CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

In letter to federal Election Assistance Commission, investigators from CA's unprecedented e-vote review blast the approval of flawed protocols in certification tests for new Diebold e-voting system...

Share article:

A group of computer scientists and security experts from California’s 2007 landmark “Top-to-Bottom Review” (TTBR) of electronic voting systems have sent a two-page letter [PDF] of condemnation to the U.S. Election Assistance Commission (EAC), taking the federal body to task for their approval of misused security findings from the TTBR in recent certification testing for a new e-voting system made by Diebold/Premier.

The voting system, Premier’s Assure 1.2 — made by Premier Election Solutions, Inc. (formerly named Diebold Election System, Inc. and recently purchased by Election System and Software, Inc.) — was granted federal certification by the EAC last August under new test protocols which “should not have received the EAC’s approval,” according to the letter penned by Aaron Burstein and Joseph Lorenzo Hall, and signed by twelve other investigators and participants in the TTBR project.

The letter was addressed to the EAC’s Director of Testing and Certification Brian Hancock, a longtime official at the commission with a disturbing background of helping to hedge test results for other electronic voting systems…

‘Completely Inadequate’

The test plan approved by the EAC’s Hancock for the Assure system, the scientists argue in their letter, allowed iBeta Laboratories to test the Premiere/Diebold combination optical-scan and Direct Recording Electronic (DRE, touch-screen) voting system based on a fundamentally misunderstood interpretation of an important finding from the TTBR study.

“iBeta interpreted the TTBR studies of the Premier system’s predecessor [the older systems made by Diebold] to have ‘concluded that the vulnerabilities within the system depend almost entirely on the effectiveness of the election procedures,'” write Burstein and Hall. “On the basis of this interpretation, iBeta developed a test plan that called for ‘no additional testing’ of the Premier system’s security properties. The EAC approved this plan.”

The EAC’s new testing regime was recently implemented in light of years of disastrous testing in which systems had been tested in secret by labs selected and paid for by the voting system manufacturers themselves. The result was the failed e-voting systems which now litter the nation’s electoral landscape. Those systems, almost every single one of them, have now been found in independent scientific study after study, including CA’s TTBR, “an unprecedented, in-depth evaluation of California’s voting systems, which allowed investigators to gain a better understanding of their vulnerabilities,” according to the letter, to be extraordinarily insecure on virtually every level, frequently unreliable and often inaccurate in their results.

The TTBR resulted in California’s decertification of a number of systems previously approved under the old EAC-overseen testing procedures. It would appear that the new testing system may be as riddled with problems and possible failure as the old one, at least if the EAC’s questionable certification of the Premier Assurance system, as described in the letter from the CA investigators, is any indication.

More from the Burstein/Hall letter:

iBeta’s misunderstanding of the significance of the TTBR findings and the EAC’s approval of a test plan that was designed around this misunderstanding, represent a missed opportunity to use the testing and certification process to improve voting system integrity and reliability.

iBeta misunderstands the results of the TTBR. The TTBR concluded that the number, extent, and severity of these vulnerabilities were so substantial that the technological security mechanisms were completely inadequate to protect the integrity and security of both the systems and of the election.[1] This directly contradicts the statement that “the vulnerabilities within the system depend almost entirely upon the effectiveness of the election procedures.” The vulnerabilities are present, regardless of the election procedures. The team concluded that these flaws were so severe as to render the system’s technological security measures essentially without value; these vulnerabilities could only be mitigated by the strictest of procedures. The California Secretary of State’s response to the TTBR was to decertify two systems until their respective vendors, one of which was Diebold,[2] fixed many problems with their security mechanisms. Even now, these machines are subject to strict new procedural rules designed to mitigate the vulnerabilities which remain. Such drastic measures were necessary precisely because the underlying vulnerabilities were not detected and analyzed during conformance testing.

iBeta’s light treatment of the TTBR results, therefore, should not have received the EAC’s approval.
_________________________

1 Other studies, such as the EVEREST study that the Ohio Secretary of State sponsored, reached similar conclusions.

2 At the time of the TTBR, Diebold, Inc. had yet to change the name of its election systems subsidiary from Diebold Election Systems to Premier Election Solutions.

The 101-page iBeta test plan [PDF] was approved earlier this year by the EAC’s Director of Testing and Certification, Brian Hancock, who notified [PDF] iBeta on April 7, 2009 “that the tests proposed, if performed properly, appear to be sufficient to fully test the system.”

The Assure 1.2 voting system was then officially certified by the EAC [PDF] on August 6th of this year, as the third “to achieve federal certification” under the EAC’s new “Voting System Testing and Certification Program.”

Hancock’s Dubious History at the EAC

It should be noted here that Hancock played a key role at the EAC in 2004, by improperly giving a “qualification number” (the phrase the EAC now uses to describe successful federal certification testing under the previous test regime) to the Sequoia Edge with Verivote Printer touch-screen voting system. The number was officially granted for the system even though testing had not been fully completed by the test labs — where the system had been failing miserable — in violation of the EAC’s own “qualification” procedures at the time.

The sleight-of-“qualification”-hand was essentially carried out in apparent hopes of legitimizing Nevada’s illegal use of that particular voting system in 2004, for the first time, where it had been used without a “qualification number,” in violation of state law, in the September primary. That, even though then-SoS, now U.S. Congressman Dean Heller (R) had lied to the press and public by telling them, in July of that year, that the system “has passed federal certification with flying colors.”

