Protecting Election Researchers Globally
Miracle Owolabi (Cyber security professional · Election Integrity Foundation)
Voting Village @ DEF CON 33 · Day 1 · Voting Village
Overview
In this critical talk at the Voting Village, Miracle Owolabi, a cybersecurity professional with the Election Integrity Foundation, shed light on the pervasive and alarming challenges faced by election security researchers worldwide. The presentation, titled "Protecting Election Researchers Globally," underscored the urgent need for a robust framework to safeguard individuals who dedicate their expertise to identifying and disclosing vulnerabilities within democratic processes. Owolabi powerfully articulated that while these researchers serve as the "last line of defense" for electoral integrity, they are frequently met with arrest, lawsuits, and intimidation rather than gratitude and protection.

Key moments
- 0:00 Introduction: Security through openness, not silence
- 1:59 Real-life examples of researchers facing arrest, threats
- 3:26 Why election security research is critical globally
- 4:09 Fragmented global legal landscape for researchers
- 5:19 Regional legal challenges: CFA, GDPR, national security laws
- 6:27 Lessons from Global South: unique challenges, high personal cost
- 7:50 Addressing the culture of distrust in election research
Protecting Election Researchers Globally
Speakers: Miracle Owolabi, Cyber security professional, Election Integrity Foundation
Conference: Voting Village
YouTube: https://www.youtube.com/watch?v=5qmpv44knF8
Overview
In this critical talk at the Voting Village, Miracle Owolabi, a cybersecurity professional with the Election Integrity Foundation, shed light on the pervasive and alarming challenges faced by election security researchers worldwide. The presentation, titled "Protecting Election Researchers Globally," underscored the urgent need for a robust framework to safeguard individuals who dedicate their expertise to identifying and disclosing vulnerabilities within democratic processes. Owolabi powerfully articulated that while these researchers serve as the "last line of defense" for electoral integrity, they are frequently met with arrest, lawsuits, and intimidation rather than gratitude and protection.
The core message of the talk revolved around the principle of "security through openness, not silence." Owolabi argued that the current global landscape, characterized by fragmented legal frameworks and a culture of distrust, actively stifles vital research. This hostile environment prevents the timely identification and remediation of flaws in increasingly complex election systems, thereby jeopardizing democratic outcomes and voter confidence. The talk meticulously detailed real-world examples of researchers facing severe repercussions across different continents, emphasizing why their protection is not merely an academic concern but a fundamental necessity for the health and resilience of global democracies.
The significance of this topic cannot be overstated, particularly in an era where elections increasingly rely on intricate software and hardware systems. A single unaddressed vulnerability can disenfranchise countless voters and undermine the legitimacy of an entire election. Owolabi's call to action resonated deeply, advocating for a collaborative, global effort involving policymakers, civil society, technical experts, and citizens to establish a safe haven for researchers. This, she contended, is paramount to ensuring that those who protect democracy are themselves protected, fostering an environment where ethical disclosure leads to stronger, more trustworthy electoral processes worldwide.
Background
▶ Watch: Introduction: Security through openness, not silence (0:00)
The problem addressed by Miracle Owolabi is rooted in the fundamental tension between the critical role of security research in safeguarding democratic processes and the often punitive legal and social environments in which this research is conducted. Modern elections are no longer simple paper-based affairs; they are complex systems where software and hardware meet and decide outcomes, making them susceptible to a myriad of vulnerabilities. Researchers who uncover these flaws, ranging from software bugs in voting machines to systemic weaknesses in electoral data management, are essential for ensuring the integrity and trustworthiness of the democratic process. However, instead of being recognized as guardians of democracy, many are treated as adversaries.
Owolabi highlighted several chilling real-life examples that illustrate the global scope of this issue:
- In the United States, a Georgia-based researcher faced arrest simply for attempting to access public files related to elections. While the charges were eventually dropped due to public outcry, the incident underscores the inherent risks researchers face even when operating within what they believe to be legal and ethical boundaries.
- In Nigeria, a researcher was silenced after disclosing a vulnerability found in the electoral process. Disturbingly, the flaw he exposed remains unfixed to this day, leaving the system vulnerable and potentially impacting the democratic rights of citizens.
- In India, a researcher who discovered significant flaws in electronic voting machines was arrested, and the case remains unresolved. Such instances create a strong deterrent, discouraging others from engaging in similar vital work.
The underlying cause of this pervasive issue is a highly fragmented and ambiguous legal landscape that offers little to no consistent protection for good-faith security research. Owolabi elaborated on how different national laws inadvertently or intentionally hamper research:
- In the US, the Computer Fraud and Abuse Act (CFA), originally intended to combat malicious hacking, often creates significant legal risk for researchers. Its provisions regarding "unauthorized access" can be broadly interpreted, potentially criminalizing actions like accessing publicly available data or conducting vulnerability assessments without explicit prior authorization, even when the intent is purely defensive.
- In countries like Nigeria and India, vulnerability disclosures are frequently treated as acts of sabotage or defamation, turning well-intentioned researchers into legal targets. This classification suppresses transparency and discourages any form of independent scrutiny of election systems.
- Even nations that offer some level of protection, like Germany, present their own challenges. While Germany provides partial protections, fines levied under GDPR (General Data Protection Regulation) can significantly limit the scope and feasibility of research, making it financially prohibitive for individuals or smaller organizations.
- More authoritarian states, such as China and Russia, employ strict national security laws to explicitly suppress security research, equating vulnerability disclosure with espionage or threats to national stability.
This patchwork of legal frameworks creates an uneven and often hostile environment for researchers, leading to a "chilling effect" that discourages vital work. Owolabi noted that in many emerging democracies, there's a distinct lack of formal channels for responsible vulnerability disclosure. Researchers often work in isolation, without legal counsel, financial support, or institutional protection. Furthermore, election flaws are frequently classified as national security secrets, which actively suppresses transparency and collaboration, deepening a culture of distrust between election bodies and independent researchers. This systemic problem ensures that reporting issues comes at a high personal cost, ranging from intimidation and legal battles to outright arrest, thereby impeding the progress of democratic processes globally.
Key Findings
▶ Watch: Why election security research is critical globally (3:26)
The central "findings" of Owolabi's presentation coalesce around the critical observations of the current global state of election security research and the actionable lessons derived, particularly from the experiences in the Global South. The primary finding is the ubiquitous and severe threat landscape faced by election security researchers, which directly undermines the integrity of democratic systems worldwide. This is not an isolated problem but a systemic one, characterized by a lack of consistent legal protection and a prevailing culture of distrust.
Owolabi's analysis highlighted several key findings:
- Global Prevalence of Researcher Persecution: Through examples from the US, Nigeria, and India, it's evident that researchers globally face arrest, lawsuits, and intimidation for disclosing vulnerabilities. This is a widespread issue, not confined to specific political systems or regions.
- Fragmented and Hostile Legal Frameworks: The current legal landscape is a "patchwork" that fails to protect researchers. Laws like the US CFA, the treatment of disclosures as sabotage or defamation in Nigeria and India, and GDPR fines in Germany, along with strict national security laws in countries like China and Russia, actively impede good-faith research.
- Unique Challenges in Emerging Democracies: The Global South offers stark lessons. Many emerging democracies lack formal, responsible vulnerability disclosure channels. Researchers often operate in isolation, without legal support, and election flaws are frequently deemed "national security secrets," stifling transparency.
- The "Chilling Effect" and Culture of Distrust: The uneven and hostile legal environment creates a "chilling effect," discouraging researchers from reporting critical flaws due to the high personal cost involved. This fosters a deep distrust between election bodies and independent researchers, hindering collaborative security efforts.
- Election Security as a Shared Responsibility: The talk implicitly finds that the current adversarial approach is unsustainable. Election security is not solely the domain of government bodies but a collective responsibility involving researchers, policymakers, civil society, and citizens.
Based on these findings, Owolabi presented a clear vision for a global "safe harbor" for election security research, advocating for "security through openness, not silence." The proposed solutions, derived from the lessons learned, constitute the talk's most significant contributions:
- Clear Legal Immunity: A fundamental requirement is unconditional legal immunity for good-faith security research, irrespective of the researcher's affiliation. This protects individuals when their intent is to improve security, not cause harm.
- Structured Disclosure Protocols: Establishing formal, well-defined protocols for vulnerability disclosure is crucial. This ensures that researchers have clear channels to report findings, preventing the "sale of vulnerabilities" and facilitating timely remediation.
- Enforceable Timelines for Remediation: Disclosure without action is ineffective. Owolabi emphasized the need for enforceable timelines that mandate election bodies to address discovered vulnerabilities promptly, ensuring that research leads to tangible security improvements.
- Independent Review Channels: To arbitrate disputes between researchers, election officials, and legal frameworks, independent review channels comprising civil society representatives, technical experts, and election officials are necessary. This ensures fair and unbiased resolution.
- Cross-Border Cooperation: In an interconnected world, mutual recognition agreements and cross-border cooperation are essential to ensure consistent protection and collaborative problem-solving for global election security challenges.
- Transparency Without Retaliation: The overarching principle must be to foster an environment where transparency in security research is encouraged and never met with retaliation. Recognizing research as a service to democracy, not sabotage, is paramount.
These findings collectively paint a comprehensive picture of the current threats and propose a detailed, multi-faceted strategy for building a more secure and transparent global electoral landscape.
Technical Deep Dive
▶ Watch: Fragmented global legal landscape for researchers (4:09)
This talk does not delve into specific technical vulnerabilities, exploit methodologies, or reverse engineering techniques. Instead, it focuses on the systemic, legal, and policy challenges that directly impact the ability to conduct technical election security research and disclose findings effectively. While the presentation itself is not a technical deep dive into how to find vulnerabilities, it deeply explores the implications of technical vulnerabilities within electoral systems and the mechanisms required to ensure their discovery and remediation.
Owolabi underscored the critical technical reality that underpins the entire discussion: "Elections today are now complex systems where software and hardware meet up and decide the outcomes of elections." This statement highlights the intricate technological stack involved in modern electoral processes, which can include:
- Electronic Voting Machines (EVMs): These can range from direct-recording electronic (DRE) machines to optical scan systems, each with their own software, firmware, and hardware components susceptible to flaws.
- Voter Registration Databases: Digital systems that store sensitive voter information, requiring robust security against unauthorized access, manipulation, or data breaches.
- Tabulation and Reporting Software: Programs used to count votes, aggregate results, and report outcomes, where vulnerabilities could lead to miscounts or altered results.
- Network Infrastructure: The underlying networks connecting electoral systems, which can be targets for denial-of-service attacks or data interception.
- Supply Chain Security: The process of manufacturing and distributing hardware and software for elections, which can introduce vulnerabilities if not rigorously secured.
The speaker emphasized that "a single vulnerability can disenfranchise voters and can affect millions of lives." This refers to any technical weakness—be it a coding error, a hardware design flaw, a misconfiguration, or a logical bypass—that could be exploited to alter votes, compromise voter data, or disrupt the voting process. For instance, a software bug could allow an attacker to change vote tallies, a hardware vulnerability might enable tampering with machine internals, or an insecure network could permit remote manipulation of results.
The role of researchers, from a technical perspective, is to act as proactive ethical hackers, employing methodologies such as penetration testing, vulnerability scanning, code review, hardware analysis, and protocol analysis to identify these flaws before malicious actors do. However, the talk explains that the legal and policy environment often criminalizes these essential technical activities. For example, a researcher attempting to access "public files" (which might involve examining publicly available network configurations or system logs) or analyzing the firmware of an electoral machine could be accused of "unauthorized access" under laws like the US CFA, even if their intent is purely defensive. Similarly, publicly disclosing a technical flaw found in an EVM could be deemed sabotage or defamation, as seen in Nigeria and India.
The proposed structured disclosure protocols are fundamentally technical in their application. They aim to create a standardized, secure channel for communicating technical details of vulnerabilities to election officials. This prevents researchers from having to resort to insecure or public methods of disclosure, which could inadvertently aid adversaries. Furthermore, enforceable timelines for addressing vulnerabilities directly relate to the technical patching cycles and software/hardware updates required to mitigate identified risks. Without these protections and channels, the technical work of identifying flaws becomes futile or dangerous for the researcher, leaving critical systems exposed. In essence, the talk argues that effective technical security for elections cannot exist without the concomitant legal and policy frameworks that protect and empower the technical experts who safeguard them.
Demo / Proof of Concept
▶ Watch: Lessons from Global South: unique challenges, high personal cost (6:27)
The presentation did not include a live demonstration or a specific proof of concept of an election system vulnerability or exploit. Instead, the talk focused entirely on the critical policy and legal frameworks necessary to enable secure election systems by protecting the researchers who identify vulnerabilities. The "proof" offered was in the form of real-world examples of researchers facing adverse legal and personal consequences, underscoring the urgency and reality of the problem being discussed.
Defensive Implications
▶ Watch: Addressing the culture of distrust in election research (7:50)
The defensive implications arising from Miracle Owolabi's talk are not about patching specific software or implementing a particular cybersecurity tool, but rather about establishing a robust, systemic defense for democratic processes by protecting the very individuals who identify its weaknesses. The core defensive strategy advocated is the creation of a global "safe harbor" for election security researchers, embodying the principle of "security through openness, not silence" (SABLE).
For governments and policymakers, the defensive imperative is clear:
- Enact SABLE Laws and Legal Immunity: Governments must create explicit laws that grant legal immunity for good-faith security research. This means distinguishing between malicious hacking and ethical vulnerability disclosure, ensuring that researchers are protected from charges like "unauthorized access" (as seen with the US CFA) or accusations of sabotage/defamation (as in Nigeria and India). This legislative action is the foundational defense against the chilling effect.
