back
157 comments
The Colorado Secretary of State is unintentionally showing the conspiracy theorists are correct. A single person having physical access to the voting machines, months before the election, who has different political views from the Secretary, is enough to make those machines unusable. When the entire election in a district is run by officials from a single political party, with unlimited access to the voting machines, what is the other political party supposed to think?

I had no opinion before now, but clearly these machines are unusable anywhere.

This is the opposite of reality.

Colorado resident here. The CO Secretary of State has been proactive about everything election related. There's complete, transparent procedures for voting, there's educational materials about the risk limiting audits that get done for every election.

All registered voters get a ballot in the mail. You can return them by mail, use a secured drop box which reside in locations under security camera. You can check your ballot's status on-line, and get email updates. You can also vote in person, should you want, on election day.

Some yahoo state rep introduced a patently-unfair bill that would have made CO do things like stop counting on midnight of election day, which would almost certainly leave large fractions of ballots uncounted no matter how you vote, mail or in-person. No way around that. Thankfully, the CO legislature is not particularly crazy this year, so it failed.

The conspiracy theorists caused the breech - the Mesa County Clerk is the one that c illegally copied the voting machine hard drives and gave the images to other conspiracy theorists.

You are putting the blame exactly in the wrong place.

The thing is, the line of reasoning that electronic voting is fundamentally not securable to a sufficient public standard was being advanced a lot before the election, and has a lot of evidence to support it.

E.g. here's sci am on 2016: https://blogs.scientificamerican.com/guest-blog/election-sec...

Contesting only elections that don't go your way and providing dubious or nonsense evidence (see various thrown out lawsuits) is simply subverting the process and the electorate.

If they're unusable, then they're unusable everywhere : and the election needs to be run without them.

> When the entire election in a district is run by officials from a single political party, with unlimited access to the voting machines

This probably shouldn't happen. Unfortunately, hyper-polarisation has.

> A single person having physical access to the voting machines, months before the election, who has different political views from the Secretary, is enough to make those machines unusable.

According to the article they disabled the security cameras monitoring the machines for a week.

Once someone deliberately breaks the chain of custody on voting equipment, whether it’s electronic or a paper ballot box, it becomes suspect. Not only that, but the machines are now evidence in the investigation, so they have to be set aside anyway.

Replacing the equipment was the only option. There is no perfectly secure voting system that isn’t affected by chain of custody breaks.

There’s a reason Taiwanese elections look like this: https://thediplomat.com/2020/02/taiwans-electoral-system-put...

You hit the nail on the head. Election systems must be obviously honest to low information voters in the other party who don’t trust the election officials.

"I had no opinion before now, but clearly these machines are unusable anywhere."

All politics aside, it's fairly obvious that electronic voting machines can be very dangerous unless they're handled very, very, very carefully. The contracts for these machines aren't going to the best of the best, they're going to the lowest bidders. As a software engineer, the idea of going from manual, verifiable tabulation to opaque software is completely horrifying.

It is significantly harder to forge thousands of paper ballots. Not impossible, but not nearly as easy as manipulating opaque software or simply gaining access to these machines.

People can actually observe and confirm the tabulation process currently. All machines should be open-source and easily audited if we want to inspire any sort of confidence in them to the average voter.

Ah yes. The conspiracy theorists really showed us! Next, proud boys and Q will team up to buy a pizza place, kidnap a bunch of kids, and create a kid prostitution ring.
I really hope I'm reading this wrong, but it looks like the key takeaway here should be that an official responsible for security completely subverted their responsibilities, allowed unauthorized access, and disabled monitoring... and the only reason anyone found out is one of their co-conspirators broadcast the resulting access all over the internet.

If the only way a bank (or its depositors) knew the bank had been robbed was if the robbers told everyone they'd robbed that bank, would we consider the bank secure, no matter what consequences employees faced?

There seems to be a fundamental failure of process with no plans to actually improve security in the future.

