← All posts

The scariest attacker already has the keys

The people who copied Georgia's entire voting system weren't hackers who broke in — they were let through the front door, and that changes everything about how we think about election security.

On the morning of January 7, 2021, the door to the Coffee County, Georgia elections office opened from the inside.

A computer-forensics team walked in. They had help: former county officials who still had access let them through. Over the hours that followed, they copied everything. The Election Management System server. The poll pads. The ballot-marking devices. The scanner software. Georgia's statewide Dominion voting-system software. All of it — extracted and carried out the door.

No alarm triggered. No lock resisted. No system flagged what was happening and alerted anyone outside the room.

The episode is now documented in depositions in the federal Curling v. Raffensperger case and figures in a later Fulton County indictment. Several people connected to it have pleaded guilty. The Georgia Secretary of State's office described it as unauthorized access that former county officials allowed in violation of state law.

But here is the question that keeps the security argument honest: if the same thing had happened quietly, with no indictment and no civil litigation, how would anyone have known?

That question has no comfortable answer. And it is the question every election security conversation needs to start with.


The threat model almost everyone gets wrong

When people worry about election security, they picture the outside attacker: a hacker in another country, a remote intrusion, a malware payload delivered over the internet. That picture is real — and we've covered it. The Princeton researchers who turned a Diebold voting machine into a self-propagating vote-stealing virus in 2006 started with physical access to the machine itself, not a remote exploit.

But the Coffee County breach reframes the problem entirely.

The people who copied that voting system were not outside attackers who defeated the perimeter. They were people the perimeter trusted — or people let in by people the perimeter trusted. The security model that stops outside hackers does almost nothing to stop that scenario.

The correct term for this is an insider threat, and election systems are peculiarly vulnerable to it. Election offices are often small, locally run, and staffed by a rotating cast of officials whose tenure is tied to election cycles. "Access controls" frequently means a key and a password shared among a handful of people. The software being protected is often proprietary — its internals hidden not by cryptographic design but by a vendor's preference — which means that once copied, it can be analyzed for weaknesses far from any oversight.

What does a security model that genuinely addresses insiders look like? The Coffee County case points to the answer, even if it points by showing exactly what was missing.


What 'tamper-evident' actually means

A system is tamper-evident if any unauthorized action it records leaves a mark that an independent observer — someone other than the person who committed the action — can detect.

That is a precise requirement. It is not enough for a system to log events if the same people who might commit the tampering can also edit the logs. It is not enough for seals to exist if the chain of custody for those seals is documented only in the files of the people handling them. It is not enough for software to be "certified" if the certification authority has no independent way to verify that the certified version is what's actually running.

In Coffee County, the copied software was proprietary — its security model depended on the code staying secret. Once it was out the door, that model collapsed. The system had been built to resist outside inspection; it had not been built to make insider actions visible to anyone who wasn't already inside.

Secrecy and transparency are not equivalent security strategies. Secrecy fails completely the moment one insider cooperates. Transparency survives that scenario because the record is public and the tamper-evidence is checkable by anyone.

The Fulton County indictment did not uncover the Coffee County breach because any technical feature of the voting system flagged it. It surfaced through litigation, depositions, and investigative journalism. That is not a security mechanism. That is luck wearing a legal robe.


Germany asked this question first — and answered it in court

In 2009, the German Federal Constitutional Court did something that deserves more attention than it receives outside Europe.

Two citizens had challenged the use of computerized Nedap voting machines in the 2005 Bundestag election. The machines recorded votes in electronic memory only, with no paper record a voter could independently verify. The court ruled — unanimously, grounded in the Basic Law — that this was unconstitutional.

The ruling's logic is worth reading closely. The court held that the essential steps of voting and the determination of the result must be examinable by the citizen reliably and without any specialist knowledge. Not by experts. Not by certified technicians. By ordinary citizens.

This requirement, the court found, flows from the principle of the public nature of elections — the idea that democratic legitimacy is not established by an authority declaring a result, but by the public being able to trace, observe, and verify how that result was produced.

The machines failed this test because their inner workings were opaque. A voter could press a button. They could not confirm what the machine recorded. They could not, after the fact, check the count against anything they could personally examine. The result was only as trustworthy as the people operating the machines — and that, the court said, is not enough.

Notice what the court did not say. It did not say fraud had occurred. It did not say the machines malfunctioned. It said the structure of the system made independent verification impossible, and that a democracy cannot rest its elections on a foundation that the public cannot check.

Read the full judgment. See the press release.

Coffee County is the American case that proves the German court was asking the right question.


Kenya pushed the same logic further — and annulled a presidential election over it

In September 2017, the Supreme Court of Kenya invalidated the presidential election held the previous month.

The court's reasoning was not primarily about fraud. It was about verifiability. Kenya's constitution requires that voting be verifiable, accurate, accountable, and transparent — not as aspirations, but as legal requirements whose violation renders a result invalid.

What the court found was that the digital chain from polling station to national tally had broken down. Not all polling-station result forms had been electronically and simultaneously transmitted to the national tallying centre as required by law. Result forms lacked consistent security features. The chairperson had declared a winner before receiving all the underlying forms.

The court annulled the result — not because it could prove the wrong person won, but because the process had not maintained the tamper-evident chain that would have allowed anyone to independently verify who won.

A fresh election was ordered. One was held.

The Kenyan case establishes something precise: a declared result is not a verified result. Verification requires a chain of custody — from individual polling station to national tally — that is documented, signed, timestamped, and independently checkable at each link. When that chain is broken, the declaration at the end of it is legally and democratically void, regardless of whether anyone can prove the break was intentional.

Read the Supreme Court judgment.


The QR code problem: when 'paper' isn't actually verifiable

Here is a subtler version of the same gap, much closer to home.

In the Curling v. Raffensperger litigation — the same federal case that later surfaced the Coffee County breach in depositions — a U.S. district court reviewed Georgia's Dominion ballot-marking device system and found something precise and troubling.

The machines print a paper ballot. That paper ballot includes a QR code. The tabulator scans the QR code to record the vote. The human-readable text on the paper shows candidates' names — but the tabulator reads the QR code, not the text.

The court found that this system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter."

Think about what that means. A hand recount of those ballots audits the QR code's output, not the voter's intent. If a compromised system generated QR codes that encoded different choices than the printed text showed — the scenario expert witnesses described as feasible — a hand count would faithfully reproduce the manipulation, because the human counters would be scanning the same codes the machines scanned.

Read the court's opinion.

The court declined to order last-minute relief before the 2020 election. But the finding stands: a paper record is only as trustworthy as the chain between what the voter marked, what the paper encodes, and what the tabulator reads — and if any link in that chain is opaque, the paper provides the appearance of verifiability without the substance.


What the CISA 'most secure in American history' statement actually says

On November 12, 2020, the Election Infrastructure Government Coordinating Council published a joint statement — under the CISA banner — declaring the November 3rd election "the most secure in American history" and asserting there was "no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised."

This is a claim worth reading carefully, not dismissing and not accepting on faith.

The statement's own reasoning is telling. It grounds its confidence in paper records that enable recounts and audits. That is an implicit acknowledgment that the assertion of security draws its force from independent verifiability — not from the authority making the claim. An election is trustworthy, by the statement's own logic, because the record can be checked, not because the officials say so.

Read the full statement.

The Coffee County breach happened eight weeks after that statement was published — on January 7, 2021, not November 3, 2020. The breach did not affect the vote count. But it exposed the proprietary software those same certified, "secure" machines ran on. And it was committed by people who had insider access. CISA's statement had no mechanism to prevent, detect, or flag that.

This is not an argument that the 2020 election was stolen. The evidence — including a Georgia hand count of roughly five million ballots that matched the machine totals to within a tenth of a percent — points firmly the other way. It is an argument that "no evidence of compromise" and "independently verifiable" are not the same sentence, and conflating them is precisely how a real compromise in a future election could stay hidden long enough to matter.


The architecture of tamper-evidence

So what does a system that actually addresses the insider threat look like?

Germany's constitutional court gave the design requirement: ordinary citizens, no specialist knowledge, independently verifiable. Kenya's supreme court gave the procedural requirement: a signed, timestamped, publicly accessible chain of custody from every polling station to every declared result. The Coffee County breach gave the negative case: proprietary software hidden behind access controls that a single cooperating insider can bypass entirely.

Los Angeles County took a step in the right direction when it built VSAP — a publicly-owned, open-source election tally system, certified by California in 2018 as the state's first. When the code counting votes is published, independent experts can inspect it. That does not guarantee perfection — implementation, chain of custody, and audit procedures all still matter — but it removes the layer of opacity that made Coffee County possible in the first place. The California Secretary of State's certification is the public record that VSAP met those standards.

Brazil's Superior Electoral Court goes further: it runs an official Public Security Test every election cycle, inviting any qualified citizen to probe the voting machines and related systems for weaknesses before the election. Findings get fixed. Fixes get re-checked. The program is not a one-off certification — it is institutionalized adversarial testing, run in public, documented, and repeatable. See the TSE's program page.

Both models share a design philosophy: replace the assertion "it is secure" with the publicly-checkable condition "here is what you would find if it weren't, and here is how you can look."

That is the architecture of tamper-evidence. Not a sealed room that trusts its occupants. A published record that survives anyone inside it going rogue.


What is still not verifiable — and what would change it

The Coffee County breach did not change the outcome of any election. The people involved have faced legal consequences. The system has presumably been updated.

But here is what remains true: in most jurisdictions running proprietary voting software, there is no public mechanism for an independent observer to confirm, after the fact, that the software running on election day was the certified version and had not been modified. Chain-of-custody seals can be checked by officials. Logs can be reviewed by officials. Certifications can be cited by officials. All of those are claims made by people inside the room.

A tamper-evident system would publish a cryptographic fingerprint of the software before the election, derived from the actual code to be run on actual machines, and allow any observer to verify after the election that the fingerprint matched what ran. It would publish precinct-level results in machine-readable form the moment each precinct closes — not because speed matters, but because granular, time-stamped, downloadable data gives independent analysts the raw material to detect anomalies before the canvass is certified. It would use voter-marked paper — not machine-generated QR codes — as the authoritative record, so that any hand audit reads what the voter chose rather than what a machine encoded.

None of this requires trusting that officials are honest. It requires building systems whose honesty is independently demonstrable — by anyone, with no specialist knowledge required.

The German court said that in 2009. Kenya's Supreme Court enforced it in 2017. The Coffee County breach showed what happens when the design ignores it.

The scariest attacker in any election system is the one who already has the keys. The only defense against that attacker is a system that proves its own integrity publicly — not one that asks you to trust the people holding the keys.

The question to ask of every election system you encounter: if one insider cooperated with an adversary, what would be left for an independent observer to check? If the honest answer is "not much," that is the gap. That is what needs fixing.

See how common this gap is across the world — Read the 2-minute version


Sources