Hacker Newsnew | past | comments | ask | show | jobs | submit | wtf_is_this's commentslogin

In case anyone is curious about this (as I was) here's an article: https://www.csoonline.com/article/3958808/trump-revokes-secu...


There are many reasons to question Krebs’ tenure and not all of them have to do with ignoring the state of election security, The Disinformation regime, viewpoint discrimination, or election interference.

There is a list of things


And what are they? Because unlike you, Chris has a very well known, positive, respected reputation in the industry.

Instead of just making accusations, back them up.


I’m not doxxing myself.

However many of my issues with CISA are based on my own professional work in security, and that of accomplished professors like J Halderman & M Blaze saying our election infrastructure is insecure.

We’ve been saying the same thing in hackerdom for 30 years!

If my career has been completely about the security of federal & military systems, then some lawyer like Krebs saying our infrastructure is secure when it’s running Windows 7 is a giant slap in the face, particularly given all of the censorship.

You wanted evidence. Here goes:

The censorship & viewpoint discrimination pressure CISA was bringing to bear has been over the top.

At the same time Krebs was talking about how secure our election infrastructure was, prominent professors such as Matt Blaze & J Halderman that have researched election security said the opposite.

This historically has been a bipartisan& Aceademic issue with more Dems & Repubs & Academia supporting claims of insecurity.

Those of us in security are convinced that all this unpatched windows7 usage is crazy and Chris Krebs lying about election security isn’t being open and truthful with the American people.

https://judiciary.house.gov/sites/evo-subsites/republicans-j...

- The Associated Press reported in 2019 on the use of vulnerable Windows 7 software in election systems, highlighting risks in swing states. https://www.pbs.org/newshour/politics/new-election-systems-u...

- NBC News revealed in 2020 that ES&S installed modems in voting machines, making them susceptible to hacking. [Note: The exact NBC News article from January 2020 titled "Voting Machines Vulnerable to Hacking Due to Modems" is not directly linked in the web results, but this matches the description in the thread. The full URL is not available in the provided web results, and I cannot search for it in real-time. You may need to look up the NBC News article from January 2020 for the precise link.]

- The Guardian exposed in 2015 that WinVote machines used weak passwords like "abcde," easily hackable from a distance. https://www.theguardian.com/us-news/2015/apr/15/virginia-vot...

- The New York Times reported in 2015 on a leaked database of 191 million voter records, raising concerns about phishing and identity theft. https://www.nytimes.com/2015/12/31/us/politics/voting-record...

- Wired noted in 2016 that many voting machines ran on outdated Windows XP, lacking security patches since 2014. https://www.wired.com/2016/08/americas-voting-machines-arent...

- Politico detailed in 2016 how a voting machine was hacked in minutes by replacing ROM chips with malicious firmware. https://www.politico.com/magazine/story/2016/08/2016-electio...

- CBS reported in 2016 that hackers demonstrated voting machine vulnerabilities, showing a $15 hack could alter votes. https://www.cbsnews.com/news/hacker-demonstrates-how-voting-...

- ABC News confirmed in 2016 that voting machines can be hacked, especially in close elections, with malware erasing itself post-attack. https://abcnews.go.com/Politics/hack-election-experts-russia...

- The Atlantic warned in 2016 about electronic voting risks, citing a case where a machine was turned into a Pac-Man console. https://www.theatlantic.com/technology/archive/2016/08/elect...

- FOX News covered a 2016 demonstration by a Princeton professor hacking a voting machine to shift votes undetected. https://www.foxnews.com/video/5126932108001

- Fortune reported in 2016 that Cylance researchers hacked a Sequoia AVC Edge machine, altering vote counts via a memory card. https://fortune.com/2016/11/04/voting-machine-hack-demonstra...

- Vox highlighted in 2016 that voting machines on Windows XP and voter databases online were vulnerable to hacking. https://www.vox.com/policy-and-politics/2016/11/7/134 educed/hackers-election-day-voting-machines

- PBS noted in 2016 that five states used digital voting systems without paper trails, increasing hacking risks. https://www.pbs.org/newshour/politics/heres-how-hackers-migh...

- Slate reported in 2016 that 42 states used decade-old voting machines, prone to hacking and lacking paper trails. https://slate.com/news-and-politics/2016/11/our-decrepit-vot...

- PBS revealed in 2016 that Pennsylvania's paperless machines made it impossible to verify vote tampering. https://www.pbs.org/newshour/politics/recounts-no-u-s-electi...

- Politico warned in 2016 that 15 states, including Pennsylvania, used electronic voting machines without paper trails. https://www.politico.com/story/2016/12/us-elections-hacking-...

- Scientific American stated in 2017 that voting systems could be hacked by foreign powers, advocating for paper ballots. https://www.scientificamerican.com/article/our-voting-system...

- Politico reported in 2017 on a Georgia election center's server misconfiguration, exposing voter data and passwords. https://www.politico.com/magazine/story/2017/06/14/will-the-...

- NPR cited a 2017 NSA report on Russian attempts to hack election systems, potentially targeting ballot programming. https://www.npr.org/2017/06/14/532824838/if-voting-machines-...

- HuffPost noted in 2017 that 15 states used hackable touch-screen voting machines without paper trails.

https://www.huffpost.com/entry/voting-machines-hackable_n_59...

- Senator Elizabeth Warren's 2019 article highlighted vulnerabilities like outdated voter databases and paperless machines. https://elizabethwarren.com/plans/strengthening-our-democrac...

- Senators Warren, Klobuchar, Wyden, and Pocan sent letters in 2019 to voting machine companies about security concerns. [Note: The direct link to the letters is not provided in the web results. These letters were sent to the private equity firms owning voting machine companies, as noted in the thread. You may need to search for "Warren Klobuchar Wyden Pocan voting machine letters 2019" to find the original source, possibly on a government or senator's website.]

- A 2019 compilation of media articles detailed election system vulnerabilities over four years post-2016 election.

https://www.pbs.org/newshour/amp/politics/new-election-syste...


Ending the statement with 'There is a list of things' and not providing it strongly suggests that you don't actually have any data or hard facts to back up your claims.

You are a random person on an internet forum, the onus is in you to provide data to back up incredible claims.


Ok

The censorship & viewpoint discrimination pressure CISA was bringing to bear has been over the top.

At the same time Krebs was talking about how secure our election infrastructure was, prominent professors such as Matt Blaze & J Halderman that have researched election security said the opposite.

This historically has been a bipartisan& Aceademic issue with more Dems & Repubs & Academia supporting claims of insecurity.

Those of us in security are convinced that all this unpatched windows7 usage is crazy and Chris Krebs lying about election security isn’t being open and truthful with the American people.

https://judiciary.house.gov/sites/evo-subsites/republicans-j...

- The Associated Press reported in 2019 on the use of vulnerable Windows 7 software in election systems, highlighting risks in swing states. https://www.pbs.org/newshour/politics/new-election-systems-u...

- NBC News revealed in 2020 that ES&S installed modems in voting machines, making them susceptible to hacking. [Note: The exact NBC News article from January 2020 titled "Voting Machines Vulnerable to Hacking Due to Modems" is not directly linked in the web results, but this matches the description in the thread. The full URL is not available in the provided web results, and I cannot search for it in real-time. You may need to look up the NBC News article from January 2020 for the precise link.]

- The Guardian exposed in 2015 that WinVote machines used weak passwords like "abcde," easily hackable from a distance. https://www.theguardian.com/us-news/2015/apr/15/virginia-vot...

- The New York Times reported in 2015 on a leaked database of 191 million voter records, raising concerns about phishing and identity theft. https://www.nytimes.com/2015/12/31/us/politics/voting-record...

- Wired noted in 2016 that many voting machines ran on outdated Windows XP, lacking security patches since 2014. https://www.wired.com/2016/08/americas-voting-machines-arent...

- Politico detailed in 2016 how a voting machine was hacked in minutes by replacing ROM chips with malicious firmware. https://www.politico.com/magazine/story/2016/08/2016-electio...

- CBS reported in 2016 that hackers demonstrated voting machine vulnerabilities, showing a $15 hack could alter votes. https://www.cbsnews.com/news/hacker-demonstrates-how-voting-...

- ABC News confirmed in 2016 that voting machines can be hacked, especially in close elections, with malware erasing itself post-attack. https://abcnews.go.com/Politics/hack-election-experts-russia...

- The Atlantic warned in 2016 about electronic voting risks, citing a case where a machine was turned into a Pac-Man console. https://www.theatlantic.com/technology/archive/2016/08/elect...

- FOX News covered a 2016 demonstration by a Princeton professor hacking a voting machine to shift votes undetected. https://www.foxnews.com/video/5126932108001

- Fortune reported in 2016 that Cylance researchers hacked a Sequoia AVC Edge machine, altering vote counts via a memory card. https://fortune.com/2016/11/04/voting-machine-hack-demonstra...

- Vox highlighted in 2016 that voting machines on Windows XP and voter databases online were vulnerable to hacking. https://www.vox.com/policy-and-politics/2016/11/7/134 educed/hackers-election-day-voting-machines

- PBS noted in 2016 that five states used digital voting systems without paper trails, increasing hacking risks. https://www.pbs.org/newshour/politics/heres-how-hackers-migh...

- Slate reported in 2016 that 42 states used decade-old voting machines, prone to hacking and lacking paper trails. https://slate.com/news-and-politics/2016/11/our-decrepit-vot...

- PBS revealed in 2016 that Pennsylvania's paperless machines made it impossible to verify vote tampering. https://www.pbs.org/newshour/politics/recounts-no-u-s-electi...

- Politico warned in 2016 that 15 states, including Pennsylvania, used electronic voting machines without paper trails. https://www.politico.com/story/2016/12/us-elections-hacking-...

- Scientific American stated in 2017 that voting systems could be hacked by foreign powers, advocating for paper ballots. https://www.scientificamerican.com/article/our-voting-system...

- Politico reported in 2017 on a Georgia election center's server misconfiguration, exposing voter data and passwords. https://www.politico.com/magazine/story/2017/06/14/will-the-...

- NPR cited a 2017 NSA report on Russian attempts to hack election systems, potentially targeting ballot programming. https://www.npr.org/2017/06/14/532824838/if-voting-machines-...

- HuffPost noted in 2017 that 15 states used hackable touch-screen voting machines without paper trails.

https://www.huffpost.com/entry/voting-machines-hackable_n_59...

- Senator Elizabeth Warren's 2019 article highlighted vulnerabilities like outdated voter databases and paperless machines. https://elizabethwarren.com/plans/strengthening-our-democrac...

- Senators Warren, Klobuchar, Wyden, and Pocan sent letters in 2019 to voting machine companies about security concerns. [Note: The direct link to the letters is not provided in the web results. These letters were sent to the private equity firms owning voting machine companies, as noted in the thread. You may need to search for "Warren Klobuchar Wyden Pocan voting machine letters 2019" to find the original source, possibly on a government or senator's website.]

- A 2019 compilation of media articles detailed election system vulnerabilities over four years post-2016 election.

https://www.pbs.org/newshour/amp/politics/new-election-syste...


Anyone know why the (only?) picture is in black and white? It seems taking one with color wouldn't be any more difficult...


Most likely the picture was taken with a monochrome sensor with a filter applied tuned to a specific wavelength. That's more valuable than a color filter, which is made up of a mosaic of single pixel individual red, green and blue filters, interpolated to produce a RGB image.


I think it is a color photo, just it’s just everything I’m pretty much is grey I think. If you look closely in some parts there’s a tiny bit of color.


Yup. I just grabbed it and pinned the saturation, and you can see that the circular grills around the edge of the head are copper-colored.


Couldn't agree more with this comment. I've had exactly the same frustration trying to get cameras months/years apart that will work. You have to open each one up and hack it yourself (and OpenIPC may support it or not), and nowadays they are protected from loading firmware easily (tiny UART/debug ports, disabled UBoot loader, etc.).

I also wish there were an option for someone to buy cameras with open HW/SW, to get away from the random cloud services they want you to open your network up to with cheap cameras.


Not just that; I'd be OK with closed source firmware if I can just put it on an isolated network and be done with it, but from typical listings on Amazon et al you cannot even tell if the camera works without a mandatory cloud connection.

I've bought a router from TPlink a while ago that wanted me to install a fucking app, create a TPlink account and send all comms over some cloud servers to configure a router that's sitting right next to me, that all the traffic from the very fucking phone is going through. It did have a classic web interface, but it was completely crippled and basically just allowed changing the Wifi SSID and doing a firmware update. There was nothing in the product description about this, and none of the customer reviews mentioned it, because obviously this shit is now completely normal to the average joe.


Has anyone else had Garnter emails start spamming them? Somehow they got my email address about a week ago and now I get one+ email a day.

Their unsubscribe process is ridiculous (illegal?). First you have to re-enter your email address (it should be included in the unsubscribe link in the email, right?) then you have to _solve a captcha_ just to hit submit on your unsubscribe request. Finally, for me at least, this goes to a "page loading" gif which never actually loads (there may be some ad-blocking stuff interfering with requests or something, I still have to check, but GOD DAMN).

I don't know the rules about unsubscribing from lists you never subscribed to, but they seemingly make it impossible to actually unsubscribe unless you are very determined. Yes, I can redirect to spam pretty easily, but I hate this shit.


I didn't see this as an answer, but use Tor (: It has the side benefit that it's harder to discover your service(s) on the wider Internet.


Good suggestion! I used this in 2014. Blog post about it: https://lucb1e.com/?p=post&id=120 (Btw, I no longer vouch for the quality or correctness of an 8-year-old post of mine.) I remember that the latency wasn't amazing or anything, but I apparently found it acceptable enough to use it for SSH.


Well, DUH.

Edit: saw this has already been posted, which made me say "duh" again.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: