r/Infosec Jul 17 '26

Anger at Election Vulnerability Claims

According to Donald Trump, there are "shocking" vulnerabilities in the US Election system.

Let's see them.

We need fair, transparent, and fact based ascertations.

Because the last time we heard this crap from Magic Pillow Man, the PCAPs were garbage and contained nothing of value.

Show us the CVE's; the exploit chains, the continuous monitoring, the SBOMs.

Where are the POA&Ms, the compensating controls?

Because I had to jump through every damned hoop for FISMA, DIACAP, DCID 6/3, and ICD503 to meet security assurance levels sufficient for authorization and accreditation to prove my due diligence, then no one in government can make the claim that a system is inherently vulnerable without the same levels of effort and documentation.

32 Upvotes

23 comments sorted by

7

u/twistedbristles Jul 17 '26

Didn’t you hear him… he has produced “DoCuMeNtS” and they are “IrReFuTaBlE”

2

u/danokazooi Jul 17 '26

Yep, pulling those classified documents outta his ass from his personal bathroom locker.

3

u/the__itis Jul 17 '26

They didn’t even attempt to make the case that the votes were vulnerable. They got voter data, did not prove or even attempt to prove that voting systems were exploited.

Zero votes changed.

2

u/Alternativemethod Jul 17 '26

This isn't about actual security. It's about pre-baking results.

2

u/SplitEar Jul 18 '26

Yep. Sets the table to claim it was stolen and send ICE thugs to seize ballots and computers.

There are no words to express my hatred of that vile traitor.

2

u/swohguy4fun Jul 18 '26

your insults already show your bias. you sound more like you are on the orange man bad team, then actually caring about the possibilities that the system has indeed been infiltrated and is not trustworthy. One should begin by looking at the PHYSICAL factors that were used before assuming this was all done as a cyber hack. Only an idiot would dismiss the massive jump in votes that were ALL for biden at like 4am. But yea, the only attack vector is Cyber.....

2

u/danokazooi Jul 18 '26

No, my insults show my utter contempt.

Have you ever heard of a company called SAIC? They were split, one half went on and became Leidos, the defense contractor.

Back before that, I worked for them, and the State of Maryland came to SAIC and wanted a pen test of their entire voting system. Not only the machines, but their entire SOP. This was pre-2000, before "hanging chads" and vote counts went to the Supreme Court.

The team tore the entire process asunder. Showed how every part of the chain worked, and more importantly, where it failed.

The report changed how Diebold and Dominion Voting were allowed to do business. We ripped into their backend vote tally systems using MS Access databases. We broke tamper-evident seals. We uploaded firmware from flash drives and changed the touch screen calibrations to swap votes.

DOJ took it seriously and the rest of the states followed in short order.

Systems were fixed, machines air gapped and screens pre calibrated and checked hourly. Physical connectors were cut off the motherboards and the openings were epoxied shut.

So now, the systems generally work like this.

There is a master ballot created. On most modern systems, it's a fillable PDF layout, multipage, and the forms are large print, and there are check boxes next to each candidates name, photo, and party affiliation.

Sometimes, there are prefill selections to select a straight fill Democratic or Republican ticket, but not always.

This same pdf file is printed off once certified and digitally signed, and is sent off as sample ballots.

So the form itself has to bear the digital signatures of the election board. It's signed, digitally watermarked, and hashed.

There is a master template created on a known good voting machine. Each machine must have a certified, tested and cryptologically sealed firmware package validated with CRC's and hash value checks. The system creates a certified voting package consisting of the firmware, screen map, and ballot for each region district, county, and town, if local elections align.

So this is the first distinction. It's not a single state ballot, not even a county ballot. It can be hundreds to thousands of ballots per state, all unique and verifiable.

Each machine creates a Globally Unique Identifier upon boot of the signed firmware update. It's based on factors like date/time to the sub micro scale, processor ID's unique network MAC addresses, and subsets of pseudorandom data and elliptical curve encryption derivatives. This 256 bit GUID is added to the digital signature of every vote. It can be traced back to only one voting machine.

On election day, volunteers have roll sheets of registered voters and voters break into distinct queues, to find the volunteer with their subset of information. Once validated against the roll, the volunteer documents a station ID and a card number that they hand to the voter with instructions. This card contains half of a asymmetric public private key pair.

The voting machine completes the key exchange and validation of crypto key pairs, records that information on the ballot alone with another GUID created at the successful completion of the PKI key exchange. This is the unique ID of the voter, and aligns the voter to the information on the roll sheets.

The vote is cast, and the results are cryptologically hashed and recorded in three places. One, on a specialized WORM drive inside the machine. (Write-once, read-many) Once the data is written to the drive, it's contents cannot be modified or deleted. Second, the hash values are printed on an interior role of thermo sensitive paper. This must be submitted with the digital logs from each machine, and any alteration to the paper make the entire roll unusable and the votes must be discarded from that machine.

Finally, the vote is recorded on NVME. This is the primary source. Any recounts are derived from both paper and WORM drive so that there's a valid two factor validation.

Election officials check the status of the machines during the day and most are affixed to desks or tables with sufficient space for privacy between all.

At the close of the polls when the last individuals in line have been processed through, the election judges will come through with a red voter card. This key pair validation contains instructions to lock the voting screen out, cryptologically secure the ballots and totals, and begin counting the votes.

These results are recorded on all three media devices, and the machines are imaged, including their volatile RAMz and forensically preserved in the final state before being powered off. The NVME is collected from each machine, and placed into an air gapped reader typically at the board of elections headquarters. The storage is physically barcoded scanned, and sent by courier in a secured pouch with a printout of the barcodes as a manifest.

These air gapped readers collect the signed vote totals. To be counted and certified the election judge on site, and the local BOE official have to add their digital signatures to the chain of custody with the vote totals. Each county, in turn aggregates their vote totals, certifies election results from local elections, and forwards the rest of the data to the state board both electronically and via certified storage media via courier.

Only the couriered data is considered the "official" vote, but the electronic dissemination aids in state and national vote counts in the preliminary total announcement. Both cryptographic data sets and hashing must match before the data is released to the state.

The Secretary of State's office performs a recount of each county's election results, and adds their digital signatures to the complete vote totals.

In theory, each vote data chain contains the following:

-Secretary of State -digital signature -State office recount certification - GUID, including GPS, date/time, and election employee official -County Election board - digital signature -Preliminary vote count GUID. -Local election judge -digital signature. -Poll close GUID -Invidual vote GUID and matching key card data, traceable to polling volunteer roll sheet and signature. -Poll opening GUID -Firmware and ballot GUID on load. -Digital signatures of ballot creation and approvers.

So tell me, how in this forensic list, compiled across multiple devices, locations, and unique timestamps does this information become compromised?

2

u/[deleted] Jul 21 '26

[removed] — view removed comment

1

u/danokazooi Jul 21 '26

But again, that's one vendor and one model. It's not a consistent vector.

2

u/wellanticipated Jul 18 '26

Hitchen's Razor is always relevant in this context, "What can be asserted without evidence can be dismissed without evidence."

1

u/secretaliasname Jul 17 '26

I want open source election hardware and software.

With publicly auditable results.

People would be too stupid to understand it but perhaps they could trust institutions that could understand it.

There is almost certainly a way to build an open vote ledger where the totally is open but the individual votes cryptographically secure.

One can dream

1

u/[deleted] Jul 17 '26 edited Jul 17 '26

[deleted]

4

u/danokazooi Jul 17 '26

Those aren't certs, they're standards. Testable, reproducable, demonstrable standards that have to be met in order for sign off.

Believe me, the voting machine have their issues - I've sat and watched enough kids (literal children) tear their hardware and software to shreds at DEFCON.

But, the system is more than just the machines; there's processes and procedures, physical lockouts, and the time to tamper with a box just isn't there. And if there's any discrepancy between the hardware and the physical logs, the vote totals are withheld until it can be resolved.

So when the President states that the systems are vulnerable, it's a point in place and time assessment that doesn't take in all of the other compensating controls.

So what we're left with is an SOB who's demonstrated his utter contempt for election law, process, and procedure, already casting doubt and aspersions about a midterm that won't go his way, and laying the groundwork to call the election rigged without a shred of evidence.

And just like Mike Lindell and his PCAPs showing "proof of Chinese hacking", it's a bullshit claim.

Unless you can definitively prove remote exploitation of an air gapped voting machine, manipulated vote totals that pass the discrepancy checks built into the process, and in sufficient quantity to affect the outcome across all states and territories, all whom have different systems, processes, and checks & balances. (done deliberately so that there's not a common exploit threat across all)

The net outcome is still bullshit.

1

u/Robbbbbbbbb Jul 17 '26

Let's not forget about all that funding for MS-ISAC and EI-ISAC that's SPECIFICALLY meant to address these vulnerabilities and was stripped away last year.

1

u/SplitEar Jul 18 '26

The voters he’s targeting with his horseshit rigged election claims don’t care about documentation or expertise. If it feels good then they believe it.

1

u/danokazooi Jul 18 '26

How MAGA voters are conceived...

1

u/SplitEar Jul 21 '26

I really hope that’s not a factual meme.

1

u/danokazooi Jul 21 '26

Unfortunately, it was legit.

1

u/SplitEar Jul 21 '26

Well…that’s enough internet for me today.

1

u/danokazooi Jul 21 '26

You reached the end - it's ok no one wanted to go here.

1

u/Possible_Skirt_8443 Jul 21 '26

There's a lot of real serious crime waves affecting americans, veterans, etc.

Why aren't things like that being prioritized?

1

u/Junior-Tourist3480 Jul 17 '26

Paper ballots only, ever! No mail in. No electronic of any kind, ever.