A Review of Post Election Audits in Swing States
Susan Greenhalgh (Free Speech for People)
Voting Village @ DEF CON 33 · Day 1 · Voting Village
Overview
In this critical talk at the Voting Village conference, Susan Greenhalgh, Senior Advisor for Election Security at Free Speech for People, presented a detailed review of post-election audits conducted in swing states following the 2020 presidential election. The presentation, based on a paper co-authored with David Jefferson titled "Don't Just Trust, Always Verify," delves into the efficacy and transparency of these audits, particularly focusing on whether they genuinely provide evidence-based assurance of election results. Given the inherent vulnerabilities of computerized election systems, post-election audits are often touted as the primary mechanism for ensuring accuracy and resilience. However, Greenhalgh's research reveals significant shortcomings in how these audits are implemented in practice.

Key moments
- 0:00 Introduction to post-election audits and paper ballots
- 2:20 States analyzed and report's purpose on audit myths
- 3:20 Pre-election testing failures and vote counting errors
- 4:00 Voting machine internet connectivity and compromise vectors
- 5:15 Serious 2024 election security breach: software extraction
- 6:40 Key criteria for effective, evidence-based post-election audits
A Review of Post-Election Audits in Swing States
Speakers: Susan Greenhalgh, Senior Advisor for Election Security (Free Speech for People)
Conference: Voting Village
YouTube: https://www.youtube.com/watch?v=5mWnGZWUEMQ
Overview
In this critical talk at the Voting Village conference, Susan Greenhalgh, Senior Advisor for Election Security at Free Speech for People, presented a detailed review of post-election audits conducted in swing states following the 2020 presidential election. The presentation, based on a paper co-authored with David Jefferson titled "Don't Just Trust, Always Verify," delves into the efficacy and transparency of these audits, particularly focusing on whether they genuinely provide evidence-based assurance of election results. Given the inherent vulnerabilities of computerized election systems, post-election audits are often touted as the primary mechanism for ensuring accuracy and resilience. However, Greenhalgh's research reveals significant shortcomings in how these audits are implemented in practice.
The talk underscores the foundational principle that while election systems are computers and thus inherently vulnerable to malfunction, misconfiguration, or malicious compromise, a robust system can be achieved through evidence-based elections. This concept hinges on recording every vote on a verifiable paper ballot and subsequently auditing the election results against these physical records. Greenhalgh's work critically examines the actual quality and methodology of audits performed, challenging the common assertion that "elections are audited, so don't worry." This investigation is crucial for policymakers, election officials, security researchers, and the public to understand the true state of election security and identify areas for urgent reform.
Background
▶ Watch: Introduction to post-election audits and paper ballots (0:00)
The imperative for robust post-election audits stems directly from the nature of modern election systems: they are fundamentally computer systems. As Greenhalgh repeatedly emphasizes, computers are susceptible to a range of issues, from software bugs and misconfigurations to sophisticated cyberattacks. This vulnerability necessitates a shift towards evidence-based elections, where the integrity of machine-tabulated results can be independently verified against a reliable physical record of voter intent. This principle has been a recurring theme throughout the Voting Village conference, highlighting the consensus among security experts regarding the need for resilient election infrastructure.
Greenhalgh addresses several pervasive myths that often diminish the perceived importance of post-election audits. One such myth is that voting systems undergo such rigorous pre-election testing and certification that they are inherently secure. However, real-world incidents contradict this. For example, the Northampton County, Pennsylvania incident in 2019 saw Ballot Marking Devices (BMDs) incorrectly recording votes in their barcodes, failing to match the human-verifiable text. Such errors demonstrate that even with testing, machines can miscount votes, necessitating post-election verification.
Another common misconception is that voting machines are air-gapped and never connected to the internet, thus rendering them immune to compromise. Greenhalgh debunks this by pointing out that some states utilize wireless modems to transmit election results from polling locations to county-level Election Management Systems (EMS) on election night. Both ends of this transmission are exposed to potential internet-based threats. Even in states with stringent "no internet connection" policies, such as California, New York, Texas, and Colorado, machines still receive critical ballot definition files via USB sticks. If the machine used to program these USBs is connected to the internet, it creates an indirect but significant attack vector.
The urgency for effective audits was dramatically heightened by serious security breaches observed in the lead-up to the 2020 election. Greenhalgh specifically references an incident where voting systems from both Dominion and ES&S in several states were improperly accessed by partisan operatives. Software was extracted from Dominion machines and subsequently shared through a file-sharing site with a network of political supporters. This was not an act of responsible disclosure for security research but rather an unauthorized acquisition with unclear motivations and consequences. This incident, described as "the most serious election security breach that we've seen in the country," underscored the critical need for post-election audits to detect and correct any potential manipulation or malfunction arising from such compromises. The lack of a comprehensive investigation into this breach further emphasizes the reliance on robust audit mechanisms to confirm election outcomes.
