Welcome and Introductions

Voting Village @ DEF CON 33 · Day 1 · Voting Village

Overview

This talk serves as the foundational opening remarks for the Voting Village at Defcon, an annual gathering dedicated to election security research. Delivered by key organizers including Matt Blae, chair of the Election Integrity Foundation (EIF), and Susan Greenholm from Free Speech for People, the session outlines the village's critical mission: to foster independent security research into election systems and openly confront their vulnerabilities. The speakers emphasize the urgent need to separate "fact from fiction" regarding election integrity, arguing that a candid assessment of system weaknesses is paramount for safeguarding democracy.

Watch on YouTube

Visual summary for Welcome and Introductions
Visual summary for Welcome and Introductions

Key moments

  1. 0:00 Welcome to Voting Village: purpose and security research
  2. 2:15 Free Speech for People's mission on election security
  3. 3:45 Confronting uncomfortable truths about election machine vulnerabilities
  4. 4:05 Overview of upcoming talks: audits, breaches, ground truth
  5. 5:50 Engaging the public in understanding voting machine implications
  6. 7:45 Making election vulnerability information accessible to average voters

Welcome and Introductions

Speakers: Matt Blae (Chair, Election Integrity Foundation), Susan Greenholm (Senior Advisor for Election Security, Free Speech for People), Kendall Spencer (Council & Board Member, EIF), David Jefferson (Board Member, EIF), Cat (Executive Director, EIF)

Conference: Voting Village

YouTube: https://www.youtube.com/watch?v=YBcJEiP_k7k

Overview

This talk serves as the foundational opening remarks for the Voting Village at Defcon, an annual gathering dedicated to election security research. Delivered by key organizers including Matt Blae, chair of the Election Integrity Foundation (EIF), and Susan Greenholm from Free Speech for People, the session outlines the village's critical mission: to foster independent security research into election systems and openly confront their vulnerabilities. The speakers emphasize the urgent need to separate "fact from fiction" regarding election integrity, arguing that a candid assessment of system weaknesses is paramount for safeguarding democracy.

The talk highlights the Voting Village's unique role in providing a safe and legal environment for security researchers to engage directly with voting machines, leveraging a specific exemption to the Digital Millennium Copyright Act (DMCA). This initiative is crucial because it addresses a significant gap in public understanding and official transparency concerning the true state of election infrastructure. By enabling hands-on, unconstrained research, the Voting Village aims to provide objective data and insights that can inform better security practices, advocate for stronger policies, and empower citizens with accurate information about the systems that underpin their democratic process.

Background

▶ Watch: Welcome to Voting Village: purpose and security research (0:00)

The genesis of the Voting Village and its mission is deeply rooted in the evolving landscape of cybersecurity law and the increasing digitization of democratic processes. Historically, the Digital Millennium Copyright Act (DMCA) posed a significant hurdle for security researchers, as its provisions effectively criminalized the reverse engineering of software-based systems, including voting machines. This created a paradoxical situation where the very tools essential for democratic governance were shielded from independent security scrutiny, leaving potential vulnerabilities undiscovered and unaddressed.

A pivotal turning point arrived with the 2017 good-faith security research exemption to the DMCA. This exemption, a hard-won victory for the security community and advocacy groups, created a legal pathway for researchers to examine software systems for security flaws without fear of legal reprisal. It was in the wake of this exemption that the Election Integrity Foundation (EIF) was formed, specifically to create platforms like the Voting Village. As Matt Blae explains, this exemption "allowed for the first time to get a room full of voting machines and let people loose on them." This historical context underscores the village's foundational principle: that open, independent research is not just beneficial, but essential for the security and trustworthiness of election systems.

Prior to the establishment of such venues, public discourse around election security was often polarized, with official entities frequently downplaying or outright dismissing concerns about vulnerabilities. Susan Greenholm of Free Speech for People articulates this challenge, noting that "weaknesses in our election infrastructure have become taboo" even among those sounding alarms about attacks on democracy. The Voting Village directly confronts this taboo, operating on the belief that burying "uncomfortable facts" about machine vulnerabilities is a disservice to democracy. The organization’s long-standing program on election security aims to improve the "security, reliability, and practices for better elections" by shining a light on these issues. David Jefferson, an EIF board member with 26 years of experience in election cybersecurity, further emphasizes the enduring nature of these challenges, especially concerning areas like internet voting. The problem, therefore, is not merely the existence of vulnerabilities, but the systemic resistance to acknowledging and addressing them through transparent, independent means.

Key Findings

▶ Watch: Confronting uncomfortable truths about election machine vulnerabilities (3:45)

While this specific session served as an introduction rather than a presentation of new technical findings, it articulated several overarching "findings" or core principles that drive the Voting Village's work and represent its collective contributions to election security discourse.

Firstly, the most significant "finding" is the ubiquity and gravity of election system vulnerabilities that often go unacknowledged or unaddressed by official channels. The speakers repeatedly emphasize that despite widespread concerns about democratic integrity, discussions about the inherent weaknesses in election infrastructure are frequently suppressed. Susan Greenholm asserts, "we can't afford to bury the uncomfortable facts about these machines on which our democracy rests." The village's existence and its annual reports serve as a testament to the continuous discovery of critical flaws, ranging from software exploits to hardware tampering possibilities, which collectively pose a real threat to the integrity of vote counts.

Secondly, the Voting Village has consistently found that independent, good-faith security research is indispensable for identifying and validating these vulnerabilities. Matt Blae highlights that some of the talks on the current year's agenda originated from work done at the previous year's village, demonstrating the direct impact of providing a platform for researchers. This continuous feedback loop ensures that new attack vectors and overlooked weaknesses are brought to light, often by individuals outside the vendor or government certification ecosystem. The freedom to "break things in interesting ways" and report those findings is core to this discovery process.

Thirdly, a critical finding is the significant knowledge gap among the general public regarding election system fundamentals and vulnerabilities. Cat, the Executive Director of EIF, stresses her interest in making the research accessible to the "average voter." She observes that many people "don't even understand sometimes the gravity of the vulnerabilities that we're talking about because often times people don't understand the fundamentals of how our election system works." This includes basic questions about machine types, ownership, and the real-world implications of identified flaws. The Voting Village implicitly "finds" that education and interactive engagement are crucial components of true election security, beyond just technical fixes.

Finally, the cumulative work of the Voting Village consistently "finds" that existing post-election audits are often insufficient or lack the rigor required to definitively prove election correctness. Susan Greenholm explicitly mentions that attendees will "hear about the reality of our post-election audits and how they are strong and how they are not strong." This indicates a systemic finding that current audit practices, while well-intentioned, may not always provide the robust evidence needed to instill full public confidence or detect subtle but impactful manipulation. The village's work, therefore, serves as a continuous challenge to the status quo, pushing for more transparent, verifiable, and resilient election processes.

Technical Deep Dive

▶ Watch: Overview of upcoming talks: audits, breaches, ground truth (4:05)

The introductory talk itself did not present a specific technical deep dive into a newly discovered vulnerability or a particular piece of election infrastructure. Instead, it provided a deep dive into the methodology and philosophy of technical security research as applied to election systems within the unique context of the Voting Village. The "technical deep dive" here refers to the operational framework that enables such research.

At its core, the Voting Village facilitates hands-on reverse engineering and vulnerability discovery on actual voting machines. This is made possible by the 2017 good-faith security research exemption to the DMCA. This legal protection is critical because it allows researchers to bypass the usual legal barriers associated with examining proprietary software and hardware. Without this exemption, any attempt to analyze the internal workings of a voting machine—which often involves disassembling hardware, analyzing firmware, or decompiling software—could be construed as a violation of intellectual property laws, despite the public interest in ensuring election integrity.

The technical environment provided by the Voting Village involves a "room full of voting machines," as Matt Blae describes. These machines are often a mix of various models and generations, representing the diverse and sometimes outdated technologies in use across different jurisdictions. Researchers are encouraged to "let people loose on them" and to "break things in interesting ways." This informal but highly effective approach allows for:

  1. Hardware Analysis: Researchers can physically inspect the machines, looking for exposed ports, insecure enclosures, or easily accessible internal components. This includes examining motherboards, storage media (e.g., USB drives, SD cards, hard drives), and network interfaces for potential vulnerabilities.
  2. Firmware and Software Reverse Engineering: With the DMCA exemption, researchers can extract firmware, analyze proprietary operating systems, and examine the vote-counting logic. This involves using tools for binary analysis, disassemblers (e.g., IDA Pro, Ghidra), and debuggers to understand how the software operates, identify potential backdoors, insecure coding practices, or exploitable flaws.
  3. Network Protocol Analysis: If machines have network capabilities (e.g., for transmitting results), researchers can analyze the communication protocols for weaknesses like unencrypted data transmission, lack of authentication, or susceptibility to man-in-the-middle attacks.
  4. Side-Channel Attacks and Physical Tampering: Beyond purely digital exploits, researchers also investigate the potential for physical manipulation, such as inserting malicious software via USB, altering ballot images, or exploiting physical access to change vote totals. The village environment allows for testing scenarios that might not be feasible in a real-world, highly controlled election setting but represent critical attack vectors if security protocols are breached.

The emphasis on "interesting ways" of breaking things suggests a focus on novel attack techniques, identifying systemic design flaws, and demonstrating practical exploitability rather than just theoretical vulnerabilities. This collective, open-source approach to security research, where findings are shared and discussed, contrasts sharply with the often opaque and vendor-controlled environment surrounding official election system certifications. The EIF's commitment to publishing "all of our previous reports, all vulnerabilities, descriptions of voting machines" on votingvillage.org further solidifies this commitment to a transparent, technically driven approach to improving election system security.

Demo / Proof of Concept

▶ Watch: Engaging the public in understanding voting machine implications (5:50)

This particular session, being an introductory address, did not feature a live demonstration or a specific proof of concept (PoC) of a newly discovered vulnerability. The speakers were setting the stage for subsequent talks and the overall activities within the Voting Village.

However, the entire ethos of the Voting Village is built upon the principle of demonstrating practical vulnerabilities through hands-on engagement. The core activity described by Matt Blae—"we have a room full of voting machines and we're going to let you loose on them"—directly implies that participants are encouraged to develop and execute their own proofs of concept. The invitation to "break things in interesting ways" and to "tell us about it because we want to include that in our report and also invite you back next year to give a talk on what you found" explicitly frames the village as a proving ground for security research.

Throughout the Defcon Voting Village, researchers typically perform various types of demonstrations:

  1. Software Exploits: PoCs often involve demonstrating how malicious code can be injected into voting machines via USB ports, network connections, or even through compromised ballot-loading procedures. These might show how to alter vote counts, change candidate names, or crash the system.
  2. Hardware Tampering: Demonstrations can include physically opening machines to replace components (e.g., memory cards, motherboards), install spy devices, or manipulate internal switches to alter functionality.
  3. Firmware Modification: Researchers might demonstrate how to extract, modify, and re-flash a machine's firmware to introduce backdoors or manipulate election logic at a low level.
  4. Network-Based Attacks: For machines with network connectivity (e.g., for election night reporting), PoCs might show how to intercept, alter, or inject data during transmission, highlighting vulnerabilities in communication protocols.
  5. Supply Chain Attacks: While harder to demonstrate live, discussions and theoretical PoCs often revolve around how vulnerabilities could be introduced during the manufacturing or deployment phases of voting equipment.

The purpose of these demonstrations, while not part of this specific talk, is critical to the Voting Village's mission. They move beyond theoretical discussions of vulnerabilities to concrete, reproducible proof that these systems can be compromised. This practical evidence is vital for convincing election officials, policymakers, and the public about the urgent need for enhanced security measures and more robust, verifiable election processes. The "interactive educational environment" described by Cat aims to make these complex technical demonstrations understandable and accessible to a broader audience, bridging the gap between highly technical findings and their real-world implications for democratic integrity.

Defensive Implications

▶ Watch: Making election vulnerability information accessible to average voters (7:45)

The insights and philosophy presented in the introductory remarks, when combined with the overall mission of the Voting Village, carry profound defensive implications for election administrators, policymakers, and the public. The overarching message is that ignoring or downplaying vulnerabilities is a critical defensive failure; instead, proactive engagement and transparency are essential.

  1. Embrace Independent Security Audits and Research: The primary defensive implication is the absolute necessity for election systems to be subjected to continuous, independent security research, akin to what the Voting Village facilitates. Relying solely on vendor-provided certifications or internal assessments is insufficient. Election officials should actively welcome and even fund good-faith security research, providing access to machines and documentation under secure conditions, rather than viewing researchers as adversaries. The DMCA exemption for good-faith research is a legal framework that should be fully leveraged and supported.
  1. Prioritize Transparency and Openness: The speakers' call to "reset the conversation to ground truth" about election systems directly implies a defensive strategy of transparency. When vulnerabilities are discovered, they must be publicly acknowledged, discussed, and addressed. Burying "uncomfortable facts" erodes public trust and leaves systems exposed. Defenders should advocate for open-source election software, publicly available audit logs, and clear documentation of system configurations and changes.
  1. Implement Robust Post-Election Audits: Susan Greenholm's mention of evaluating the strength of post-election audits highlights a critical defensive gap. Defenders must push for the implementation of robust, risk-limiting audits (RLAs) that are statistically sound and capable of detecting even small-scale manipulation. These audits should ideally be conducted independently, with clear procedures for public observation and verification. The goal is not just to count votes, but to verify that the machines counted them correctly and that the outcome reflects voter intent.
  1. Secure the Supply Chain and Physical Access: The nature of vulnerabilities often found at the Voting Village (hardware tampering, software injection) points to the critical need for end-to-end supply chain security. This includes vetting vendors, securing manufacturing processes, and implementing strict physical access controls for all election equipment—from storage facilities to polling places. Defenders must consider that an attack can originate long before election day, through compromised hardware or software components.
  1. Educate Election Officials and the Public: Cat's emphasis on voter education is a crucial defensive measure. A well-informed public is less susceptible to misinformation and better equipped to identify potential irregularities. Election officials, too, need continuous training on emerging threats, secure operational practices, and the importance of cybersecurity hygiene. Understanding "the fundamentals of how our election system works" is a foundational defensive posture for everyone involved.
  1. Advocate for Resilient and Verifiable Systems: Ultimately, the defensive implications push towards advocating for systems that are inherently more resilient and verifiable. This often means moving away from purely electronic systems (known as Direct Recording Electronic - DRE machines) that lack voter-verifiable paper trails, towards systems that produce human-readable paper ballots as the official record. This allows for independent recounts and robust audits, creating a critical defensive layer against software-based attacks. David Jefferson's long-standing work on internet voting also implies a defensive stance against systems that introduce broader attack surfaces and are notoriously difficult to secure.

In essence, the Voting Village's work serves as a continuous warning signal and a blueprint for defensive action: confront vulnerabilities head-on, foster transparency, and empower all stakeholders with the knowledge and tools to protect the integrity of the vote.

Key Takeaways

  • Independent Security Research is Essential: The 2017 DMCA good-faith security research exemption was critical in enabling organizations like the Election Integrity Foundation to legally facilitate independent examination of voting machines, revealing vulnerabilities that might otherwise remain hidden.
  • Transparency Over Taboo: Acknowledging and openly discussing the vulnerabilities in election infrastructure is not an attack on democracy, but a necessary step to strengthen it. Burying "uncomfortable facts" hinders progress and erodes public trust.
  • Hands-On Engagement Drives Discovery: Providing a safe, legal environment for researchers to directly interact with and test voting machines ("break things in interesting ways") is highly effective for discovering practical exploits and systemic flaws.
  • Public Education is a Defensive Layer: There's a significant knowledge gap regarding election system fundamentals and vulnerabilities among the average voter. Educating the public about how these systems work and their potential weaknesses is crucial for fostering informed civic engagement and resilience against misinformation.
  • Audits Need Rigor: Existing post-election audit processes are often insufficient to provide conclusive evidence of election correctness. There's a continuous need to improve and implement robust, statistically sound audits, such as Risk-Limiting Audits (RLAs), to verify election outcomes.
  • Democracy Depends on Verifiable Systems: The ongoing work of the Voting Village underscores that securing democratic processes requires not just technical fixes, but also systemic changes towards more transparent, auditable, and resilient election systems that prioritize verifiability.

About the Speaker(s)

Matt Blae is the Chair of the Election Integrity Foundation (EIF), the non-profit organization primarily responsible for running the Defcon Voting Village. He played a key role in establishing the village after the 2017 good-faith security research exemption to the Digital Millennium Copyright Act (DMCA), which allowed for the legal reverse engineering of software-based systems, including voting machines. His vision is to provide a platform for researchers to identify and report vulnerabilities in election equipment.

Susan Greenholm serves as the Senior Advisor for Election Security at Free Speech for People, a national non-profit legal advocacy organization. Her work focuses on protecting democracy and civil rights, with a particular emphasis on advancing policies to improve the security, reliability, and practices for better elections. She advocates for confronting the "uncomfortable facts" about election system vulnerabilities to safeguard democratic processes.

Kendall Spencer is a Council and Board Member on the Election Integrity Foundation (EIF). His legal practice encompasses privacy, cybersecurity, tech transactions, and corporate M&A. Within the Voting Village, he aims to engage everyday people in discussions about the real-world implications of voting machine vulnerabilities for civics and democracy.

David Jefferson is a Board Member of the Election Integrity Foundation (EIF) and has been actively involved in election cybersecurity work for 26 years. He has served in various advisory roles for five Secretaries of State of California, demonstrating his deep expertise and long-standing commitment to the field. He dedicates much of his time to studying, writing, and speaking about internet voting, a topic he continues to address at the conference.

Cat is the Executive Director of the Election Integrity Foundation and one of the primary organizers of the Voting Village. This marks her fifth year organizing the event, during which she has significantly contributed to its growth and transformation into a "fabulous event." Her passion lies in making complex election security information accessible to the "average voter," fostering an interactive educational environment where curiosity is encouraged, and no question is considered "stupid."

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This is an opening remarks session for the Voting Village — a panel of organizers welcoming attendees and explaining why the village exists. Graded as a panel/intro session, it still delivers almost nothing that couldn't be absorbed by reading the EIF website for ten minutes. The DMCA exemption, the 'we let researchers loose on machines' pitch, the audit-rigor concerns — all of this is boilerplate that has been said at every Voting Village since 2017.

Heather Calloway (CISO) — WEAK

This is an opening ceremony, not a talk. It articulates the right principles — transparency, independent research, audit rigor — but delivers no findings, no accountability frame, and no decision path. The article's attempt to manufacture 'key findings' and a 'technical deep dive' from introductory remarks makes it read longer than it earns.

→ Top-rated talks at Voting Village @ DEF CON 33

All talks from Voting Village @ DEF CON 33