2019 Defcon Voting Village findings reveal detailed vulnerabilities related to six models of voting machines, most of which are still in use
and they paint an ugly picture for voting machine security. https://www.wired.com/... @verifiedvoting : How do we make our election infrastructure as secure as possible? By having voter-marked paper ballots, ability for voters to check the accuracy of their ballots and rigorous post-election ballot audits. #Validate2020 Read more from @WIRED: https://www.wired.com/... Jennifer Cohn / @jennycohn1 : Discussing vulnerabilities is critical. But such discussions often overlook the blatant corruption that supports the purchase of such woefully insecure systems & dangerously imply that throwing $$$ at a corrupt system—even without election-security requirements—is the answer. 1/ https://twitter.com/... @metacurity : DEF CON 27 Voting Village Report Released Showing Vulnerabilities in Top Voting Machines Used in Nearly 30 States @lilyhnewman https://www.wired.com/... https://metacurity.com/...
Context & Ripple Effects
This year's Voting Village report builds on last year's event, where attendees including an 11-year-old successfully hacked voting machines while vendors and officials downplayed the results. The difference now is specificity: documented vulnerabilities across six named models, most still deployed — which turns a demonstration into an inventory of live exposure.
It lands alongside two related threads in the coverage: Politico's finding that 14 states used paperless voting machines in 2018 with slow replacement efforts, and Defcon's parallel showcase of a DARPA-funded $10M open-source secure voting prototype. The report also gives Verified Voting and election-security advocates like Jennifer Cohn a concrete artifact to anchor their push for paper ballots and audits.
First-order effects
- Jurisdictions running any of the six compromised models face immediate pressure to justify their continued use heading into the 2020 cycle, since most are confirmed still in service.
- Vendors of those models can no longer dismiss the findings as hobbyist stunts — the report documents specific, model-level weaknesses rather than generic attack claims.
Second-order effects
- Verified Voting's remedy — voter-marked paper ballots, voter verification, and rigorous post-election audits — becomes the de facto checklist for officials under scrutiny, shifting procurement debates from machine features to auditable paper trails.
- Jennifer Cohn's critique reframes the fix: more funding without purchase requirements won't help if corrupt or lax procurement keeps buying insecure systems, putting state purchasing processes themselves on trial.
Third-order effects
- If the pattern holds — annual public hacking reports followed years later by official confirmation, as when CISA acknowledged nine unexploited vulnerabilities in Dominion machines used in at least 16 states — disclosure will keep outrunning remediation, making vendor opacity untenable.
- The structural exit being tested is the DARPA-backed open-source platform on secure hardware: election infrastructure migrating from closed proprietary systems toward publicly inspectable designs, contingent on states actually replacing paperless fleets.
The trend: US election security is shifting from vendor-controlled secrecy toward adversarial public testing paired with paper-ballot and audit mandates, with procurement rules — not research budgets — emerging as the binding constraint.