d2jsp
Log InRegister
d2jsp Forums > Off-Topic > General Chat > Political & Religious Debate > November 2018 > Elections
Prev11516171819120Next
Add Reply New Topic New Poll
Member
Posts: 105,123
Joined: Apr 25 2006
Gold: 10,475.00
Aug 10 2018 05:14am
Quote (Black XistenZ @ Aug 10 2018 06:40am)
yeah, and the vote tallies for the state are the sum of dozens if not hundreds of precincts/polling stations.




Dude, it's 2018. We put men on the moon in the 60's. You're saying we can count tom 522? :)
Member
Posts: 105,123
Joined: Apr 25 2006
Gold: 10,475.00
Aug 10 2018 08:40am


Kobach to recuse himself from Kansas governor's race recount

https://www.reuters.com/article/us-usa-election-kansas/kobach-to-recuse-himself-from-kansas-governors-race-recount-idUSKBN1KV1GY

Quote
(Reuters) - Kris Kobach, the Republican candidate endorsed by U.S. President Donald Trump in the Kansas governor’s race, said he plans to recuse himself from the vote recount after a correction in the total cut his lead to just 91 votes.
Member
Posts: 5,942
Joined: Apr 29 2018
Gold: Locked
Trader: Scammer
Warn: 10%
Aug 13 2018 12:06pm
Kasich subtly trolls trump lol:

https://twitter.com/JohnKasich/status/1029033017602465792

Member
Posts: 105,123
Joined: Apr 25 2006
Gold: 10,475.00
Aug 15 2018 04:07am


Boy, 11, hacks into replica U.S. vote website in minutes at convention

https://www.reuters.com/article/us-usa-election-cyber/boy-11-hacks-into-replica-u-s-vote-website-in-minutes-at-convention-idUSKBN1KZ0O2

Quote
(Reuters) - An 11-year-old boy managed to hack into a replica of Florida’s election results website in 10 minutes and change names and tallies during a hackers convention, organizers said, stoking concerns about security ahead of nationwide votes.



SEE! Now we know, even democrats could hack the elections. Russians, Russians, we don't need no stinking Russians.
Member
Posts: 54,061
Joined: May 26 2005
Gold: 4,945.67
Aug 15 2018 04:10am
Quote (Ghot @ 15 Aug 2018 12:07)
Boy, 11, hacks into replica U.S. vote website in minutes at convention

https://www.reuters.com/article/us-usa-election-cyber/boy-11-hacks-into-replica-u-s-vote-website-in-minutes-at-convention-idUSKBN1KZ0O2




SEE! Now we know, even democrats could hack the elections. Russians, Russians, we don't need no stinking Russians.


the boy probably already has a job offer from the NSA for the day he turns 18.
Member
Posts: 105,123
Joined: Apr 25 2006
Gold: 10,475.00
Aug 15 2018 04:17am
Quote (Black XistenZ @ Aug 15 2018 06:10am)
the boy probably already has a job offer from the NSA for the day he turns 18.




Hell, the NSA doesn't have to wait till he's 18. :D
Member
Posts: 14,099
Joined: Jul 13 2006
Gold: 83.30
Aug 15 2018 04:40am
Quote (Black XistenZ @ Aug 15 2018 10:10am)
the boy probably already has a job offer from the NSA for the day he turns 18.


Not really.



The big thing to learn from this is that SQL injection is both incredibly easy to do, and one of the first things even low level sysadmins get taught about security. SQL injection is quite simply the first step any hacker will take. What you try to do is just feed code into the website (usually in fields like search boxes or personal information).

An example of horrid Java:

Code
String query = "SELECT account_balance FROM user_data WHERE user_name = "
+ request.getParameter("customerName");

try {
Statement statement = connection.createStatement( … );
ResultSet results = statement.executeQuery( query );
}

query gets executed, and query has the "customerName" parameter as an unsanitized input. If someone inputs code into that field, it will just execute.

A more safe approach is seen below. custname is retrieved from the field, and is defined as a string variable. In this case the database would just try to find whatever matches the input in the database instead of executing code.

Code
String custname = request.getParameter("customerName"); // This should REALLY be validated too
// perform input validation to detect attacks
String query = "SELECT account_balance FROM user_data WHERE user_name = ? ";

PreparedStatement pstmt = connection.prepareStatement( query );
pstmt.setString( 1, custname);
ResultSet results = pstmt.executeQuery( );


However, vote tally counting websites I would not count as extremely vulnerable. The other hacks at Defcon that managed to gain access to the voting machines however, I do count as extremely vulnerable. Regardless of who you support, electronic voting is a mistake and will stay a mistake. There is no safe way. Paper ballots are the best at risk averting as you have to influence multiple people instead of just one firmware flaw. For fuck's sake, these machines are even connected via Wifi, which makes remote attacks a huge possibility.

-edit: I'll just add that there should be no way that government websites are still vulnerable to SQL injection. However, (local) governments are notoriously slow in adapting and changing. I've heard of local governments here who until recently had citizen data stored in plain text (on an offline machine, but still). There is a lot of ground to gain in security, especially for governments.

This post was edited by balrog66 on Aug 15 2018 04:42am
Member
Posts: 54,061
Joined: May 26 2005
Gold: 4,945.67
Aug 15 2018 05:23am
Quote (balrog66 @ 15 Aug 2018 12:40)
Regardless of who you support, electronic voting is a mistake and will stay a mistake. There is no safe way. Paper ballots are the best at risk averting as you have to influence multiple people instead of just one firmware flaw. For fuck's sake, these machines are even connected via Wifi, which makes remote attacks a huge possibility.

vouch.
Member
Posts: 12,379
Joined: Jul 14 2008
Gold: 2,620.00
Aug 15 2018 11:40am
"Democrats, please do not distance yourselves from Nancy Pelosi. She is a wonderful person whose ideas & policies may be bad, but who should definitely be given a 4th chance. She is trying very hard & has every right to take down the Democrat Party if she has veered too far left!" DJT on Twitter

Already been posted before in another thread but holy shit.

"Happy Birthday to the leader of the Democrat Party, Maxine Waters!" DJT on Twitter

Gotta hand it to Trump on this one. Trump's trolling efforts are only as effective as the Democratic party is ineffective.
Member
Posts: 54,061
Joined: May 26 2005
Gold: 4,945.67
Aug 15 2018 11:50am
Quote (ThatAlex @ 15 Aug 2018 19:40)
"Democrats, please do not distance yourselves from Nancy Pelosi. She is a wonderful person whose ideas & policies may be bad, but who should definitely be given a 4th chance. She is trying very hard & has every right to take down the Democrat Party if she has veered too far left!" DJT on Twitter

Already been posted before in another thread but holy shit.

"Happy Birthday to the leader of the Democrat Party, Maxine Waters!" DJT on Twitter

Gotta hand it to Trump on this one. Trump's trolling efforts are only as effective as the Democratic party is ineffective.


He's one of the greatest trolls of our time.
Go Back To Political & Religious Debate Topic List
Prev11516171819120Next
Add Reply New Topic New Poll