- Establish Structured Disclosure Protocols: Implement clear, formal, and secure channels for researchers to report vulnerabilities. These structured disclosure protocols should define the process, expected timelines for acknowledgment, and mechanisms for communication, ensuring that critical information reaches the right authorities without being sold on black markets or publicly exposed prematurely.
- Mandate Enforceable Timelines for Remediation: Disclosure is only the first step. Governments must establish enforceable timelines that compel election bodies to address and mitigate discovered vulnerabilities promptly. This ensures that research translates into actual security improvements, preventing known flaws from lingering (as highlighted by the Nigerian example).
- Create Independent Review Channels: To arbitrate disputes that may arise between researchers and election officials, independent bodies composed of representatives from civil society, technical experts, and election officials should be established. These channels provide a fair and unbiased forum for resolving conflicts and building trust.
- Foster Cross-Border Cooperation: In an interconnected world, election security threats are global. Governments should pursue mutual recognition agreements and other forms of cross-border cooperation to ensure consistent protection for researchers and collaborative responses to shared vulnerabilities.
For NGOs and legal teams, the defensive role involves:
- Providing Legal Defense and Advocacy: Offering pro-bono legal counsel and public advocacy for researchers who face legal threats, arrests, or intimidation. This acts as a crucial shield for individuals, ensuring they are not left isolated against powerful state apparatuses.
For civil society and citizens, the defensive action is to:
- Demand Transparency and Support Ethical Disclosure: Public pressure and support are vital. Citizens should advocate for greater transparency in election systems and actively support ethical security research, shifting the narrative to recognize researchers as guardians of democracy, not adversaries.
For researchers themselves, while seeking protection, the defensive call is to:
- Maintain Ethical Engagement: Continue to engage in good-faith security research, adhering to ethical disclosure practices, and understanding their role as part of a larger, shared responsibility for democratic integrity.
Ultimately, the most profound defensive implication is that protecting researchers directly protects democracy itself. When researchers feel safe and supported, ethical disclosures increase, leading to more immediate fixes for vulnerabilities. This, in turn, strengthens public trust in electoral processes, fosters global cooperation among security experts and governments, and keeps skilled researchers engaged and motivated rather than discouraged. By creating a safe haven for those who safeguard our democratic foundations, we build a more resilient and trustworthy electoral future.
Key Takeaways
- Election security researchers globally face severe risks: Individuals who identify vulnerabilities in electoral systems are frequently subjected to arrest, lawsuits, and intimidation instead of recognition.
- Fragmented legal frameworks hinder security: A patchwork of inconsistent national laws, including the US CFA, defamation laws in some countries, and GDPR fines, creates a hostile environment that stifles good-faith security research.
- "Security through openness, not silence" is paramount: The core principle for enhancing election security is to encourage transparency and ethical disclosure rather than suppressing research.
- A global framework for researcher protection is urgently needed: This framework should include clear legal immunity for good-faith research, structured disclosure protocols, enforceable timelines for vulnerability remediation, and independent review channels for disputes.
- Protecting researchers is essential for protecting democracy: By safeguarding those who uncover flaws, governments ensure that critical vulnerabilities are addressed, thereby strengthening public trust and the integrity of electoral processes.
- Election security is a shared responsibility: Effective solutions require collaborative efforts from governments, policymakers, NGOs, legal teams, civil society, citizens, and researchers themselves.
About the Speaker(s)
Miracle Owolabi is a dedicated cybersecurity professional and a passionate advocate for the global protection of security researchers. Representing the Election Integrity Foundation, Owolabi champions the cause of individuals working to secure democratic processes worldwide. Her work emphasizes the critical role of ethical security research in maintaining electoral integrity and the urgent need for legal and policy frameworks to safeguard these vital contributors.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A policy-lane talk at a niche venue where the topic is genuinely important and underserved. Owolabi makes a coherent case for researcher safe-harbor frameworks with real-world examples that most attendees won't have heard laid out this way. The argument is sound but the content stays at the level of well-organized advocacy — no new data, no legal analysis with teeth, no insider access to rulemaking.
Heather Calloway (CISO) — SOLID
Owolabi identifies a real and under-addressed problem — the legal exposure of election security researchers — and grounds it in credible cross-jurisdictional examples. The talk is advocacy-forward and the framework it proposes is directionally correct, but it stays at the surface of both the policy and operational dimensions, leaving security leaders without a concrete decision path.