Virginia e-voting systems relied on weak hard-coded passwords, trivial Wi-Fi security, unpatched OS
Meet the e-voting machine so easy to hack, it will take your breath away — Virginia decertifies device that used weak passwords and wasn't updated in 10 years.
Context & Ripple Effects
Virginia pulled the plug on an e-voting device that had gone a decade without an OS update and shipped with hard-coded passwords and trivially breakable Wi-Fi security — a single-state decertification that turned out to be an early sighting of a systemic problem rather than a local anomaly.
What came after confirms it: [[a:946301|Defcon Voting Village researchers later documented detailed vulnerabilities in six machine models still in service]], ES&S was forced to admit to Sen. Wyden that some systems sold between 2000 and 2006 carried a remote-access feature, and by 2018 fourteen states were still running paperless machines experts describe as easily hacked. The story matters because it shows the gap between what vendors certify and what attackers can actually do.
First-order effects
- Virginia election officials lose a certified voting option outright and must fall back on alternative equipment or procedures, absorbing the cost of replacing hardware that was allowed to age ten years without patches.
Second-order effects
- Vendors get dragged into public accountability: Election Systems and Software reversed earlier denials and conceded to Sen. Wyden that systems sold from 2000-2006 included a remote-access feature, while Defcon attendees — including children — hacking machines live forced officials and vendors into a defensive posture they had avoided under certification regimes.
Third-order effects
- If the pattern holds, certification itself becomes the contested ground rather than the fix: the US Election Assistance Commission's proposed standards would allow machines with wireless hardware, drawing expert objections even as replacement of paperless fleets proceeds slowly and unevenly across states.
The trend: US voting-machine security is being driven by demonstrated exploits and forced vendor admissions rather than proactive standards, leaving decertification and uneven state-by-state replacement as the main corrective mechanism.