Electronic Voting System Integrity

Electronic voting systems lack the transparency needed to promote public trust in election outcomes (US)

Disputed Fact Together, illusory contracts, FOIA obstruction, and denials of access create a structural environment in which grave technical weaknesses can persist indefinitely without detection or remediation. Mesa County’s case demonstrates that unauthorized software (SSMS), global SQL exposure, disabled logging, and mass deletion of audit trails can coexist with EAC/VSTL “certification” and state assurances precisely

Electronic voting systems lack the transparency needed to promote public trust in election outcomes (US) Read More »

EAC governance system is an insulated “circle of trust” that lacks independent oversight needed for the security of critical infrastructure (US)

Disputed Fact CISA’s Cyber Risk Assessment depicts U.S. election infrastructure as a highly networked, variably secured critical infrastructure ecosystem with persistent, exploitable weaknesses, while the EAC’s election system oversight is narrowly product centric, episodic, and largely detached from those systemic cyber risk realities. Unlike other critical infrastructure systems, there are no failure modes and effects

EAC governance system is an insulated “circle of trust” that lacks independent oversight needed for the security of critical infrastructure (US) Read More »

EAC lacks analysis rigor sufficient for critical infrastructure (US)

Disputed Fact CISA’s Cyber Risk Assessment depicts U.S. election infrastructure as a highly networked, variably secured critical infrastructure ecosystem with persistent, exploitable weaknesses, while the EAC’s election system oversight is narrowly product centric, episodic, and largely detached from those systemic cyber risk realities. Unlike other critical infrastructure systems, there are no failure modes and effects

EAC lacks analysis rigor sufficient for critical infrastructure (US) Read More »

EAC features significant security gaps (US)

Disputed Fact The latest VVSG 2.0 standard features the following security gaps: • System boundary: focuses on the voting device and EMS, not the full enterprise and vendor environments.• Operational security: limited guidance on continuous monitoring, vulnerability management, and incident response.• Identity and access: no full RBAC requirement and constrained, fragmented MFA implementation relative to

EAC features significant security gaps (US) Read More »

RestoreDatabase API Found – Able to Overwrite Voter Database at Runtime (MI)

Established Fact Binary analysis of EPBHostService.exe — the poll book host service deployed to all 44 Livonia precincts on Election Day 2020 — reveals a RestoreDatabase API endpoint capable of overwriting the entire active voter database (EPB.accdb, 79 MB) at runtime. Calling this endpoint during an election would replace all voter check-in records accumulated since

RestoreDatabase API Found – Able to Overwrite Voter Database at Runtime (MI) Read More »

Voting System’s Encryption Keys Provided to Counties Unprotected in Plain Text (GA)

Disputed Fact Encryption is used to protect the voting system configuration files, programming, election results, and functions. With the cryptographic encryption keys, the programming, results, and functions can be easily manipulated without detection. Citations Fulton County, GA 2020 General Election Report for Georgia State Election Board, Election Oversight Group, LLC https://drive.google.com/file/d/1UzJ4qX6iBSrFMtkoRnOGIe3q8pzGjkVx/view?usp=drive_link

Voting System’s Encryption Keys Provided to Counties Unprotected in Plain Text (GA) Read More »

EAC security rigor insufficient to secure election systems as critical infrastructure (US)

Disputed Fact On December 7, 2025, the Chair of the Election Assistance Commission, Donald Palmer, issued a statement designed to give a false sense of security that our electronic voting systems are secure. The Election Crime Bureau responded with a report supported by evidence that asserts that the security safeguards in place for election systems

EAC security rigor insufficient to secure election systems as critical infrastructure (US) Read More »

Dominion iButtons – Hardware Authentication Tokens Retained Exclusively by Vendor, Never Transferred to County (AZ)

Established Fact Maricopa County did not possess the administrative iButtons – hardware authentication tokens required to configure, validate, and independently access the Dominion tabulation systems it deployed in the 2020 election. These tokens were retained exclusively by Dominion Voting Systems throughout the election cycle. As a consequence, Maricopa County election officials had no independent ability

Dominion iButtons – Hardware Authentication Tokens Retained Exclusively by Vendor, Never Transferred to County (AZ) Read More »

FIDO Key Mismanagement and Private Operative’s Control of Hidden Election-Night Wi-Fi Network (WI)

Established Fact The Wisconsin Elections Commission (WEC) issued 3,137 FIDO (Fast Identity Online) hardware security keys for WisVote database access while admitting it cannot account for how many keys it has actually issued. At least one county received 15 keys after requesting only 2, and was told to hold unused keys “just in case.” Of

FIDO Key Mismanagement and Private Operative’s Control of Hidden Election-Night Wi-Fi Network (WI) Read More »

ESS Installed Remote-Access Software (pcAnywhere) on EMS Systems – Source Code Was Stolen by Hackers (PA)

Established Fact Election Systems & Software (ESS), the largest U.S. voting machine vendor, admitted in a 2018 letter to Senator Ron Wyden that it had installed pcAnywhere remote-access software on election management systems sold to Pennsylvania and other states between 2000 and 2006 – directly contradicting prior public representations that it had never done so.

ESS Installed Remote-Access Software (pcAnywhere) on EMS Systems – Source Code Was Stolen by Hackers (PA) Read More »