to sound "fishy" by anyone who wants it to. "Why were they installing a so-called 'update' an hour before the polls open?" versus "Why were they installing so-called 'updates' on the voting machines two weeks before the election?" Obviously, they were installing hacked firmware in either case, right?
- wskinner 6y agoIf it would hard or impossible to produce evidence of tampering, it’s easy for that statement to be true.
- 0xy 6y agoNot only are they closed source, but insanely sometimes they have REMOTE ACCESS enabled. [1] The companies involved can only be described as utterly incompetent in security. [2] [1] https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-hacker-proof-voting-machine.html https://www.nytimes.com/2018/02/21/magazine/the-myth-of-the-... [2] https://en.wikipedia.org/wiki/Election_Systems_%26_Software#Controversies https://en.wikipedia.org/wiki/Election_Systems_%26_Software#...
- deleted 6y ago[deleted]
- aw1621107 6y ago> It makes me wonder how a statement like this can be proved. >> There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised I suppose it might depend on how you read that statement. One person might read it as "There is no evidence (that exists/that will exist) that any voting system deleted or lost votes, changed votes, or was in any way compromised", in which case some backing would be desirable. Another person might read it more like "There is no evidence (that we're aware of) that any voting system deleted or lost votes, changed votes, or was in any way compromised", in which case proof technically doesn't need to be provided, as one can truthfully state that they are not aware of evidence of an event independently of whether that event occurred or not.
- jlgaddis 6y agoI always read "we got pwn3d" disclosures this way. For example, it's common to read something like "we have found no evidence that the hacked data has been (ab)used ...". Cynical me just assumes they decided to leave out the rest of the sentence, "... because we didn't actually go looking for any such evidence", therefore they can ("honestly") "plead ignorance".
- deleted 6y ago[deleted]
- rendall 6y agoI was just about to make an obnoxious, downvotable joke to that effect!