It was my understanding that going into the symposium, the issue of Mesa County’s machines was already on the radar and there was an active probe into Peters
Have predicted for years that electronic voting would cause civil unrest because in a highly contested election, it does not provide adequte physical evidence of vote integrity. The whole idea of electronic voting is designed to forfeit the integrity of a process whose entire legitimacy depends on the integrity of that process. As they say, this isn't the first time they stole from us, it's just the first time they've been caught. Anyone who has scratched the surface of this issue is unlikely to be persuaded by new assurances about new electronic voting controls, other than committed partisans who are fine if it's rigged in their favour.

The more interesting question is, what are the knock on effects of a popular loss of confidence in western elections held with these machines?

i would assume that the presumption of fraud would itself lead to greater degrees of fraud with the inherent justification among partisans being 'well the other guy is doing it so this is the only way we can keep up'. that in of itself might not be that bad but if the fraud or perception of fraud has potential to act as a force multiplier for existing instabilities and intra-party paranoias then it becomes very easy to imagine the process dismantling itself. it really seems like the experiment for this decade is figuring out just how much distrust institutions can take on while still remaining functional.
This story is wild. The headline is about the machines, but the article is really about some strange corruption within the department that led up to the breach:

> Griswold also said that one week before the breach, Peters ordered her staff to turn off the video surveillance system that monitors the voting machines and that it was only recently turned back on.

Somehow they ended up with an unauthorized person attending a procedure to update the machines, which then resulted in video and other information being posted to a QAnon-affiliated blog.

Replacing the potentially compromised machines is a good move, but it seems like the real story is that something has gone very wrong inside this government office.

> Peters ordered her staff to turn off the video surveillance system that monitors the voting machines and that it was only recently turned back on.

This is probably about the point where you should ask your boss's boss "is this okay?" rather than just following orders, tbh. The whole thing is bizarre.

Why replace the machines instead of using paper ballots?
It frankly seems like a deliberate sabotage. It doesn’t help that the county clerk is apparently attending a QAnon conspiracy conference at the moment.

Any election official that shows allegiance to such theories should be summarily banned from ever holding public office.

Can't they just wipe them clean and restart?

How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?

If they are compromised, I'd love to see a post mortem and understand how they were compromised and how that can be mitigated going forward.

No reason for your question to be downvoted. I've done my small part to reverse that.

I doubt the officials suspect the machines have been compromised, but they have no way of knowing. There are chain of custody rules to help ensure integrity of the systems. Those have been violated so the machines can't be used until they've been carefully examined and recertified.

Putting this in a money context might help some--lets say you owned slot machines that could have big payouts. Would you let rando unauthorized person to be alone with one of your machines in a private office, doing upgrades, and still trust the machine? Probably not. You'd want to take a look at it top to bottom before trusting it to do any payouts. The person might not have done anything wrong but you've got to be sure first, and since there are other ways these things could be compromised than just adding unauthorized software to the hard drive, a clean install isn't enough.

> Can't they just wipe them clean and restart?

I mean, _probably_. There's malware that's extremely difficult to get rid of, but probably it wasn't used here.

But it looks like they have elections coming up in a few weeks, so "do it on paper" is probably a not-unreasonable precaution, particularly given the general pattern of dodginess, in particular the thing about the video surveillance.

If nothing else, if you phone up the manufacturer and tell them that a weird pillow website devotee allowed some unknown third party to potentially mess with the machines, the manufacturer is probably _not_ going to say "yeah, that'll definitely be fine, use them"; they won't want to take the risk. This is probably a return-to-manufacturer job.

> How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?

As soon as an unidentified attacker has unsupervised access to a piece of hardware it's game over. An exploit that uses persistence features like embedding itself into the BIOS/UEFI firmware (see e.g. https://www.coresecurity.com/core-labs/articles/the-bios-emb...) can be very hard to get rid of - so hard that it's likely easier to dispose of the machines entirely.

> Can't they just wipe them clean and restart

They’re now evidence in an ongoing investigation. They don’t know exactly what happened to them because the perpetrators deliberately disabled the security cameras monitoring the machines before doing whatever they did.

Wiping them could destroy evidence or it could miss a different issue (hardware modification, for example).

The only reasonable response is to quarantine the machines as evidence and replace them with new machines with a known chain of custody.

> How is one person being present during an upgrade enough to render the physical machines suspect and beyond repair/review?

