Discussion about this post

User's avatar
Mark Bohrer @LocalPoet's avatar

As someone who manages complex software and systems projects, you can’t test a system to prove it’s secure. You must have access to the source code, and verify an unbroken chain from the source code to the tools that build it, all the way to the images loaded onto the system. This post says what I was most afraid of - that the the states who are responsible for election security don’t have access to the source code, and don’t oversee and verify the process of who puts code into the change management system.

This is the worst case. If what I’m reading is true, we have a completely insecure election system. In this case, the testing performed is meaningless.

How can the Secretaries of State across the country let this happen?

Expand full comment
Bob Stromberg's avatar

Thank you, Lulu, for this excellent explanation.

Given the hollowing out of the federal government by Trump and Musk, perhaps some states might have the political will to institute effective testing of voting systems.

I was impressed by a 2014 report of independent testing of Dominion's Democracy Suite 4.14-A and 4.14-A.1, now hosted at Verified Voting:

https://verifiedvoting.org/wp-content/uploads/2020/08/red-team-support.pdf

As a result of an initial round of testing, Dominion corrected some, but not all, of the vulnerabilities discovered. That's the kind of "positive feedback mechanism" that we want to see with current voting systems (only, please, correct *all* of the problems). This approach to testing actively encourages independent testing that finds problems, and requires a response from the vendors that corrects those problems. Then, further testing to show that the vendor response actually fixed the problems.

Just considering my home state of NY, I have seen nothing like this in the NYS BOE tests of the currently available voting machine systems approved in NY (ClearBallot, Dominion, ES&S, and Hart InterCivic). The NYS BOE published only one high-level, completely inadequate report for each voting system tested. See:

https://elections.ny.gov/voting-systems-testing

Expand full comment
6 more comments...

No posts