Key Findings
▶ Watch: Pre-election testing failures and vote counting errors (3:20)
Greenhalgh's review of post-election audits in key swing states revealed a mixed but predominantly concerning picture regarding their effectiveness in providing genuine evidence-based assurance. The findings are categorized into "bad news" and "good news," detailing specific deficiencies and best practices observed.
The "Bad News": Significant Deficiencies Across Multiple States
A central and pervasive issue is the lack of timely and transparent reporting. Michigan and Wisconsin, for instance, published their audit reports months after election results were certified. Michigan's 2020 state audit report wasn't published until April 2021, approximately six months post-election. In 2024 (referring to the most recent election cycle at the time of the talk), Michigan had yet to publish a state-level report, with only some counties releasing partial information. Wisconsin's 2020 audit report was published in March 2021, and while they hand-counted more ballots than any other state, the report lacked granular detail, offering only a summary interpretation by the Wisconsin Election Commission rather than raw data on discrepancies.
Crucially, none of the states claiming to conduct Risk Limiting Audits (RLAs) – namely Georgia, Nevada, and Pennsylvania – actually met the baseline requirements for a true RLA. The most significant failing was the widespread use of electronic devices, such as Ballot Marking Devices (BMDs), for in-person voting. These devices produce ballots where voter intent is often recorded in an unreadable barcode, rather than directly on hand-marked paper, thereby undermining the trustworthiness of the audit trail.
Specific state examples highlight these deficiencies:
- Pennsylvania: Claimed an RLA, but it was conducted on the State Treasurer's race, not the much closer and contested Presidential or Senate races. Pennsylvania also conducts a "2% statistical audit" where counties recount either two precincts or a certain number of ballots. However, these recounts can be done by machine, often using a different machine but one still programmed by the same county EMS. This means that if the EMS had a bug or malicious code, the "audit" machine might replicate the same error, failing to detect the original problem.
- Nevada: Provided "very little information" about its audit, with "scant document[s]" that lacked transparency. While Nevada's laws mention a 2% statistical audit, Greenhalgh's inquiries suggested this had effectively been replaced by the RLA, which itself was found to be deficient.
- North Carolina: Also has a 2% audit, but its implementation can be insufficient. In Mecklenburg County, for example, out of 580,000 ballots, only 1,200 were audited. While a truly rigorous RLA with strong randomization might allow for a small sample, Greenhalgh argues that without such rigor, this falls short of a meaningful audit, effectively being "less than 2%" in practice.
The "Good News": States Demonstrating Best Practices
Despite the widespread issues, Greenhalgh identified states that exhibited stronger audit practices, offering models for improvement:
- Arizona: Conforms to many best practices, making its audits mandatory and conducted before certification. Ballots, machines, and races are randomly selected, and audits expand if discrepancies are found. Critically, Arizona provides a high degree of transparency, posting actual tally sheets for public review. While there's room for improvement (e.g., the expansion mechanism requires every county in a multi-county race to expand for a full hand count), Arizona's approach is commendable.
- North Carolina: Shares several best practices with Arizona, including mandatory hand-count audits conducted before certification, randomized selections, and provisions for expansion. Although it offers less detail than Arizona, it provides an accounting of what was audited.
In summary, Greenhalgh concludes that the majority of audits reviewed are not providing sufficient evidence to confirm election results, emphasizing the urgent need for more rigorous and transparent processes, particularly those focused on verifying physical paper ballots before certification.
Technical Deep Dive
▶ Watch: Voting machine internet connectivity and compromise vectors (4:00)
The technical core of Susan Greenhalgh's presentation revolves around defining and evaluating the criteria for effective post-election audits, particularly in the context of Risk Limiting Audits (RLAs). An effective audit, she argues, must provide evidence-based elections, meaning that the computer-generated results are sufficiently confirmed by evidence of voter intent to be declared accurate.
The key criteria for such an audit include:
- Conducted Before Certification: An audit's primary purpose is to verify results before they are made official. If conducted post-certification, its ability to correct an erroneous outcome is severely diminished, and its evidentiary value for the certified result is moot.
- Mandatory Nature: Audits should not be optional. They must be a required component of the election process to ensure consistent application.
