Election Systems and Software contradicts earlier statements, admits to Sen. Wyden some voting systems sold to states from 2000-2006 had remote access feature
Remote-access software and modems on election equipment ‘is the worst decision for security short of leaving ballot boxes on a Moscow street corner.’ Tweets: @nycsouthpaw , @briankrebs , @kimzetter , and @zackwhittaker Tweets: Southpaw / @nycsouthpaw : Why are voting machine vendors lying all the time? https://motherboard.vice.com/ ... @briankrebs : Good get by @KimZetter on how one of the largest voting machine manufacturers enabled PCAnywhere on systems, and how it is still stonewalling lawmakers seeking answers about the security of these systems https://motherboard.vice.com/ ... Can't wait for election hacking village at DEFCON Kim Zetter / @kimzetter : In February I asked top voting machine maker ES&S if it had ever installed remote-access software on its election-management systems; the company insisted it never had. Now it admits it did install pcAnywhere on machines between 2000-2006. https://motherboard.vice.com/ ... Zack Whittaker / @zackwhittaker : Wow, this @RonWyden quote is something. Installing remote-access software and modems on election equipment “is the worst decision for security short of leaving ballot boxes on a Moscow street corner.” Great story by @kimzetter. https://motherboard.vice.com/ ...
Context & Ripple Effects
ES&S had previously denied installing remote-access software on its election-management systems; the admission to Sen. Ron Wyden that pcAnywhere shipped on machines sold to states from 2000-2006 reverses that position and confirms what security reporters had been pressing the vendor to disclose.
The admission lands in a documented pattern: sources later tied VR Systems' use of remote-access software to a possible opening for tampering with North Carolina voter data in 2016, and researchers found dozens of ES&S systems online despite the vendor's claims its equipment is never connected to the internet — all against a vendor that a ProPublica profile found controls roughly half the US voting machine market.
First-order effects
- Sen. Wyden and other lawmakers now have written confirmation contradicting ES&S's earlier denials, sharpening oversight questions the vendor was already accused of stonewalling.
- States still running election-management systems from the 2000-2006 era face immediate pressure to determine whether their deployments include pcAnywhere or modems.
Second-order effects
- Other voting-equipment vendors come under the same line of questioning about remote-access tools, since the VR Systems case shows the practice extended beyond ES&S.
- The gap between vendor claims and researcher findings — ES&S saying its systems are never online while 35 systems across 10 states were found connected — pushes election officials to demand independent verification rather than vendor assurances.
Third-order effects
- If vendors retain dominant market positions despite repeated security disclosures, accountability shifts from the companies to Congress and outside researchers — a dynamic that culminated years later when three major manufacturers allowed researchers to stress-test their systems for transparency.
- Remote-access capability in election infrastructure becomes a standing audit item for every future procurement, not a legacy footnote.
The trend: US voting-machine vendors are being pushed from denial toward grudging transparency as congressional investigators and independent researchers systematically document security practices vendors once disputed.