Between the September Primary and the November Presidential General Election, Hancock issued the “qualification number,” commonly known as “federal certification” back then, to the Sequoia Edge with Verivote system. The completion of the paperwork by the test lab, allowing for the qualification to be issued, would not officially be completed until December 21, 2004. The system would not be officially certified in the state of Nevada until January 12, 2005, as documents obtained by The BRAD BLOG’s long efforts at public records requests has revealed.

The entire EAC/Nevada/Sequoia scam described above is documented at length in “The Selling of the Touch-Screen ‘Paper Trail’: From Nevada to the EAC,” an investigative report we contributed with Michael Richardson and John Gideon as a chapter for Mark Crispin Miller’s 2008 book Loser Take All: Election Fraud and The Subversion of Democracy, 2000-2008.

In requesting a comment from Hancock and EAC spokesperson Jeannie Layson in regard to the letter from the CA investigators, we were told that the commission is preparing a formal reply to the authors. We will update this item appropriately when we receive a copy of that reply.

UPDATE 10/22/09: The EAC has finally responded today, with a letter in reply [PDF]. The reply from Hancock seems to attempt to rebut Hall/Burstein’s assertion that iBeta’s tests did “‘no additional testing’ of the Premier system’s security properties.” The scientists tell us they’re reviewing the letter and may be preparing their own response in turn. If they do, we’ll update again.

The BRAD BLOG covers your electoral system, fiercely and independently, like no other media outlet in the nation. Please support our work with a donation to help us keep going.Please CLICK HERE to help support our work today!

Share article:

Reader Comments on

CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

2 Comments

(Comments are now closed.)


2 Responses

  1. 1)
    David Jefferson said on 10/16/2009 @ 6:08pm PT: [Permalink]

    Just a note of clarification, the signers were computer scientists and scholars involved in the TTBR from all over the U.S., not just from California.

  2. Avatar photo
    2)
    Brad Friedman said on 10/17/2009 @ 10:55am PT: [Permalink]

    Thanks for helping to clarify, David. I had the most difficult time explaining clearly who the authors/signatories exactly were in this story for some reason!

    BTW, any particular reason you were not one of the signatories? I was surprised to see your name NOT on the letter.

(Comments are now closed.)


Thanks to you, The BRAD BLOG has been trouble-making and muckraking for … 22 YEARS!!!

Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman / BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

The BRAD BLOG Reborn…

And it only took 20 years or so...

Corrupt SCOTUS Undermines U.S. Constitution, Guts Last Remaining Protections of Voting Rights Act: ‘BradCast’ 4/29/2026

Guest: Redistricting expert Dan Vicuña of Common Cause; Also: Comey's dumb new indictment; E. Jean Carroll wins again; More new lows for Trump approval...

Trump’s Activist Rightwing ‘Originalist’ Judges Strike Again in Texas: ‘BradCast’ 4/28/2026

Guest: Jay Willis of Balls and Strikes; Also: Dem takes polling lead for U.S. Senate in TX as Repubs brace for 'sour, ugly, bad, bleak' midterm elections...

‘Green News Report’ – April 28, 2026

With Brad Friedman and Desi Doyen

Trump, Repubs Exploit Failed Assassination Plot to Advance Ballroom Blitz: ‘BradCast’ 4/27/2026

What we know about the alleged shooter, Trump's opportunist response, corrupt contracting for the ballroom, fury at being described as a 'pedophile'; Also: Callers ring in!...

Sunday ‘So Much Winning’ Toons

THIS WEEK: Punch Drunk ... Kash Poor ... Forever War ... The Shadow Docket Knows! ...

So Much Losing: ‘BradCast’ 4/23/2026

In Iran, in public opinion, at the ballot box, in the courtroom...

‘Green News Report’ – April 23, 2026

With Brad Friedman & Desi Doyen...

‘A Scammer’s Treasure Trove’: DOGE Bros Stole Your Social Security Data: ‘BradCast’ 4/22/2026

Guest: Nancy Altman of Social Security Works; Also: 'Yes', Virginia, there is a new U.S. House map! (For now)...

Insiders Making a Killing Betting on Trump’s War: ‘BradCast’ 4/21/2026

Guest: Craig Holman of Public Citizen; Also: Judge blocks Admin scheme to prevent wind, solar development; Another TACO Tuesday for Iran...

‘Green News Report’ – April 21, 2026

With Brad Friedman & Desi Doyen...

Week 8: Iran War Lies Continue from Sundowning Gaslighter-in-Chief: ‘BradCast’ 4/20/2026

Also: Approval rating plummets; More Dem overperformance in NJ; VA voters voting; CA primary election chaos; Callers ring in...

Sunday ‘WWJD?’ Toons

THIS WEEK: Paging Dr. Jesus ... Strait Outta Hormuz ... It's What's for Dinner ...

U.S. Middle Eastern ‘War Crimes’ Then and Now: ‘BradCast’ 4/16/2026

Guest: Attorney, former U.S. Army Captain Keith Barber; Also: Eastman disbarred; ICE official charged in MN...

‘Green News Report’ – April 16, 2026

With Brad Friedman & Desi Doyen...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster. Full Bio & Testimonials… Media Appearance Archive… Articles & Editorials Elsewhere… Contact…

He has contributed chapters to these books…
…And is featured in these documentary films…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

Media Appearance Archives…

AD
CONTENT

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards