CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

In letter to federal Election Assistance Commission, investigators from CA's unprecedented e-vote review blast the approval of flawed protocols in certification tests for new Diebold e-voting system...

Share article:

A group of computer scientists and security experts from California’s 2007 landmark “Top-to-Bottom Review” (TTBR) of electronic voting systems have sent a two-page letter [PDF] of condemnation to the U.S. Election Assistance Commission (EAC), taking the federal body to task for their approval of misused security findings from the TTBR in recent certification testing for a new e-voting system made by Diebold/Premier.

The voting system, Premier’s Assure 1.2 — made by Premier Election Solutions, Inc. (formerly named Diebold Election System, Inc. and recently purchased by Election System and Software, Inc.) — was granted federal certification by the EAC last August under new test protocols which “should not have received the EAC’s approval,” according to the letter penned by Aaron Burstein and Joseph Lorenzo Hall, and signed by twelve other investigators and participants in the TTBR project.

The letter was addressed to the EAC’s Director of Testing and Certification Brian Hancock, a longtime official at the commission with a disturbing background of helping to hedge test results for other electronic voting systems…

‘Completely Inadequate’

The test plan approved by the EAC’s Hancock for the Assure system, the scientists argue in their letter, allowed iBeta Laboratories to test the Premiere/Diebold combination optical-scan and Direct Recording Electronic (DRE, touch-screen) voting system based on a fundamentally misunderstood interpretation of an important finding from the TTBR study.

“iBeta interpreted the TTBR studies of the Premier system’s predecessor [the older systems made by Diebold] to have ‘concluded that the vulnerabilities within the system depend almost entirely on the effectiveness of the election procedures,'” write Burstein and Hall. “On the basis of this interpretation, iBeta developed a test plan that called for ‘no additional testing’ of the Premier system’s security properties. The EAC approved this plan.”

The EAC’s new testing regime was recently implemented in light of years of disastrous testing in which systems had been tested in secret by labs selected and paid for by the voting system manufacturers themselves. The result was the failed e-voting systems which now litter the nation’s electoral landscape. Those systems, almost every single one of them, have now been found in independent scientific study after study, including CA’s TTBR, “an unprecedented, in-depth evaluation of California’s voting systems, which allowed investigators to gain a better understanding of their vulnerabilities,” according to the letter, to be extraordinarily insecure on virtually every level, frequently unreliable and often inaccurate in their results.

The TTBR resulted in California’s decertification of a number of systems previously approved under the old EAC-overseen testing procedures. It would appear that the new testing system may be as riddled with problems and possible failure as the old one, at least if the EAC’s questionable certification of the Premier Assurance system, as described in the letter from the CA investigators, is any indication.

More from the Burstein/Hall letter:

iBeta’s misunderstanding of the significance of the TTBR findings and the EAC’s approval of a test plan that was designed around this misunderstanding, represent a missed opportunity to use the testing and certification process to improve voting system integrity and reliability.

iBeta misunderstands the results of the TTBR. The TTBR concluded that the number, extent, and severity of these vulnerabilities were so substantial that the technological security mechanisms were completely inadequate to protect the integrity and security of both the systems and of the election.[1] This directly contradicts the statement that “the vulnerabilities within the system depend almost entirely upon the effectiveness of the election procedures.” The vulnerabilities are present, regardless of the election procedures. The team concluded that these flaws were so severe as to render the system’s technological security measures essentially without value; these vulnerabilities could only be mitigated by the strictest of procedures. The California Secretary of State’s response to the TTBR was to decertify two systems until their respective vendors, one of which was Diebold,[2] fixed many problems with their security mechanisms. Even now, these machines are subject to strict new procedural rules designed to mitigate the vulnerabilities which remain. Such drastic measures were necessary precisely because the underlying vulnerabilities were not detected and analyzed during conformance testing.

iBeta’s light treatment of the TTBR results, therefore, should not have received the EAC’s approval.
_________________________

1 Other studies, such as the EVEREST study that the Ohio Secretary of State sponsored, reached similar conclusions.

2 At the time of the TTBR, Diebold, Inc. had yet to change the name of its election systems subsidiary from Diebold Election Systems to Premier Election Solutions.

The 101-page iBeta test plan [PDF] was approved earlier this year by the EAC’s Director of Testing and Certification, Brian Hancock, who notified [PDF] iBeta on April 7, 2009 “that the tests proposed, if performed properly, appear to be sufficient to fully test the system.”

The Assure 1.2 voting system was then officially certified by the EAC [PDF] on August 6th of this year, as the third “to achieve federal certification” under the EAC’s new “Voting System Testing and Certification Program.”

Hancock’s Dubious History at the EAC

It should be noted here that Hancock played a key role at the EAC in 2004, by improperly giving a “qualification number” (the phrase the EAC now uses to describe successful federal certification testing under the previous test regime) to the Sequoia Edge with Verivote Printer touch-screen voting system. The number was officially granted for the system even though testing had not been fully completed by the test labs — where the system had been failing miserable — in violation of the EAC’s own “qualification” procedures at the time.

The sleight-of-“qualification”-hand was essentially carried out in apparent hopes of legitimizing Nevada’s illegal use of that particular voting system in 2004, for the first time, where it had been used without a “qualification number,” in violation of state law, in the September primary. That, even though then-SoS, now U.S. Congressman Dean Heller (R) had lied to the press and public by telling them, in July of that year, that the system “has passed federal certification with flying colors.”

Between the September Primary and the November Presidential General Election, Hancock issued the “qualification number,” commonly known as “federal certification” back then, to the Sequoia Edge with Verivote system. The completion of the paperwork by the test lab, allowing for the qualification to be issued, would not officially be completed until December 21, 2004. The system would not be officially certified in the state of Nevada until January 12, 2005, as documents obtained by The BRAD BLOG’s long efforts at public records requests has revealed.