- Trustworthy Record of Voter Intent: This is perhaps the most critical technical point. Greenhalgh, referencing research by experts like Philip Stark (University of California, Berkeley), Rich Dillo (Georgia Tech), and Andrew Appel (Princeton), strongly advocates for hand-marked paper ballots as the gold standard. These ballots directly capture the voter's intent with pen on paper, offering an unambiguous, human-verifiable record.
- The BMD Problem: A significant challenge arises with Ballot Marking Devices (BMDs). While they produce a paper printout, voter intent is often encoded in a barcode that the voter cannot read. The human-readable text on the BMD printout might not match the barcode, as seen in the Northampton County incident. Auditing such ballots by scanning the barcode again on a different machine (as is permitted in Florida) merely checks if two machines count the barcode the same way, not if the voter's actual intent was accurately captured and counted. Experts now largely agree that these paper trails from computerized BMDs are "not reliable enough" for effective auditing, emphasizing the need for the original source document of voter intent.
- Hand Counts, Not Machine Recounts: For true verification, ballots must be counted by hand. Recounting ballots by machine, even a different machine, introduces the same potential vulnerabilities (bugs, malicious programming from the same EMS) that the audit is supposed to detect. If the underlying programming from the EMS is flawed, both the original counting machine and the "audit" machine could make the same error.
- Random Selection: To ensure statistical validity and prevent manipulation, ballots, machines, or races selected for audit must be chosen randomly. Greenhalgh cites instances where election officials pre-sorted ballots or pre-selected precincts known to count correctly to avoid triggering expanded audits, thereby undermining the audit's integrity.
- Inclusion of All Ballot Categories: An effective audit must encompass the entire universe of ballots, including military, overseas, provisional, and absentee ballots. Excluding any segment creates a potential vector for targeted manipulation that could go undetected.
- Public Conduct and Data Availability: Transparency is paramount. Audits should be conducted publicly, and their results, including any discrepancies, should be immediately made available for public review and verification before certification. This allows stakeholders to assess the findings and, if necessary, call for recounts or further investigation.
- Adherence to RLA Requirements: A Risk Limiting Audit (RLA) is considered the "gold standard" because it provides a statistically robust level of confidence that the election outcome is correct, or it will correct the outcome with a known high probability (e.g., 95% or 99%). Key RLA requirements include:
- A trustworthy paper record of voter intent.
- Random sampling of ballots.
- Hand-counting of the sampled ballots.
- A pre-defined risk limit (the maximum chance of certifying an incorrect outcome).
- The ability to expand the audit to a full hand count if discrepancies exceed the risk limit.
- Crucially, they must be conducted before certification to have any impact on the official outcome.
Greenhalgh's analysis reveals that many states claiming to perform RLAs fall short on these technical requirements, particularly concerning the trustworthiness of the voter intent record and the timeliness of the audit. For example, Pennsylvania's 2% statistical audit, which allows machine recounts using potentially similarly programmed systems, directly contravenes the spirit of independent verification inherent in a robust audit. The speaker's emphasis on the distinction between auditing a machine's consistency (e.g., re-scanning a barcode) and auditing the accuracy of voter intent (e.g., hand-counting a hand-marked ballot) is a critical technical distinction for election integrity.
Demo / Proof of Concept
▶ Watch: Serious 2024 election security breach: software extraction (5:15)
The talk by Susan Greenhalgh did not include a demonstration or proof of concept of any technical tools or vulnerabilities. Instead, it focused on a comprehensive review and analytical assessment of existing post-election audit practices and their adherence to established best practices for election security.
Defensive Implications
▶ Watch: Key criteria for effective, evidence-based post-election audits (6:40)
The detailed review of post-election audits presented by Susan Greenhalgh offers crucial defensive implications for election officials, policymakers, and the public dedicated to safeguarding democratic processes.
- Prioritize Hand-Marked Paper Ballots: The most significant defensive measure highlighted is the universal adoption of hand-marked paper ballots as the primary and auditable record of voter intent. States should phase out Ballot Marking Devices (BMDs) that rely on unreadable barcodes for vote tabulation, or at minimum, ensure that the human-readable text on BMD printouts is the definitive record for auditing and that these are hand-counted. This directly addresses the "trustworthy record of voter intent" criterion.
- Implement True Risk Limiting Audits (RLAs) Before Certification: Election jurisdictions must move beyond merely claiming to conduct RLAs and ensure that their audits meet the full technical specifications. This means mandatory, statistically robust, random sampling, hand-counting of ballots, and crucially, conducting these audits before election results are certified. This allows for the correction of erroneous outcomes and builds public confidence.
- Enhance Transparency and Public Access: Audits should be conducted openly, with observers permitted, and all audit data, including raw tally sheets and discrepancy reports, should be immediately made public before certification. This transparency empowers citizens and provides an independent check on the process, reducing opportunities for conspiracy theories rooted in a lack of information.
- Ensure Comprehensive Ballot Inclusion: All categories of ballots (absentee, provisional, military, overseas) must be included in the audit universe. Excluding any segment creates a potential blind spot that adversaries could exploit.
- Advocate for Independent Audit Bodies: Greenhalgh suggested the long-term vision of establishing independent audit boards, separate from the election officials who run the election. This separation of duties, akin to external financial audits, could increase trust and reduce the burden on election staff, potentially leading to faster and more thorough audits.
- Educate Against Misinformation: Defenders must actively counter myths about election system security, such as the infallibility of pre-election testing or the complete air-gapping of machines. A realistic understanding of vulnerabilities underscores the necessity of robust audits.
- Review and Strengthen Audit Expansion Rules: States with audit expansion triggers should review their rules to ensure they are effective. Arizona's current system, requiring all counties in a multi-county race to expand, presents a practical limitation. Rules should enable comprehensive recounts when significant discrepancies are found in any relevant jurisdiction.
- Avoid Machine-Based "Audits" of Machine-Counted Ballots: Recounting ballots by a different machine, especially if both are programmed by the same Election Management System (EMS), offers little defensive value against systemic errors or malicious programming. Hand-counting remains the most reliable method for independent verification.
By adopting these defensive strategies, states can move closer to achieving truly evidence-based elections, where the integrity of every vote is verifiable and transparently confirmed, thereby strengthening the resilience of democratic institutions against both accidental errors and intentional attacks.
Key Takeaways
- Hand-Marked Paper Ballots are Essential: The most reliable record of voter intent is a hand-marked paper ballot. Systems like Ballot Marking Devices (BMDs) that encode votes in unreadable barcodes undermine the integrity of post-election audits.
- Risk Limiting Audits (RLAs) are Critical but Often Deficient: While RLAs are the gold standard for election verification, many states claiming to conduct them fail to meet baseline requirements, particularly regarding the trustworthiness of the paper trail and the timeliness of the audit.
- Audits Must Occur Before Certification: For an audit to meaningfully impact election results and build public trust, it must be completed and its findings acted upon before the election is officially certified.
- Transparency and Public Data are Non-Negotiable: Audits should be conducted publicly, and all results, including raw data on discrepancies, must be immediately accessible for public review and verification.
- Machine Recounts are Not True Audits: Recounting ballots by another machine, especially if programmed by the same Election Management System (EMS), does not provide independent verification against systemic errors or malicious code; hand-counting is necessary.
- Continuous Improvement and Reform are Needed: Most current audit practices are insufficient for providing robust evidence of election accuracy. States like Arizona and North Carolina offer models for best practices, but even they have room for improvement, emphasizing the need for ongoing reform efforts.
About the Speaker(s)
Susan Greenhalgh is a Senior Advisor for Election Security at Free Speech for People, an organization dedicated to upholding constitutional rights and democratic principles. In her role, she focuses on advocating for secure and transparent election processes. Greenhalgh is a prominent voice in the election security community, actively contributing to research and public discourse on the vulnerabilities of voting systems and the importance of robust post-election audits. She was also one of the organizers for the speaker track at the Voting Village conference where this presentation was delivered, demonstrating her deep engagement and leadership within the field. Her presentation was based on a paper she co-authored with David Jefferson titled "Don't Just Trust, Always Verify," reflecting her commitment to evidence-based approaches to election integrity.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Greenhalgh delivers a competent, well-organized policy/audit-review talk that correctly classifies this as a threat-to-process lane rather than a technical research drop. The content is substantive for its lane — state-by-state audit deficiencies, RLA compliance gaps, BMD barcode problems — and the paper it's based on ('Don't Just Trust, Always Verify' with David Jefferson) gives it real grounding. Nothing here will surprise anyone who follows election security closely, but it's a solid reference session for the Voting Village audience.
Heather Calloway (CISO) — SOLID
Greenhalgh's audit review is methodologically sound and the policy diagnosis is clear — most states claiming audit rigor aren't delivering it, and the distinction between auditing machine consistency versus auditing voter intent is the sharpest technical point in the talk. For the Voting Village audience, this is directly useful. The ceiling is a 3 because it stays within that lane without crossing into the institutional accountability questions that would make it resonate beyond election security specialists.