Security experts say companies that dominate the US election tech market have failed to acknowledge and remedy vulnerabilities in systems used to hold elections
The last few years have been an awakening for Election Systems & Software. Before 2016, very few people were publicly pressing …
Context & Ripple Effects
This story lands mid-arc in a long-running fight over US voting machine security. Experts had been calling for post-election audits to ease doubts about voting systems since late 2016, and by fall 2018 reporting detailed severe vulnerabilities across many levels of the election system just ahead of the midterms.
What changed with this piece is the target: rather than the systems themselves, security experts are pointing at Election Systems & Software and the other dominant vendors for refusing to acknowledge or remedy the flaws — a shift from technical critique to accountability of the companies that control the market.
First-order effects
- Election Systems & Software comes under direct public pressure to respond, alongside its market dominance — the criticism names the vendor, not just its equipment, making remediation a corporate reputation issue rather than a county IT problem.
Second-order effects
- Rivals like Hart InterCivic and Unisyn face the same scrutiny by association, which helps explain why all three major makers later opened their software and hardware to vetted researcher stress-testing in a bid to counter conspiracy theories with transparency.
- County election officials buying equipment gain leverage: documented, publicly acknowledged vulnerabilities become a procurement argument for machines with paper trails over paperless devices.
Third-order effects
- If vendor resistance keeps drawing expert and press attention, the market structure itself becomes the fix — consolidation among a few dominant suppliers means transparency practices like researcher access and auditable paper records get set at the vendor level rather than jurisdiction by jurisdiction.
The trend: US election technology is moving from closed, vendor-controlled secrecy toward externally verifiable systems, pushed by researchers and pulled by post-2016 public distrust.