I bought used voting machines on eBay for $100 apiece (2018)
wired.com
wired.com
They turned out to contain hundreds of highly classified documents detailing years of cabinet discussions of successive Australian governments ("cabinet" here meaning the core group of senior ministers). This probably happened because the (filing) cabinets were locked and no-one could find the keys, so someone at parliament house got lazy and didn't dispose of them properly.
The documents were handed over to journalists and the whole saga became known as "the cabinet files".
https://www.abc.net.au/news/about/backstory/news-coverage/20...
> The fact that voter information is left on devices, unencrypted, that are then sold on the open market is malpractice
I disagree with him that what he describes is "voter information".
There's vote information and election information, both which are already public information and are not sensitive information at all. The machines do not have voter information on them nor does he give any evidence of it. What he describes finding was:
> The information I found on the drives including candidates, precincts, and the number of votes cast on the machine, were not encrypted.
All these things are public information already.
> Worse, the “Property Of” government labels were still attached, meaning someone had sold government property filled with voter information and location data online, at a low cost, with no consequences. It would be the equivalent of buying a surplus police car with the logos still on it.
When government agencies auction off surplus cars they seldom repaint them first. It's common to find them with the logos. Example:
https://www.copcarsonline.com/2018_Dodge_Charger_Largo_FL_35...
Even comes with the original light bar and the radar!
No kidding. You don't even have to buy a voting machine to get that information.
A good question though is how much do you have to change before you can legally drive it?
This guy here seems to believe that driving a police car with lights and even "911" and "Dodge Law Enforcement" is Ok as long as it doesn't say the word "Police" at which point it would be impersonating a police officer.
https://www.motorauthority.com/news/1100773_driving-a-police...
In this police forum where they are discussing the issue one person notes that in California driving anything that remotely looks like a police car is illegal, and another states that in Tennessee you can drive a police car if you feel like it. So state laws perhaps vary as to whether you have to remove the decals and/or repaint the whole thing before driving a decalled surplus acquisition.
https://forum.officer.com/forum/public-forums/general-law-en...
Then, you know, they are also cool with others’ impersonation of well known Tennessean.
Seriously though are they the only state left with "Constables" which are completely independent law enforcement officers who have to buy their own cruisers, guns, and uniforms, which they get to design themselves?
It sounds pretty cool, like there's no possibility of conspiracy with other cops in their department since there aren't any, there's no supervisor so they can't say they were just following orders, and if the entire local police force is corrupt, one can use the constable as a last form of justice. And if people don't like the job they are doing they can simply vote them out.
Then proceeded to cruise around town. The Police were, of course, not amused. He got it impounded twice, but they had to return it on both occasions with no charges filed.
If you combine a voting machine ID from a certain time and place, can you determine with good certainty the way that a particular person voted?
Luckily, we don't have electronic voting machines.
[1]: https://twitter.com/hackerfantastic/status/11874911773035520...
[2]: https://twitter.com/hackerfantastic/status/11881873784368046...
[3]: https://twitter.com/hackerfantastic/status/11872782894353899...
[4]: https://twitter.com/hackerfantastic/status/11881788254876057...
[5]: https://hacker.house/lab/hacking-elections-diebold-accuvote-...
[6]: https://github.com/hackerhouse-opensource/electionhacking
[7]: https://twitter.com/RachelTobac/status/1028437783050776576
ATMs are secure because banks would lose money if they weren’t. Not because of regulation.
Regulation leads to a bare minimum of safety, not a best-in-class security.
One thing banana-republics all have in common is nationalized voting commissions. Doesn’t turn out as well as the author here suggests.
Do you really feel like banking and medical records are being kept secure? If so I envy your confidence.
Compare that to the way our messages are being encrypted these days (iMessage comes to mind) and i think we’d find the regulation to be lacking.
The incentive provided by regulations (I.e. jail time or fines) doesn’t compare to incentives derived from competition, or (heaven forbid) profit.
It’s, for better or for worse, human nature.
Banking is heavely regulated. I agree that security is good business practice. But, to disregard regulations without proof is a big leap of faith.
Banking have survived thanks to government intervention. And to start with got itself in a mess because Great Depression era regulations where removed.
Now that's wishful thinking. Do you know how hard it is to get your money back from fraudulent transactions caused by compromised ATMs (card skimmers etc - the kinda thing Krebs routinely writes about)?
The banks don't lose their money, they lose your money, and good luck proving this in many countries around the world including the US, UK, Europe.
One of these is not like the other. ;)
PCI-DSS = Payment Card Industry Data Security Standard. It’s not a regulation (as in law), it’s a self imposed industry standard as the name implies.
HIPAA - Health Insurance Portability and Accountability Act, as in an actual law passed by Congress and signed into law by President Clinton.
While PCI can end up with huge fines and/or inability to process payment transactions for non-compliance, it’s not a law.
I mean, we’re only talking twice a year events!
E-voting? One hacker can reprogram thousands of machines, possibly not having to even be in the country, anonymously. It gets even worse when you have online voting, because then you have a whole host of potential exploits, like MITM, DDOSing targets like libraries, gathering IDs, etc. When you consider the amount of money running on elections, it's not unthinkable to consider there could be state-sponsored hackers, so there's no problem of resources there. And this is all assuming the hardware and software aren't already compromised by the manufacturers; considering we've seen compromised hardware coming from China it's a very likely possibility.
Like, I'm sure there are some folks whose concern about voting maching hacking isn't just a partisan tactic - especially on places like HN - but Wired magazine isn't one of them. Given that the last time this was such a major mainstream topic was after the 2004 election, well...
And apparently you only needed to flip 4000 votes in swing states to secure the electoral college numbers... 4000 targeted ads on Facebook, how much did that cost? Cambridge Analytica knows.
Where did you get that idea? We know from the Mueller report that they indeed paid to try to influence the election, but the sums were tiny compared to what the actual candidates paid. Also, please remember that Cambridge Analytica was hired by Trump ('s people) , not the Russians.