Election Computers Are at High Risk at Manufacturers

1.     "Vendors represent an enticing target" ~US Senate Intelligence Committee

2.     Vendors send updates for election computers every year. The updates can be hacked or have bugs, but if you don't do them, machines are even less secure.

3.     Candidate list is loaded for each election, so officials access every machine, and errors can creep in.

4.     Most states only check logic and accuracy with small samples, where hackers and bugs may lie low and avoid detection.

5.     Phishing and insecure emails (Candidates resist security too)

6.     Insecure passwords

7.     Zero-days which hackers sell to attackers

8.     Election virus

9.     Counterfeit software

10.  Backdoors, see pages 55-61 in Georgia case for paper ballots.

11.  Machines are also vulnerable to physical access if delivered to polling places the night before the election.

12.  Entry is also usually easy, even at secure storage sites.

13.  If bad software is installed in advance, any one ballot can tell the bad software what to do: For example a write-in for Alyx Brown can be an instruction to shift votes to or from a real candidate named Brown.

14.  Software from Scytl, a Spanish company which went bankrupt in May 2020, delivers ballots to US military and other citizens overseas for 1,400 counties (half). Scytl's software also transfers results between vote-tabulation computers and the internet in 7 states with 44,000,000 registered voters (a fifth). The only software Scytl has shown to the public, for a Swiss vote, was insecure, with a flaw which let insiders or hackers change all the votes. Two outsiders found the flaw, which had not been found by Scytl or the reviewers hired by Scytl and Switzerland.