The entire EAC/Nevada/Sequoia scam described above is documented at length in “The Selling of the Touch-Screen ‘Paper Trail’: From Nevada to the EAC,” an investigative report we contributed with Michael Richardson and John Gideon as a chapter for Mark Crispin Miller’s 2008 book Loser Take All: Election Fraud and The Subversion of Democracy, 2000-2008.

In requesting a comment from Hancock and EAC spokesperson Jeannie Layson in regard to the letter from the CA investigators, we were told that the commission is preparing a formal reply to the authors. We will update this item appropriately when we receive a copy of that reply.

UPDATE 10/22/09: The EAC has finally responded today, with a letter in reply [PDF]. The reply from Hancock seems to attempt to rebut Hall/Burstein’s assertion that iBeta’s tests did “‘no additional testing’ of the Premier system’s security properties.” The scientists tell us they’re reviewing the letter and may be preparing their own response in turn. If they do, we’ll update again.

The BRAD BLOG covers your electoral system, fiercely and independently, like no other media outlet in the nation. Please support our work with a donation to help us keep going.Please CLICK HERE to help support our work today!

Share article:

--- COMMENTS follow below Ad Content ---

Reader Comments on

CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

2 Comments

(Comments are now closed.)


2 Responses

  1. 1)
    David Jefferson said on 10/16/2009 @ 6:08pm PT: [Permalink]

    Just a note of clarification, the signers were computer scientists and scholars involved in the TTBR from all over the U.S., not just from California.

  2. Avatar photo
    2)
    Brad Friedman said on 10/17/2009 @ 10:55am PT: [Permalink]

    Thanks for helping to clarify, David. I had the most difficult time explaining clearly who the authors/signatories exactly were in this story for some reason!

    BTW, any particular reason you were not one of the signatories? I was surprised to see your name NOT on the letter.

(Comments are now closed.)


--- Ad Content ---

BB SIDEBAR NOTICE

Thanks to you, The BRAD BLOG has been trouble-making and muckraking for … 22 YEARS!!!

Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman / BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

Dead Ends: Iran, Platner, McConnell: ‘BradCast’ 7/9/2026

Guest: Prof. David Faris, Roosevelt University author, political scientist...

‘Green News Report’ – July 9, 2026

with Brad Friedman & Desi Doyen...

John Roberts and his Corrupt Republican SCOTUS Majority Winning the Long Game: ‘BradCast’ 7/8/2026

Guest: Former Dep. Asst. A.G. Lisa Graves on the Chief Justice's decades-long fights to undermine voting rights, expand Presidential power...

The Trump Crime Family’s Staggering Second-Term Crime Spree Comes into View: ‘BradCast’ 7/7/2026

Also: Platner support collapses in ME; How Trump's 'Freedom 250' hijacked America's 250th birthday...using wire fraud to do it...

‘Green News Report’ – July 7, 2026

with Brad Friedman and Desi Doyen...

Maine U.S. Senate Race Rocked by Sexual Assault Claim; Callers Want Platner to Stay In: ‘BradCast’ 7/6/2026

Dem candidate 'categorically' denies 'false' allegation, but 'taking time to reflect on best path forward...and goal of defeating Susan Collins' ahead of July 13 deadline to drop out and be replaced by state party...

Sunday ‘One Small Step for Americans…’ Toons

THIS WEEK: SCOTUS Out ... Birthday Blues ... Fair/Enough ... Grift in Plane Sight ...

SCOTUS Hot Takes: Mailing it In

Hitting the road, but with some VERY quick thoughts before we go...

Sunday ‘A Quack in the Case’ Toons

THIS WEEK: Wet Dreams ... Trump's 250th ... SCOTUS Bloody SCOTUS ... Elon Bloody Elon ...

Court Blocks Trump’s Executive Power Grab Seeking to Nationalize Vote-By-Mail Eligibility

Federal judge rules the U.S. Postal Service cannot refuse to deliver mail-in ballots based upon a federal 'Confirmed Citizen List'...

‘So Stupid it Makes Your Head Explode’: ‘BradCast’ 6/25/2026

Guests: Heather Digby Parton of Salon, 'Driftglass' of 'Pro Left Podcast' on court rulings (good and awful), Dem Primaries, Trump's 'Deflecting Pool' and more...

‘Green News Report’ – June 25, 2026

with Brad Friedman & Desi Doyen...

Help Stop Trump’s Project 2025 Scheme to Kill Science: ‘BradCast’ 6/24/2026

Guest: Dr. Colette Delawalla of Stand Up for Science; Also: Judge nixes Trump election rigging order; Mamdani's progressives sweep; Primary results from UT, MD, SC, NY...

The Horses Races AND The Track Conditions: ‘BradCast’ 6/23/2026

The real reason Trump endorsements matter; SCOTUS v. VRA again; Judge blocks Admin vote suppression tool; GOP meddling in Dem primaries; Senate Repubs to finally stand up to Trump?...

‘Green News Report’ – June 23, 2026

with Brad Friedman & Desi Doyen...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster.
Full Bio & Testimonials…
Media Appearance Archive…
Articles & Editorials Elsewhere…
Contact…

He is featured in these documentary films…
…And has contributed chapters to these books…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally syndicated, Monday-Thursday, on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneIn | Apple Podcasts/iTunes | iHeart | Amazon Music
GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneIn | Apple Podcasts/iTunes | iHeart | Amazon Music
Media Appearance Archives…

--- Ad Content ---

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards