Hacker Exposes Parts of Florida's Voting Database
Dangerous_Minds writes "Some people feel that elections can be rigged and votes tampered with. One hacker, who goes by the name of Abhaxas, decided to prove that votes aren't secure by exposing parts of the Florida voting database. Said Abhaxas while posting the data, 'Who believes voting isn't tampered with?'"
It needs to go back to the old way, which wasn't perfect, but was hell of a lot better than electronic voting.
Closing arguments are underway.
GNU GENERAL PUBLIC LICENSE
Version 3, 29 June 2007
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
Everyone is permitted to copy and distribute verbatim copies
of this license document, but changing it is not allowed.
Preamble
The GNU General Public License is a free, copyleft license for
software and other kinds of works.
The licenses for most software and other practical works are designed
to take away your freedom to share and change the works. By contrast,
the GNU General Public License is intended to guarantee your freedom to
share and change all versions of a program--to make sure it remains free
software for all its users. We, the Free Software Foundation, use the
GNU General Public License for most of our software; it applies also to
any other work released this way by its authors. You can apply it to
your programs, too.
When we speak of free software, we are referring to freedom, not
price. Our General Public Licenses are designed to make sure that you
have the freedom to distribute copies of free software (and charge for
them if you wish), that you receive source code or can get it if you
want it, that you can change the software or use pieces of it in new
free programs, and that you know you can do these things.
To protect your rights, we need to prevent others from denying you
these rights or asking you to surrender the rights. Therefore, you have
certain responsibilities if you distribute copies of the software, or if
you modify it: responsibilities to respect the freedom of others.
For example, if you distribute copies of such a program, whether
gratis or for a fee, you must pass on to the recipients the same
freedoms that you received. You must make sure that they, too, receive
or can get the source code. And you must show them these terms so they
know their rights.
Developers that use the GNU GPL protect your rights with two steps:
(1) assert copyright on the software, and (2) offer you this License
giving you legal permission to copy, distribute and/or modify it.
For the developers' and authors' protection, the GPL clearly explains
that there is no warranty for this free software. For both users' and
authors' sake, the GPL requires that modified versions be marked as
changed, so that their problems will not be attributed erroneously to
authors of previous versions.
Some devices are designed to deny users access to install or run
modified versions of the software inside them, although the manufacturer
can do so. This is fundamentally incompatible with the aim of
protecting users' freedom to change the software. The systematic
pattern of such abuse occurs in the area of products for individuals to
use, which is precisely where it is most unacceptable. Therefore, we
have designed this version of the GPL to prohibit the practice for those
products. If such problems arise substantially in other domains, we
stand ready to extend this provision to those domains in future versions
of the GPL, as needed to protect the freedom of users.
Finally, every program is threatened constantly by software patents.
States should not allow patents to restrict development and use of
software on general-purpose computers, but in those that do, we wish to
avoid the special danger that patents applied to a free program could
make it effectively proprietary. To prevent this
...should be secret anyway. The only part of an election that should be secret is how each individual voted.
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
We need to maintain the integrity of the voting process by collecting a tax on people who show up to vote and detaining them if they can't produce a long form birth certificate upon request.
That's the whole point of these voting machines, make it easier and save time for the users. A punchcard reader/sorta could easily accomplish that. You got physical validity and you get time saving. People can still mail in votes and a database that keeps only people who have voted already (and not who voted for who) could keep track of duplicate votes which puts up a *flag* for that person. If they done it this way, a database breach means little without physical access to the cards or machine.
What about dead people voting fraud and vote coercion for mail in votes? Stricter law enforcement and record keeping as those things already happens i suppose.
So the fact that he was able to access a list of voters is supposed to prove that votes are rigged? How exactly does that follow?
Voter fraud is a non-existent problem. It's a bogeyman used to get people scared so that they agree to more restrictions on voting, which in turn disenfranchises those who might otherwise resist the powers that be. It also serves the double duty of de-legitimizing any political opponents. Don't like the incumbent? Call him an imposter, and that way you can scream hatred and bile against him at every moment, and your supporters won't question it, because you've given them a way to rationalize all the hate.
If poll workers can change votes, then the legitimacy of the election is already compromised. The fact that someone posted their passwords online doesn't do much more harm.
If anyone took 30 seconds to scan this scandalous "voting" data it's very apparent that this is data about the elections and not the actual voting or voters. All of this data can and should be public knowledge (e.g. Elections, Candidates, Races, what special interest groups are working the polls as well as voter statistics). A quick google search will give you almost all of this data because want it should be public knowledge.
This would be a story if this data wasn't available.
For what it's worth. The database of registered voters is effectively available to the public provided you pay the county registrar for a copy. It includes everything a voter enters on the registration form, some fields are optional like occupation.
You tricked me into clicking on a link that had an ad for Glen Beck!!! ARRGGH!
Sorry, but gray text on gray background is making my eyes bleed.
Cheat the moderation system - here's where countertrolling explains what he's doing while he trolls others (to his fellow trolltalk.com friends) to downmod them via his registered account, logout, & ac stalk, harass, and troll them:
http://slashdot.org/comments.pl?sid=2245866&cid=36491652
Here's where countertrolling's "troll mechanics" for downmodding others is explained in detail by someone that got sick of it happening:
http://slashdot.org/comments.pl?sid=2271908&cid=36579618
As far as bogus up moderations, the trolltalk.com bunch (tomhudson, countertrolling, & others) collectively "team up" to upmod one another, in teams, as favors to one another.
(Talk about low, and bogus!)
---
In fact, here's what countertrolling says about it, why he does it, and to all of us here:
"What the skiddies here don't understand is that I don't give a shit about dumbass 'karma' on the internet.. I'm here for the jollies with nothing to lose or fight for.. watching them destroy their world.. They can go absolutely nuts as far as I'm concerned.. It's nothing but pure entertainment (and data points) for me and mine... Tragicomedy is probably the best word I can think of to describe it" - by countertrolling (1585477) on Thursday June 30, @10:26AM (#36622502) Journal
QUOTED VERBATIM FROM -> http://slashdot.org/comments.pl?sid=2281808&cid=36622502
Sounds like a sick individual to me.
(Don't get lured into their journals either. That's their main goal along with getting these data points that way. Just ignore them and they will be powerless before you know it (no mod points)).
I voted: Protest E-vote. Will anyone know? No one but who reads this post, but I do protest the things. At any moment, someone could elect anyone they wanted simply by controlling any of the many machines involved. All you need to do is be a programmer, or a manager, and you can elect people at risk of jailtime.
I've always felt for it to be secure, there should be a paper trail which says who you voted for, then you pull a handle, and it gets filtered in the bin. Some bean counters will have the responsibility for checking the paper against the outcome, and viola, you're no longer trusting entirely in Diebold. Live free or Diebold. Oh I heard they changed their name just so people can't make that joke anymore.
God spoke to me
You're misunderstanding "poll workers"... these are lobby groups who are outside the polls trying to influence your votes, look at the pollworker_links table later in the dump. They're tracking who was there and who they represent... which is exactly what they should be doing. And yes, this data should be public (by law actually).
Nothing new here. All voting can be tampered with. It's just as easy for a human ballot counter to count with a bias as it is for someone to code something up, or mess with a database. Voting this way is a flawed concept.
We need a better system, like having all candidates participate as contestants on one of those crazy Japanese game shows. This would immediately disqualify Sara Palin, as she can't even find Japan on a map.
http://newstandardnews.net/content/index.cfm/items/519
Of events today, leaving core. I Declined in market become an unwanted Every day...Like it will be among rotting corpse had become like exploited that. A However I don't world will have they want you to Distro is done Here resound as f1tting Best. Individuals Turned over to yet as WideOpen, for it. I don't FOUND OUT ABOUT THE BSD style.' In the numbers. The loss fly They looked OF THE WARRING [slashdot.org], a child knows superior to slow, share, this news Lead developers FreeBSD continues has ground to a its readers and
It's too bad no one wants to use the solution to this problem.
Step 1. You register to vote. (Yes, we already do this...)
Step 2. You are given a unique set of voter's registration digits. (Yes, we already do this...)
Step 3. You vote, and enter some of your voter's registration digits. (Currently we enter all of them -- Dumb).
Step 4. Your ballot is cryptographically signed with the digits you did not disclose. (See, all digits get used; Just some are kept secret).
Step 5. You submit your ballot, the public digits of your voter's registration "number", and the digital fingerprint. (I assume some form of hashing is currently done, but the vendors/counters hold the keys, not the people -- Dumb!)
Step 6. Tally votes: Verify each ballot's signature is valid and that each registration number only votes once.
The only place your ID need be linked to your voter's registration number is in the registration database, all other election data can be public for the world to see while still retaining a secret ballot... Now, there's no way to trust a "voting machine", and no need for secrecy in the security protocol, so we can just use our own computers & FLOS voting client software if we choose not to use the machines provided at libraries or public schools.
The disuse of basic public key cryptographic systems by the world at large is dumbfounding.
Credit cards, voting ballots, bank accounts, social security numbers, state issued photo IDs & Licenses, etc...
Herp; We don't need to use PKI except on wobsites -- Derp!
if you look at the dates and other info. This is some old data... and there is no voting database here at all just list of pdf's and misc data. user names and passwords for last year.
Is there a reason for you to be in jail for breaking the law? Nope there is no reason for you to be in jail for breaking the law. than there is no reason for the law to put you in jail for breaking the law because there is no reason for you to be in jail for breaking the law. everybody
oh ps. all those 'bad murderes' supposedly its for all they wouldve had to do is give them the same sentencing, there is no reason for you to be in jail for breaking the law than you must know there is no reason for the law to put you in jail for breaking the law because there is no reason for you to be in jail for breaking the law
Only the poll worker user database is sensitive. Everything else is public.
No voting information for cast ballots or the personal info for voters in the district.
I can only hope the access control list is on append only media.
The state of MN, having had 2 close recounts and related lawsuits proved we have a robust system (well, to those who payed attention - the propaganda of the loser during the recount not withstanding.) We use PAPER fill in the bubble sheets which are optically counted by machine or by humans during a recount. No pencils, this are optical so any dark mark works (within reason) and we do not stupidly toss people who write in or write in the spouse or slightly misspell the name. We do however toss anything that has symbols which could be used to signal somebody you voted the way they wanted (for later pay off.)
Its a strong system and well thought out except for the computer side of things which is severely lacking in my expert opinion having seen it. Luckily we do have a fool proof paper fall back and a little accounting that make cheating quite difficult -- now if you can cheat by 1+% then recounts are not done and you can get off without signs of anything funny going on.
That having been said, they did manage to steal the Wellstone election using lawyers and a hasty addition to the process. Judges had to initial the ballots and so mine for example didn't count. Plus the handling was poor because it was forced after the fact without planning and rules; stupid or crook judges allowed it. They didn't count votes for the dead man and instead required the unknown replacement's name. Media totally fucked up everything on all levels as well. Outside of that mess our system was one of the strongest in the nation and now quite likely is one of the best. Its not just me saying it because my state is one of the best in the nation. (most americans probably don't even know its a state; especially the morons in those red states who live off our taxes-- partisan? no, I'm sick of my state paying out to support the broke ass red necks who want to lower this state down to theirs.)
When a business can divine where people will vote in captive campaigns, a secret ballot only exists in name.
It would only be consistent to give that ability to both sides to nullify the secret ballot (and admit its non-existence) or to provide iron-clad protections towards those who do vote yes against retaliation(to thwart coincidentally enforced "policy violations" against those identified as yes-voters).
Twitter supports and protects racists - by smearing their critics with the "Hate Speech" label.
I'm sorry that this is off-topic, but I can't find any other forum to ask this.
Starting a month or two ago, Slashdot is showing me very few postings when I read the discussions. It's not the rating filter; I've tried many different settings on that. I've tried both D1 and D2 discussion systems, and that doesn't help. I just want things to be the way they used to be.
Is this a problem that many people are having, or have I done something uniquely stupid to my settings?
The veracity of an election is not based upon technology, so being able to hack into a server run by a state board of election means little. An election is a system, a tightly-controlled process completely specified in legal language, with many interlocking parts and thousands of people involved. At each interface point in the process, there are cross-checks to verify accuracy. You can't "fix" an election just by cracking into some file system somewhere, you'd have to beat the entire system.
For example, in Virginia where I am a poll-worker, we have independent tallies of the number of people allowed in to vote, and the number of votes cast on the voting machines. During an election, we compare these two numbers each hour and call them into the Registrar who records them in a third system. To "stuff" the ballots in this system, you'd have to compromise three sets of records, each of which are backed up in multiple formats. The chances that you'd get away with this in the open while people are watching the election are infinitesimal.
"We receive as friendly that which agrees with, we resist with dislike that which opposes us" - Faraday
I don't think you want viral distribution of your penis and anything it gets involved with. ;)
I listen to both RIAA and non-RIAA stuff if I like the music, tangential business/politics nonwithstanding.
... where do we go to login with the posted usernames and passwords and become the next senator/governor/president of florida?
I was an Election Judge in Boulder County CO during the 2008 elections. I also worked in the county DP room where the votes were “counted.” The scanning machines were scoring “votes” based on folds in the paper. Here is more on what I found:
http://www.dansher.com/scan-dal/scan-dal03bc.html
IT IS POSSIBLE TO WIN THE VOTE BUT LOSE THE COUNT.
... tyres slash you!
Ok, no real idea why I wanted to contribute that. Must be the sheer horror of seeing "ostracised" spelled with a "z".
Abhaxas must have taken the name from Abraxas Guardian Of The Universe. It easily ranks among some of the worst movies ever mane. But I'll let other be the judge of that. Here's part one: http://www.youtube.com/watch?v=xs6yYAMpxUs
How could voters provide for themselves a true reproducible record of their own votes [ the ideas that voters votes are secret is no more anyway]. Then the voters could call for and document audits.. ..I think it is common knowledge that certain parties can match who voted for whom; so your ballot and name might as well be made public knowledge at the time of your vote.
No doubt exist in my mind exist that being elected has little to do with ballots cast under the present system.
Without Vote corruption, media propaganda, and fiat money the SENMACE would lose their grip on our society.
One way to accomplish successful ballot audits, might be to post the ballots in three places, one an electronic card which fits into a wallet, in printed form at the poll, and a printed copy of the ballot from the wallet card, such that the voter confirms it and sign it before a) the voting machine records the vote. Then have the documented ballot is mailed to the address of the voter and picked up by the voter himself (return receipt) within 10 days or the vote does not count.
i don't have the system worked out, but my point is, it should be easy to develop one. IF Americans leave vote counting to the elected, the voters will never have a system that works.
.
I think that there's a decent bit of irony in the fact that he "hacked" the voting database of the State of Florida, and then laments the ability of the United States Government to keep its data secure. Apparently while he may or may not be a decent cracker, he doesn't know the difference between state and federal government.
Other than this text, there is no discernible information contained in this sig.
I would design a voting machine as follows.
Principles:
- The machine should be such that it proofs to voter that his vote has been registered correctly.
- The machine should produce a tangible ballot for each vote casted.
- It should be impossible for anyone to find out how someone voted.
The desire of up-to-the-minute results is understandable but should be secondary to the principles above. Yet, I don't think the demands are mutually exclusive.
I can imagine a design where the voter can see his ballot, for instance behind a sheet of glass. The voter votes by pressing a button which causes a physical hole to be punched in the ballot. It should be clear to the voter how he voted from the position of the hole in the ballot. Then, the ballot should be visibly dropped in a sealed box. The voter should not be able to physically access the ballot.
The ballots are machine-countable since the holes were punched in mechanically. More importantly, the ballots can also be recounted manually if required.
My karma ran over your dogma
Some excellent documentaries and other exposes explaining this fact are free on google video (video.google.com) and youtube for those looking for the (ugly) truth. HBO produced a good documentary that is up on one of those sites.
Without well-done open-source software running these machines, manipulation and errors are guaranteed to be the rule instead of the exception, with or without voter fraud. The current systems are simply too open to error and manipulation to make them viable without independent verification, currently illegal thanks to IP (intellectual property) laws and partisan politics.
Pedantic Hat on:
Though the common stereotype is for R / L confusion with speakers of Chinese, the Chinese language (Beijing dialect for sure, Cantonese most probably, others probably too) has a clear L sound and something close to an R sound, making it very unlikely that Chinese speakers would get those two mixed up when speaking English. FWIW, I've never heard a native Chinese speaker goof those up when speaking English.
Meanwhile, Japanese has no close analogs for the English L or R sounds, the closest being what's called a "flap" sound, most commonly pronounced a bit like a Spanish R that's not trilled (like the R in pero but not in perro). Some Japanese dialects pronounce this more closely to the English L (from what I've heard, old folks in the far north), but most Japanese speakers pronounce it as a flap. Most native Japanese speakers that I've heard speaking English have trouble distinguishing the English L and R sounds at some point during the learning process.
Though probably apocryphal, there's a story from the later years of the Occupation period when rumors abounded that MacArthur would run for US President. He was quite popular in Japan, and the story goes that some public pro-MacArthur demonstration unfolded a banner reading:
We Play For MacArthur's Erection
Pedantic Hat off again. Cheers,
"What in the name of Fats Waller is that?"
"A four-foot prune."
it's still true that dead people do vote in Chicago.
I call bullshit. Do you have a citation?
George W. Bush really needed you when he was trying to find one.