6 ms·
Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other op
by cushpush 2y ago
Uh oh. Ignorance of computing showing. IF they need two passwords to combine to make one, but sometimes have one of them, they just need to brute the other open... I think it's a bigger problem than the administration understands, unless the passwords are for something inert like wattage delivered to the machine.
- EasyMark 2y agothese machines aren't hooked up to the internet, how are you going to brute force every machine that a community uses and also requires physical proximity?
- cushpush 2y agoAre the machines physically incapable of internet?
- leereeves 2y agoCan you brute force a BIOS password without prolonged physical access? The leak does increase the risk of a single trusted insider messing with the system, though.
- jeroenhd 2y agoI personally don't put much trust in the security of BIOS vendors. My desktop's motherboard straight up displays the BIOS password if you read the right EFI boot variable (obfuscated with some proprietary "encryption" algorithm with a hard coded key). Based on previous reports on the security of devices like these, I wouldn't be surprised if a quick flash dump of the NVRAM is enough to crack the password in seconds already. Perhaps voting machine manufacturers have finally made it too difficult to disassemble these machines in a short amount of time, but that's historically not been very difficult. I would reckon the access time needed to hack+access the BIOS lies in the area of "a few minutes, twice", not the kind of prolonged physical access you'd need to brute force the password. That's not exactly "someone posing as a voter could hack the machine", luckily, but then again apparently at least one hacker at DEF CON found a vulnerability in voting machines this year that won't be fixed before the upcoming American elections, so who knows if there's an exploit like that lying around.
- cushpush 2y agoEvery vote counts. The problem is that some votes are counted twice.
- cushpush 2y ago"Can you without prolonged access?" Hahaha have you heard of any of the three letter agencies and what they have on hand? Do you know what a rainbow table is? Is this a tech forum, or just newbies trolling experts?
- leereeves 2y agoI guess I wasn't clear. I'm asking you to describe exactly what scenario you're imagining. You can't simply assume the attacker already has the bios password hash. How do they get that? And if they can get that, why do they still need to brute force the bios password? Why can't they do what they need to do already? Do you know of a vulnerability that allows someone to access the bios password hash but can't also be used to hack the election without bothering with the bios password?