Page 17 of 67 FirstFirst ... 713141516171819202127 ... LastLast
Results 401 to 425 of 1658
  1. #401
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    the investigation Brian Kemp just opened is based on vulnerabilities in the state election system pointed out by Democratic officials, to security experts:

    From the reporting, it appears that the vulnerability is the kind of mistake that was common on the web two decades ago, that once you've logged in you can access anyone else's content just by changing the URL. Basically anyone with any degree of knowledge of online security learned to block such a vulnerability at least a decade or more ago. It is astounding that such a vulnerability might still exist online, let alone on something as vital and key to democracy as a state election system.


    It appears that this is the basis of Kemp's new investigation.
    https://www.techdirt.com/articles/20...n-system.shtml


  2. #402
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    A later story on WhoWhatWhy details that it wasn't the Democratic Party who had discovered the vulnerability in the first place, but rather someone else, who then contacted a lawyer for someone already suing Kemp over weaknesses in Georgia's election system:

    A man who claims to be a Georgia resident said he stumbled upon files in his My Voter Page on the secretary of state’s website. He realized the files were accessible. That man then reached out to one of Cross’s clients, who then put the source and Cross in touch on Friday.

    The next morning, Cross called John Salter, a lawyer who represents Kemp and the secretary of state’s office. Cross also notified the FBI.

    As noted above, WhoWhatWhy reached out to multiple security experts who all confirmed the vulnerability -- and apparently all five of them noted that actually testing the vulnerability would be illegal. But all five of them were able to just look at the code on the site and confirm the vulnerability was real and could be used to alter voter information in the rolls, which is an especially big deal considering that one of Kemp's voter suppression methods was to insist that if any tiny bit of your information did not match what was in the rollbook, you couldn't vote.

    The report further notes that the security researchers approached by WhoWhatWhy reached out to both US intelligence officials and the Coalition for Good Government, who also reached out to Kemp's own lawyers to alert him to the problems in the system:

    Bruce Brown, a lawyer for the group, then reached out to Kemp’s attorneys to alert them of the problem. At 7:03 PM Saturday night, he emailed John Salter and Roy Barnes, former governor of Georgia, in their capacities as counsel to Secretary of State Kemp, to notify them of the serious potential cyber vulnerability in the registration files that had been discovered without any hacking at all, and that national intelligence officials had already been notified.
    [....]

    “What is particularly outrageous about this, is that I gave this information in confidence to Kemp’s lawyers so that something could be done about it without exposing the vulnerability to the public,” Brown told WhoWhatWhy. “Putting his own political agenda over the security of the election, Kemp is ignoring his responsibility to the people of Georgia.”

  3. #403
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    The first vulnerability identified in the email is on the My Voter Page, where voters can check their registration, the status of their mail-in or provisional ballots, or change their voter information. After following a commonly used link, one arrives at a page that is not secure. To view any file on the server that runs the My Voter Page nothing more is needed than typing any file name into the web browser, the experts said.

    In addition to do ents, files include things like network configuration files, cryptographic keys, and possibly even code that could be used to break into the server.

    Because it would be illegal to explore what is available on the site, the extent of the vulnerability is still not known.

    “Holy ,” Duncan Buell told WhoWhatWhy when he logged onto the website. “Presumably, you could just hit the backspace button on the file, put in a new file name, and it would let you download that.”

    Even if someone didn’t know the name of the do ent they were trying to access, they could instead find it by writing a code to probe the My Voter Page, said Buell, a computer science professor at the University of South Carolina and elections and voting technology expert.
    https://whowhatwhy.org/2018/11/04/ke...curity-crisis/

  4. #404
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    The second vulnerability described in the email is found in the state’s online voter registration system.

    In the code of the website — which anybody can access using their internet browser — there is a series of numbers that represent voters in a county. By changing a number in the web browser’s interface and then changing the county, it appears that anybody could download every single Georgia voter’s personally identifiable information and possibly modify voter data en masse.

    In addition, voter history, absentee voting, and early voting data are all public record on the secretary of state’s website. If a bad actor wanted to target a certain voting group, all of the information needed is available for download.

    “It’s so juvenile from an information security perspective that it’s crazy this is part of a live system,” Constable said.
    same article

  5. #405
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    What’s more, there don’t seem to be any security measures that could detect these changes or trace them back to a source, according to several of the experts.


    Worse yet, a bad actor could easily pretend to be someone else, according to Constable. “In theory you could copy and paste that session ID or cookie — that unique string — and put it in your browser to emulate that person,” Constable said. “So not only could you access that person’s information and act as that person, you could then make changes under that person’s iden y.”

  6. #406
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    essentially, Brian Kemp is investigating Georgia Democrats for pointing out egregious vulnerabilities in the elections system he oversees.

  7. #407
    Veteran
    My Team
    San Antonio Spurs
    Join Date
    Mar 2009
    Post Count
    97,536
    red/slave state Repugs, Dedicated Guardians of the Mythical, Sacred Right To Vote

  8. #408
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    pattern of incompetence:

    If the assessment of these vulnerabilities is accurate, it would be the fourth time in as many years that the private information of every voter in Georgia, as well as other information related to voting, has been exposed.


    In 2015, an employee at the secretary of state’s office sent out personally identifiable information to 12 news media and political party organizations.
    In August, 2016, computer researcher Logan Lamb, formerly of Oak Ridge National Laboratory, was able to access Georgia’s entire voter registration database, including all personally identifiable information. The system was not password protected and was vulnerable to being rewritten. He notified the state of the problem.
    Then in February, 2017, Christopher Grayson — a Los Angeles-based security engineer — and Lamb found that the problem had not been fixed and that the same information was still unprotected.

  9. #409
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927

  10. #410
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    during the same period, 637 people in the US were killed by lightning strikes

  11. #411
    Veteran
    My Team
    San Antonio Spurs
    Join Date
    Mar 2009
    Post Count
    97,536
    Georgia Officials Quietly Patched Security Holes They Said Didn’t Exist

    the state was busily fixing problems in its voter registration

    hours after the office of Secretary of State Brian Kemp, the Republican candidate for governor,

    had insisted the system was secure.

    in the evening hours of Sunday, as the political storm raged, ProPublica found state officials quietly rewriting the website’s computer code.

    https://talkingpointsmemo.com/news/g...+%28TPMNews%29

  12. #412
    4-25-20 Will Hunting's Avatar
    My Team
    Boston Celtics
    Join Date
    Jun 2009
    Post Count
    22,468
    Arizona GOP now suing to stop 600,000 of mail in ballots from being counted.

    Why is it that the GOP is always trying to limit the amount of votes that matter?

  13. #413
    Veteran
    My Team
    San Antonio Spurs
    Join Date
    Mar 2009
    Post Count
    97,536
    Arizona GOP now suing to stop 600,000 of mail in ballots from being counted.

    Why is it that the GOP is always trying to limit the amount of votes that matter?
    "About 75 percent of Arizona voters cast ballots by mail,"

    so AZ Repugs want to disenfranchise, for this race, 75% of the voters?


  14. #414
    俺はまんこが大好きなんだよ baseline bum's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Mar 2003
    Post Count
    97,881
    Arizona GOP now suing to stop 600,000 of mail in ballots from being counted.

    Why is it that the GOP is always trying to limit the amount of votes that matter?
    Because they're from blue districts duh

  15. #415
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    Arizona GOP now suing to stop 600,000 of mail in ballots from being counted.

    Why is it that the GOP is always trying to limit the amount of votes that matter?
    sue to stop the counting while you're ahead.

    worked for GWB.

  16. #416
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    Only 147 votes, still, 100% illegal.

  17. #417
    6X ST MVP
    My Team
    San Antonio Spurs
    Join Date
    Jul 2015
    Post Count
    81,091
    Arizona GOP now suing to stop 600,000 of mail in ballots from being counted.

    Why is it that the GOP is always trying to limit the amount of votes that matter?
    That's a load of illegal alien votes right there, tbh.

  18. #418

  19. #419
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    That's a load of illegal alien votes right there, tbh.
    how did you reach this conclusion?

    did your spidey sense tingle?

  20. #420
    6X ST MVP
    My Team
    San Antonio Spurs
    Join Date
    Jul 2015
    Post Count
    81,091
    Yeah, I guess I haven’t watched the youtube videos that you depend on to give you an opinion.
    You don't know the glaring difference between me and ducks and chris. Not a big deal other than it makes you look a bit thick for habitually mentioning me with them.

  21. #421
    6X ST MVP
    My Team
    San Antonio Spurs
    Join Date
    Jul 2015
    Post Count
    81,091
    how did you reach this conclusion?

    did your spidey sense tingle?
    How did you not reach that conclusion? That's rhetorical. We all know it's a matter of convenience for you.

  22. #422
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    How did you not reach that conclusion?
    read these and explain how mail in ballots ended up in the hands of ineligible voters.

    did the Republican AZ Secretary of State send mail in ballots to 600,000 illegal aliens?

    https://www.fvap.gov/uploads/FVAP/Forms/fpca.pdf

    https://apps.azsos.gov/apps/election...terVoter1.aspx

  23. #423
    6X ST MVP
    My Team
    San Antonio Spurs
    Join Date
    Jul 2015
    Post Count
    81,091
    read these and explain how mail in ballots ended up in the hands of ineligible voters.

    did the Republican AZ Secretary of State send mail in ballots to 600,000 illegal aliens?

    https://www.fvap.gov/uploads/FVAP/Forms/fpca.pdf

    https://apps.azsos.gov/apps/election...terVoter1.aspx
    Were you under the impression that I don't know the law?

    That you look up such boring links for nothing. That takes a special kind of person I think.

  24. #424
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    you cited the volume of mail in ballots as being evidence illegal aliens voted. I'm curious to know how you think that happened.

    do you think Mic e Reagan sent mail in ballots to illegal aliens?

  25. #425
    dangerous floater Winehole23's Avatar
    My Team
    San Antonio Spurs
    Join Date
    Nov 2008
    Post Count
    113,927
    Were you under the impression that I don't know the law?
    Yep

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •