News: 0175363997

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Colorado Agency 'Improperly' Posted Passwords for Its Election System Online (gizmodo.com)

(Wednesday October 30, 2024 @11:30PM (BeauHD) from the not-a-good-look dept.)


For months, the Colorado Department of State [1]inadvertently exposed partial passwords for voting machines in a public spreadsheet . "While the incident is embarrassing and already fueling accusations from the state's Republican party, the department said in [2]a statement that it 'does not pose an immediate security threat to Colorado's elections, nor will it impact how ballots are counted,'" reports Gizmodo. From the report:

> Colorado NBC affiliate station 9NEWS [3]reported that Hope Scheppelman, vice chair of the state's Republican party, revealed the error in a mass email sent Tuesday morning, which included an affidavit from a person who claimed to have downloaded the spreadsheet and discovered the passwords by clicking a button to reveal hidden tabs.

>

> In its statement, the Department of State said that there are two unique passwords for each of its voting machines, which are stored in separate places. Additionally, the passwords can only be used by a person who is physically operating the system and voting machines are stored in secure areas that require ID badges to access and are under 24/7 video surveillance.

>

> "The Department took immediate action as soon as it was aware of this, and informed the Cybersecurity and Infrastructure Security Agency, which closely monitors and protects the [country's] essential security infrastructure," The department said, adding that it is "working to remedy this situation where necessary." Colorado voters use paper ballots, ensuring that a physical paper trail that can be used to verify results tabulated electronically.



[1] https://gizmodo.com/colorado-agency-improperly-posted-passwords-for-its-election-system-online-2000518572

[2] https://www.coloradosos.gov/pubs/newsRoom/pressReleases/2024/PR20241029Passwords.html

[3] https://www.9news.com/article/news/politics/elections/colorado-secretary-of-state-posted-voting-system-passwords/73-c9264216-7a0a-4d5b-9f64-60a28eb57e4d



Re:What's going on in Michigan? (Score:5, Informative)

by illaqueate ( 416118 )

five seconds of search revealed the "expert" "is awaiting trial on felony charges related to allegedly breaching election machines". maybe not the best source of information. i recall pjmedia also posted loads of bogus election denial content in 2020

improperly? (Score:5, Funny)

by Local ID10T ( 790134 )

Is there a proper way to post your passwords list on your website?

Re: (Score:2)

by ls671 ( 1122017 )

> Is there a proper way to post your passwords list on your website?

Voting machines with passwords are scary. Just use public key auth so no passwords need to be transmitted at all and every authorized person or system can easily be tracked when they access the system even if they use a single account.

Re: (Score:2)

by 93 Escort Wagon ( 326346 )

Voting machines that are connected directly to the internet are scary...

Re: (Score:2)

by XXongo ( 3986865 )

> Voting machines that are connected directly to the internet are scary...

The summary says

> the passwords can only be used by a person who is physically operating the system and voting machines are stored in secure areas that require ID badges to access and are under 24/7 video surveillance

so apparently the machines are not connected to the internet,

Re: (Score:2)

by Malay2bowman ( 10422660 )

Putting ballot boxes out on the street is also scary -

https://www.cnn.com/2024/10/29/us/ballot-box-fires-what-we-know/index.html

Re: (Score:1)

by 93 Escort Wagon ( 326346 )

> Is there a proper way to post your passwords list on your website?

A properly configured web server should automatically identify and replace passwords with stars/asterisks. Here, I'll try it with some of my server passwords...

admin: *********************

operator: *************

monitor: ***********

Yup, the "preview" indicates it's working properly, so I can safely post this. Go ahead and give it a try!

Re: improperly? (Score:2)

by samwichse ( 1056268 )

hunter2

Re: improperly? (Score:2)

by samwichse ( 1056268 )

Doesn't look like stars to me.

Re: (Score:2)

by 93 Escort Wagon ( 326346 )

That's because you're viewing your own post - I should have mentioned you have to check with a different browser where you aren't logged in.

Here's what I see when I look at your post:

> Re: improperly? (Score:2)

> by samwichse ( 1056268 ) Alter Relationship on Wednesday October 30, 2024 @07:21PM (#64907953)

> *******

> Reply to This Parent Share

Re: (Score:3)

by sinij ( 911942 )

Exposing passwords is a good thing if your goal is to find an infosec professional to scapegoat actual security breaches on. Because if you find "the guy", nobody will be looking at anything that happened prior to that.

Re: (Score:2)

by gosso920 ( 6330142 )

"iNaDvErTeNtLy"

Re: (Score:2)

by chuckugly ( 2030942 )

Speech to text not your friend?

Re:How quaint (Score:4, Informative)

by quonset ( 4839537 )

It was this sort of stuff that Trump was whining about in 2020.

No, he was whining that millions of illegals voted, that Georgia [1]needed to "find" 11,780 votes [cnn.com] after lying about ballots being counted multiple times or how a fake video from Lyin Rudy showed ballot stuffing or lies about ballots being destroyed, how there were tens of thousands of people across the country [2]who voted [cnn.com] [3]while dead [bbc.com], except for all those [4]Republicans [foxnews.com] who [5]cast votes [msnbc.com] for [6]dead people [msnbc.com], and he was whining in general just because he lost. Every single lie he came up with was either shot down or he showed no proof when given the opportunity. In fact, when multiple attorneys were asked during "fraud" trials whether they were saying they had evidence for vote fraud, [7]every single one said no [time.com].

While this incident will certainly bring about more whining from the petulant 4 year old, even if it hadn't happened, he'd still whine when he loses again.

[1] https://www.cnn.com/2021/01/03/politics/trump-brad-raffensperger-phone-call-transcript/index.html

[2] https://www.cnn.com/2020/11/08/tech/michigan-dead-voter-fact-debunking/index.html

[3] https://www.bbc.com/news/election-us-2020-54874120

[4] https://www.foxnews.com/politics/pennsylvania-voter-fraud-republican-felony-charges-casting-ballot-for-dead-mother

[5] https://www.msnbc.com/rachel-maddow-show/maddowblog/another-gop-voter-caught-casting-ballot-dead-relative-n1276965

[6] https://www.msnbc.com/rachel-maddow-show/maddowblog/gop-voter-gets-light-sentence-after-casting-ballot-deceased-wife-n1284011

[7] https://time.com/5914377/donald-trump-no-evidence-fraud/

Re: (Score:2)

by Pascoea ( 968200 )

What do you mean? He was just on Joe Rogan earlier this week, he said he had tons of proof the 2020 election was stolen from him. He's just waiting for the right time to release it I guess.

Re:How quaint (Score:4, Informative)

by 93 Escort Wagon ( 326346 )

> It was this sort of stuff that Trump was whining about in 2020. And... it was dismissed out of hand in the firm belief that this sort of stuff had. It happened and could not happen. As in, it waits Jen seriously. Audits were token at best.

Remember the [1]Maricopa County Audit in 2020 [wikipedia.org]? The one paid for by Arizona Republicans and One America News and was headed by a GOP-picked Trump-favoring conspiracy theorist? That took six months - and, in the end, it found no proof of any fraud - and even gave Biden 360 more votes!

Trump's whining got "dismissed out of hand" because he and his team couldn't even convince Trump-appointed judges that there was any evidence of fraud. In one of those, when pressed under oath, Giuliani stated "this is not a voting fraud case".

People dismissed all that crap because there was nothing there but bullshit and hot air .

[1] https://en.wikipedia.org/wiki/2021_Maricopa_County_presidential_ballot_audit

Re: (Score:2)

by ArchieBunker ( 132337 )

Every single lawsuit was dismissed, some even by Trump appointed federalist society judges.

Giuliani: Your honor I have a signed affidavit.

Judge: Alright, do you have evidence to corroborate these affidavits?

Giuliani: SIGNED AFFIDAVIT...

Judge: Yes but I need some sort of evidence here.

Giuliani: SIGNED AFFIDAVIT...

Judge: Case dismissed.

And to the surprise of everyone except Giuliani, Trump stiffed him. [1]https://news.bloomberglaw.com/... [bloomberglaw.com]

[1] https://news.bloomberglaw.com/bankruptcy-law/giuliani-says-trump-campaign-rnc-owe-him-2-million-in-fees

Why do voting machines need passwords? (Score:2)

by Mirnotoriety ( 10462951 )

a. Who made these voting machines?

b. Do they in fact provide a paper-trail?

Re: (Score:2)

by Firethorn ( 177587 )

The ballots themselves are paper. Nothing stopping a hand count of them all if necessary.

How very unfortunate (Score:2)

by haxor.dk ( 463614 )

... considering that this election is said to be the most important in recent American history.

Standardize on paper ballots or analogue machines only. None of this electronic bs. It's simply too untrustworthy on several fronts.

Re: (Score:2)

by Valgrus Thunderaxe ( 8769977 )

... considering that this election is said to be the most important in recent American history.

I can't recall an election where this was NOT said. Can you?

Re: (Score:3)

by quonset ( 4839537 )

> ... considering that this election is said to be the most important in recent American history.

> Standardize on paper ballots or analogue machines only. None of this electronic bs. It's simply too untrustworthy on several fronts.

We have paper ballots which are scanned and then held in case there are issues. A handcount can be done to verify vote totals. The best of both worlds.

Re: (Score:2)

by Malay2bowman ( 10422660 )

"analogue machines"

Wow, this brings back memories of those huge 1950s era metal cabinets on rollers stored in my elementary school's gymnasium which was designated a voting site.. And I remember the teacher scaring us by saying that if we did so much as touch those maxhines we would go to jail.

"Partial Passwords" (Score:2)

by Petersko ( 564140 )

While it's not a good look no matter what, I'd like to know what a "Partial Password" looks like.

LGhn644$| with unknown length is not actually that concerning.

Re: (Score:2)

by Entrope ( 68843 )

"Partial" was a very misleading word choice. These were (I *hope* that's the correct tense) BIOS passwords, meaning another password was required to boot into the normal application. Presumably, the BIOS password would be sufficient to boot from a thumb drive or similar device that has a fake or altered voting machine application.

[1]https://www.wqad.com/article/n... [wqad.com]

[1] https://www.wqad.com/article/news/politics/elections/colorado-secretary-of-state-posted-voting-system-passwords/73-c9264216-7a0a-4d5b-9f64-60a28eb57e4d

Kamala is your Karma (Score:1)

by NewID_of_Ami.One ( 9578152 )

When you have agencies that have become experts at toppling governments in foreign nations and supporting or installing toxic opposition parties with stupid pro US puppet leaders in power, it is inevitable that these agencies finally do the same in their own country and install puppet leaders via the same tactics of massive misinformation and misleading the population, turning them against each other, funding unrest via courts, institutions and violent protests and installing Biden & Kamala type blatant

modem, adj.:
Up-to-date, new-fangled, as in "Thoroughly Modem Millie." An
unfortunate byproduct of kerning.

[That's sic!]