There’s more to the story, including someone intentionally disabling the security cameras that monitored the machines for at least a week. With a gap in the surveillance of the machines combined with a QAnon-associated leak and an intruder who misled the office, it’s time to start fresh and set the old machines aside as evidence.

Whole countries with public counting of paper ballots have election results faster than we do.

The phrase "voting system" is an absurdity. It highlights the overly complex, bug-riddled lunacy we have now.

A lockbox, under guard with multiple observers, collecting ballots over the voting period, followed by a public counting of the paper ballots is simple and fast. What we have now isn't.

Australia has a simple and trustable election system. Paper ballots, reinforced by the fact that more or less every citizen can get a job working on election day. Your duties include looking up people based on what they say their name an address is (no ID required; although many electors hand me their ID anyway) on a big electoral roll book, cross out their name, and hand them a ballot with your initials.

They go to one of the booths and mark their selection, and drop it off into a zip-tied big ballot box (that is visible to the general public, and of course election staff at all times).

After the polls close, the polling official cuts the zip-ties on the ballot boxes, everyone working sorts ballots into piles and count them, along with scrutineers from political parties who can watch. An officer-in-charge records and publishes the results continuously, and everything is saved and shipped for OCR-based recounting to verify the numbers. The process is federally operated and the same processes are followed everywhere.

Results are almost always revealed on election night.

The electoral roll books are processed centrally after every election, so someone who votes twice would be quickly caught. Someone who votes under fake names and addresses would most likely cross-over with someone else, hence an investigation would still happen. (We also have compulsory voting, which is another subject for debate, but it does mean "vote under multiple names" is mitigated without the need for ID laws).

The job pays reasonably well (A$457 for the day), more or less everyone who applies gets hired (I believe there is a bias towards maximizing first-time applicants), and it's hard to think about election fraud when every citizen can be part of the election process itself, and it's hard to conceive of how fraud can happen.

I agree, the overly complex use of machines, followed by closed door counting, lends it self too much to impropriety. I think America has mostly honest elections, but after last year‘s election I am… Uneasy about the whole system. Simple is better.
> Whole countries with public counting of paper ballots have election results faster than we do.

How many of those countries have as many races on a typical presidential-year ballot as the US does?

The US is also generally pretty fast to count its ballots; note that the election result is usually known within hours of polls closing, despite the insane number of races on the ballots. What happened in 2020 is there was an unusually high number of mail-in ballots, and this was combined with several states intentionally slowing down the counting process.

This system is simple but it’s neither fast nor available. The thing you have to worry about with this kind of system is ballot stuffing which leads to needing an additional requirement to verify each voter and observe them filling out and depositing the ballot. This creates a bottleneck at the polls which is why every election there are news stories about people having heat strokes or being turned away after the polls close.

It’s also not available because making people show up to a few set of fixed locations at specific polling hours will exclude people who don’t have access to transportation which is why during the Obama election the big thing was the Obama campaign providing busses to voters.

If you’re willing to give up some anonymity (only that you voted not what/you voted for) then mail in ballots, public drop-boxes, and walk-in deposits are much faster and more available. If you can mail in then great! Done. If you want to go to the polls then you fill out your ballot ahead of time, verify yourself with the poll worker and then drop it in the box. Done. 30 seconds a person rather than 10 minutes a person.

I think the culture in the US surrounding voting is the real issue. The discussion is always around security and integrity and making sure only the right people vote which are the kind of problems people who read too many Tom Clancy books care about. Meanwhile we only get at most ~50% turnout every year and people have to fight to actually cast their ballots. And we pretend that our election results actually mean something when half the country doesn’t vote and the sample that does is so skewed because the factors that keep people from voting aren’t random.

Hand counting of ballots works well when you're only voting for a single elected office. In the US, most elections involve voting for many different offices all on the same ballot.

Really, we should just be switching to using scantron style ballots everywhere. They're paper ballots which can be efficiently counted by a machine, and are super easy to manually recount later

My only issue with a paper-only drop box is there's no redundancy. I would think with having poll watchers from multiple affiliations and multiple shifts per day to ensure you have many eyes on the box it wouldn't be a concern. But, if someone or some group managed to figure out a way to "stuff the box," you'd have no proof it happened.

I really like the system we have in DFW now. We have a global voter roll so you can vote in any location in your county. You submit your vote on a machine, which keeps a local machine-level tally and prints out a paper ballot. You verify the contents of the paper ballot, then drop it into a vote counting box, which scans, tallies, and displays your vote for you to confirm. If at any time anything looks wrong, you notify a poll worker to resolve it. At the end of each day, they verify the counts on the machines and ballot box match, then the ballot counter/box is locked along with the memory cards of each individual machine, so you have day-by-day results.

When the election ends, the ballot boxes are delivered to a central county counting system where they are put into another large-scale counting machine to verify that the counts there match the local counter/box. If at any point there's too many discrepancies, they'll do hand counts of the paper ballots. They can also unlock the voting machine memory cards if necessary. All of this process is done under the supervision of poll watchers.

In theory, you get near instantaneous results as each voting location can simply total the ballot box results and report them. You also have 4 separate systems (voting machine, local counter/ballot box, central counter, paper backups) that would need to be compromised to successfully tamper with the results.

I'm sure it wouldn't make a conspiracy theorist satisfied, but to me, it's a system that balances speed and convenience with the simplicity and security(?) of a paper ballot, without unnecessarily obfuscating the process behind electronic-only voting.

I think Tom Scott's video about e-voting couldn't be more relevant today: https://www.youtube.com/watch?v=w3_0x6oaDmI
If a single breach to a ceremony involving the equipment is enough to invalidate it’s use completely, doesn’t sound like the machines are designed with enough layers of security? Couldn’t they repeat that step and reset that leaked password?
Note the story isn't "insecurities suspected in voting systems", its "systems exposed for inspection" ... Why would a voting system not be totally open and inspect-able by any citizen of the jurisdiction using it, and/or anyone else? What've they got to hide?
This past election cycle politicized what should have otherwise been treated as a national security threat in unauthorized access to voting systems.

Notice i use the word "systems" to include the human element as well as all the other components that go into making what we have today far from an acceptable system of voting in the most powerful individual on the planet.

Breaches are acceptable and their detection proves the security system works. Undetected breaches would indicate a complete failure of the security.

Problems are to be expected, as long as the system can detect and deal with the breach, democracy is protected, albeit at greater cost in this instance.

“Nobody except us can be alone with these machines otherwise you can’t trust them”

Is not something that anybody trying to ensure trust in elections should ever say.

“On conspiracy website”

Heh. What’s that saying, “even paranoid people have enemies.”

Democracy is broken because half of the people don’t want it anymore. So they will never be satisfied in that process.
I live in Mesa County. This is a costly mess.
GOOD. Now we need to ban mail-in voting and move voting day to a Sunday.
> Peters was among those who have been spreading baseless conspiracies about the election, but despite being accused of helping leak official election data to a QAnon promoter, she still appears to have a large support base in Mesa County. The Daily Sentinel reported Wednesday that “a large group of Mesa County residents asked the county commissioners to condemn Griswold for her investigation and to stand behind Peters, saying the clerk is a hero for trying to uncover cracks in the state’s election system.” And this Saturday, supporters will hold a “patriot rally” for Peters.
lol more and more conspiracies are becoming more and more likely
One of those contradictions I am at a loss to explain is that the same people who seem to be freaking out about vaccine card fraud completely deny that voting fraud is widespread.
If a lone clerk can compromise the machines, should we really be using them? Do we know and trust everyone who had (legitimate or otherwise) access to these machines, including the manufacturer?

And what benefit do they offer over a hand count, to justify so much risk?

Just because the Republican's allegations about fraud were without merit, does not mean electronic voting is a good idea.

> Peters survived an effort to recall her from office over the ballots and other issues, including allegations that she failed to maintain adequate staffing in the election division.

I might be tempted to say that the voters of Mesa County deserve having their freedoms stolen away. A vital part of democracy is holding transgressors accountable, and the voters of Mesa County have failed their responsibility.

Unreal. Because voting is secure the conspiracy theorist decided to create a conspiracy and potential security threat by releasing passwords online for the system and allowing people in to the back door. How pathetic. You were that hard up for a conspiracy? They should vet these people more and allow less individual access. I’ve seen some systems where 2 or more people of opposite political parties have to open the facilities at the same time. Maybe try that?