Electronic voting infrastructure in the United States is a critical national security failure. The current systems act as “black boxes” that cannot prove their own correctness. Rather than a series of unrelated defects, the vulnerabilities identified form a single, escalating structure where information collection enables manipulation, and the absence of forensic evidence is a design feature.
An Unnecessary National Security Risk
The Case Against Electronic Voting Systems
This approach prioritizes verifiability over convenience, aligning with the practices of approximately 80% of countries in international surveys that do not use electronic voting due to concerns over security and trust.
Download Full AnalysisThis analysis identifies five primary areas of concern:
- Area A (Intelligence Platform): The integration of registration, pollbook, and tabulation systems allows for the real-time collection of data necessary to plan election manipulation.
- Area B (Ballot Ordering): Systems are designed to produce ballots on demand, creating a mechanism to fill gaps between actual and desired counts.
- Area C (Direct Manipulation): Documented vulnerabilities allow for the installation of malicious code and the manipulation of tallies at the tabulator level.
- Area D (Interoperability and AI): Standardized, unpatchable interface layers create a systemic surface for automated attacks.
- Area E (Lack of Transparency): The lack of independent auditability and the destruction of forensic records ensure that results can neither be confirmed nor refuted.
Area of Concern A: Intelligence Platform
The current election enterprise aggregates sensitive data—who is registered, who has voted, and on which machine—into a single data chain.
- System Integration: In Michigan, every certified voting system (Dominion, ES&S, Hart InterCivic) is required to interface with the statewide Qualified Voter File (QVF). This creates a direct data path from the registration database to the tabulation software.
- CISA Confirmed Vulnerabilities: CISA advisory ICSA-22-154-01 confirmed nine distinct vulnerabilities in the Dominion ImageCast X, including:
- CVE-2022-1739: Ability to install malicious code via removable media.
- CVE-2022-1746: Exposure of cryptographic secrets from poll-worker cards.
- CVE-2022-1747: Ability to “print an arbitrary number of ballots without authorization.”
- Postural Weakness: A 2021 CISA internal assessment (TLP:AMBER) found that 48% of assessed election entities had critical or high-severity vulnerabilities on internet-accessible hosts, and 34% were running unsupported operating systems (Windows 7, Vista, XP).
- Information Exposure: NIST published the file-level manifest of a certified voting system on a public S3 bucket, including SHA-1 and MD5 hashes, providing a “reconnaissance aid” for adversaries seeking to modify builds.
Area of Concern B: Ballot Ordering
Electronic systems facilitate “ballots when and where you want them,” shifting control from physical inventory to software authorization.
- On-Demand Printing: Vendors market ballot-on-demand capabilities that integrate directly with voter registration systems. CISA has confirmed that the authorization checks for these sessions can be forged (CVE-2022-1747).
- The Green Bay Precedent: In 2020, a private party at the Green Bay central count facility requested data on “absentee ballots returned and outstanding per ward” to determine which wards were mapped to which machines. This represents the complete input set for a “ballot-ordering calculation.”
- Hidden Connectivity: At the same facility, a hidden, password-free wireless network (“2020vote”) was established specifically for “sensitive machines that need to be connected to the internet.”
Dominion Voting Systems proudly advertised their Mobile Ballot Printing in their proposal to the State of Michigan with the tag line “Ballots when & where you want them!”
Meanwhile, election officials insist that one can determine the integrity of any given election if you “just look at the ballots.”
Area of Concern C: Direct Manipulation
Evidence suggests that tallies can be altered with minimal physical access and high internal consistency.
- Malicious Code Propagation: Princeton researchers demonstrated that malicious code can be installed on a voting machine in under a minute and modify all records and logs to remain internally consistent. CISA (CVE-2022-1743) confirmed code could spread from a central management system to every device in a jurisdiction.
- Self-Attestation Failure: The mechanisms meant to report tampering rely on the software itself to self-attest its integrity (CVE-2022-1740), meaning compromised software can simply lie about its status.
- Materiality of Margins: Because presidential elections are often decided by thin margins in a few counties (e.g., 10,457 votes in Arizona; 11,779 in Georgia), a threat model does not require widespread fraud, only targeted exploitation in approximately five jurisdictions.
Area of Concern D: Interoperability and Artificial Intelligence
Mandated data formats and a frozen certification regime create a vulnerable, uniform target for automated attacks.
- The “Frozen” Interface: Because software updates require lengthy EAC re-certification, systems often remain unpatched against known vulnerabilities for years. For example, Georgia declined to install a 2023 patch for known CVEs until after the 2024 election.
- Artificial Intelligence: A uniform interface layer across thousands of jurisdictions allows an adversary to develop a single exploit that applies everywhere. Artificial Intelligence can than use that exploit to manipulate election results while ensuring consistency across the entire digital election record chain of custody without detection.
Area of Concern E: Lack of Transparency
The final failure is the inability of the system to produce a record capable of settling disputes.
- Destruction of Records: In Mesa County, Colorado, a “Trusted Build” update ordered by the Secretary of State destroyed all data on the EMS hard drive, despite federal 22-month retention requirements.
- Reporting Anomalies: Analysis of the 2020 national results feed showed that within a four-hour window on November 4, 50 of 51 presidential races had their totals discarded and reset to zero—affecting over 134 million votes—with no public log or explanation.
- Chain of Custody Failures: In Bailey v. County of Antrim, four separate counts of the same election produced four different totals, leading the judge to state he lacked the facts to determine if the data was corrupted.
Conclusion and Remedy
The findings indicate that the U.S. conducts elections on systems that cannot be independently verified, promptly patched, or lawfully examined. This is defined as a national security problem regardless of whether an attack has been proven.
Proposed Remedy: The document recommends an Executive Order to:
- Mandate hand-marked, hand-counted paper ballots as the primary method for federal elections.
- Restrict machine assistance only to jurisdictions that demonstrate necessity.
- Require mandatory manual audits where machines are used, with the human-readable record governing any conflict.
This approach prioritizes verifiability over convenience, aligning with the practices of approximately 80% of countries in international surveys that do not use electronic voting due to concerns over security and trust.