Episode 806 ·

We’re Running Out of Time to Secure US Election Tech with Harri Hursti, Security Researcher & International Speaker

Today, we’re talking to Harri Hursti, Security Researcher & International Speaker. We discuss the impending technological vulnerabilities of the upcoming US election, whether or not they can be mitigated, and what Harri thinks about the future of voting technology in the US.

All of this right here, right now, on the Modern CTO Podcast! 

To learn more about Jothy Rosenberg, check out his WikiPedia here: https://en.wikipedia.org/wiki/Harri_Hursti

Produced by ProSeries Media: https://proseriesmedia.com/

For booking inquiries, email [email protected]

About Harri Hursti

My strengths lie in taking any problem and looking at it from a new angle to find unexpected solutions, having the communication skills needed to manage multi-cultural environments, whether it is bringing the commercial side and technology side of a business together, or getting an international teams in line to achieve a common goal. I have the skills needed to take over and manage a crisis, a chaotic business environment, or one undergoing strategy changes - entrepreneurial to the core. I come with deep, “nuts'n'bolts” level of technical understanding for such field as IP networking and services, telecom and internet communications networks and infrastructures, security, and cloud computing. I have a passion for understanding new technologies before they hit the market, and understand the strategic implications, the disruptive effects, and the new opportunities they bring into the business.

My skills and experience range from managing designs of complex computing environments to the evaluation of security issues around various widely used systems, including some election equipment. I have authored or co-authored number of papers and academic studies about
election security.My podcast, Designing Successful Startups, drops a new episode every Wednesday. The guests are founders and those that support startup founders. Each one is packed with that guest's experiences and lessons learned. It is turning out to be so fun for me and I think useful to current and future founders.

Transcript

(Intro Narrator at 00:00:00) Today, we're talking to security researcher and international speaker, Harri Hursti, about the tech vulnerabilities of US elections and whether or not they can be solved by voting day. You're listening to Joel Beasley, Modern CTO.

(Joel Beasley at 00:00:19) Hi, Harri. How are you, bud?

(Harri Hursti at 00:00:21) I'm good. How are you?

(Joel Beasley at 00:00:22) Wonderful. Where are you calling in from today?

(Harri Hursti at 00:00:25) Okay.

(Joel Beasley at 00:00:27) Very cool. Very cool. Well, I like to just go over quickly how I found you. I was reading an article on Politico, and it said the nation's best hackers found vulnerabilities in voting machines. I actually was on X, and I saw it, and then I clicked it and it happened to be a Politico article. But that there's no time to fix these voting machines. So best hackers found the vulnerabilities in voting machines, no time to fix them for an election. And I saw you were associated with this group that found these vulnerabilities, and I said, Josh, we gotta go talk to Harri.

(Harri Hursti at 00:01:03) Well, first of all, I'm the co-founder of the Voting Village and co-organizer of it. And the other thing is what Politico didn't really capture is, I would say the whole quote is to say, but there's still time to mitigate against the risks. So the bigger problem here is that some of the vulnerabilities have been unfixed for twenty years. And a lot of the things what we published in a number of secretaries' studies back in 2007, they're still out in the wild. And so for that reason, it's unfortunate those things haven't been fixed, but still, it doesn't mean that if something is vulnerable, it doesn't mean it's exploited. And those vulnerabilities just have to be mitigated, and we have to be aware how those exploitations can happen and build a strategy around it.

(Joel Beasley at 00:02:03) So is it safe to say that in the past twenty years with American elections, we've known that there are vulnerabilities that haven't been addressed in our digital voting machines?

(Harri Hursti at 00:02:15) Well, twenty years—let me let me go back because it's important to understand how we got into this mess. Basically, year 2000, Bush versus Gore, huge embarrassment. And instead of understanding why the embarrassment happened, the US did what the US does—throw a lot of money into the problem. And when Congress passed the 2002 Help America Vote Act, creating, give or take, $3 billion of funding, the Congress had an intention that security standards will be enacted before the money is handed out to the states. That didn't happen. Instead, the administration at the time felt, and that's a public statement from them, that elections need more innovation. And so when new agency EAC was created and the voting machines were handed over from FEC, Federal Election Commission to EAC, some of already existing regulations got weakened or not enforced anymore. So basically, 2002, the money came available, and states and counties went to a store buying whatever is being sold. And, of course, that means that you are buying yesterday's technology. These are machines which many of them were old designs already back in 2002. And, of course, back those days, cyber warfare was science fiction. There was no today's understanding of cyber risks or even the word cyber really didn't exist. That was, at the time, mainly thought to be a science fiction word, and last part of the people who now proudly call themselves as cybersecurity practitioners were rejecting the whole word. That's ridiculous. Anyway, so these machines were—and a lot of the machines were designed at a time when there was no real consideration of security whatsoever because there were no understanding of the risks as we have today. And since no new pool of money has been created, there's still these machines which were bought 2002, a lot of those machines are still in use, unfortunately.

(Joel Beasley at 00:04:43) Still machines in use from 2002?

(Harri Hursti at 00:04:46) Yep. Yes. Yes. Yes. And the other problem here is that when, as I said, when EAC was created, there was no—they didn't assess any mandatory rules. So voting machines are certified against volunteer voting system guidelines. It's not the standard, and the keyword is volunteer. So there is—well, from 2005, the standard 1.0, then the 1.1, 2.0, and now newest 3.0. Almost every machine today certified is still certified against the 2005 volunteer guidelines because there's no reason for—that's the easiest way to pass. So there's no requirement for anyone to certify against 1.1 or 2.0 or 3.0. Everybody still today going after the volunteer guidelines of 2005. And only 3.0 actually starts to implement some security measurements. 1.0 is just like humidity test, drop test, you know, safety means the voting machine shouldn't electrocute the voter or poll worker. So it's a very unfortunate state of affairs. So just to recap, so everybody is certifying still against 2005 guidelines, which is basically silent about any kind of security measurements. And even further, this model works in a way that vendor is paying the testing lab, not the government or the buyer. So there is an inherent—a perceived at least perceived conflict of interest. But as a volunteer, it means that the vendor can choose which standards or how the testing is done.

(Joel Beasley at 00:06:39) That's crazy.

(Harri Hursti at 00:06:40) It is crazy. This is something what we as a security community has been flagging since we got involved. And basically, the security community only got involved in 2004, 2005 time frame. But ever since, me and my colleagues in Verified Voting and colleagues throughout the security election, we have been voicing these concerns and the fact that self-regulation doesn't work. This has—up to twenty years of this has proven that self-regulation doesn't work. Actually, even funnier is that some voting system vendors have been suing the states who have demanded higher security standards, claiming that the states don't have a right to demand higher security because that will be giving an unfair competitive edge to other vendors. It's pure insanity. No other industry—

(Joel Beasley at 00:07:40) That's so crazy.

(Harri Hursti at 00:07:41) Is working like this, but this industry is.

(Joel Beasley at 00:07:44) How many—are there a lot of vendors of these machines? Can I just go start a business and become a voting machine vendor?

(Harri Hursti at 00:07:51) So there are three major players. Out of those, the two major players control over 80% of the market. And there is multiple barriers of entry coming to the business. So that's why what when 2005 happened and 2006 happened, there was a number of—a larger number of vendors. And after that, there have been market consolidation. Basically, two main vendors control 80%. One company costs about 10%, and the remaining 10% is then diversified between large number of players. Some of those are outgoing players who are basically still around but haven't made a new voting machine offering for twenty years. Some are new players. So that tells how consolidated the market is.

(Joel Beasley at 00:08:45) That should be broken up from, like, anti—that we have laws for monopolization. Right?

(Harri Hursti at 00:08:51) Well, there was a recent event where a one player exiting the market was acquired by another one of the two. DOJ intervened and forced the worst or half of the assets to the other one of the major players who then back-licensed a lot of stuff. So basically nullifying the antitrust action. So the unfortunate thing—I said we—there is a—this is a classical example when the free market competition doesn't work because it's too consolidated and because there is no regulation. The developing of better systems has not been financially making sense to vendors. So I don't know what is the logic why there is no improvement. Maybe it's just because there's no need for improvement because you can still use the 2005 volunteer guidelines.

(Joel Beasley at 00:09:55) Which is an oxymoron, volunteer guidelines. It doesn't even really make sense. If you're gonna have guidelines, make a standard.

(Harri Hursti at 00:10:03) Well, this was—this was a, back then, Bush administration who were feeling that this volunteer guideline will maybe cultivate innovation.

(Joel Beasley at 00:10:13) Well, Harri, here's a question for you. Let's say I go start my own voting machine company. Right? I happen to know—let's just hypothetically, like, the governor of Texas. And I'm like, hey, Texas. We're gonna make our own system. You guys are gonna be my customer, and we're gonna make this new voting system that's really secure and transparent. And so we go build that and put that into Texas. Is that—first of all, can people just start those companies? Is there a legal barrier to entry? Like, or can I just become a vendor of voting machines? That's my first question. And my second question is, who is to—like, I'm a—my background is software engineering. I wasn't cybersecurity, but I build applications from the ground up. How does that information get relayed, and how do they know that what's coming to them from the vendor of the voting machines is truthful and accurate?

(Harri Hursti at 00:11:11) So the first answer is it's an unregulated market. So everybody who has deep pockets can start a voting system company. I personally have been involved in attempts to do that. The problem is that in order to get through all the bumps on the road, you are—basically after you have developed your product, you have to go through a number of different hoops after which will take, give or take, at least year and a half, maybe two years. And a number of states doesn't even allow you to start marketing to try to find if you have a customer before you have gone through those hoops. So as long as you have deep pockets, there's nothing stopping you to start a voting system company. Nothing at all. There's no requirement to even be a US company. So just go ahead and do it. The problem is really it takes a long time, and it's expensive. And that is the reason why a number of states have been making an exemption if an open source company would come to the market. And Texas is a good example because there was an initiative between one county in Texas, one big area of California, a couple other places to start a project of making a publicly funded open source voting system. And the way it died was because you have to basically, in the Texas, California—California city were asking the vendors to—in an RFI, are you offering this modular? And when everybody said yes, then this open source initiative would say, well, we will do the hard parts, and then they can buy the easy parts as modules from the existing vendors. Of course, when the RFP came, nobody offered modular. So since the open source initiative didn't have a complete system, they were kicked out and it was too late to start over for the purchasing. So there's a lot of tricks in the book to prevent—have the barriers of entry high. So that's why it takes a long time and a lot of money to create a voting system. And my personal opinion is I don't understand why we don't have publicly funded open source system. And after that, you still need the services companies to help the counties, etcetera. There's still a private enterprise which is needed, but at least now you can have a secure software and secure design and architecture. And, by the way, because the requirements in the US are so vastly different between jurisdictions, the US always needs more than one system. It's hard to imagine that it will be making the best sense to create a single system for all of the US to use because you have vastly populous, humongous amount of different ballot style environment like LA County, California, or Seattle. And then polar opposite, you have small counties with a few hundred voters, a single ballot style. And if you create a system which can help both, you actually create a massive attack surface for the easy places for no good reason whatsoever. So the US really needs two or three different code bases and systems to best serve and most securely serve different kind of jurisdictions.

(Joel Beasley at 00:15:15) So it's not even a requirement to be an American to make American voting machines?

(Harri Hursti at 00:15:20) No. And, actually, interestingly enough, most of the systems sold today are—even if the company with the US—the system was not created in the US.

(Joel Beasley at 00:15:31) Are you serious? Most of our voting machines are not created in the US?

(Harri Hursti at 00:15:34) Yep.

(Joel Beasley at 00:15:36) It's like the least American thing I've ever heard.

(Harri Hursti at 00:15:39) Well, when I started Voting Village with my friends, a criticism was to say we are irresponsible because we are allowing foreign citizens, foreign people to see what is inside a voting machine, how they work. And my comment was, yes, the foreign people are called the citizens of the United States because, for example, the market—number two system, that system is coded in a former Eastern Bloc country, and their first customer was state of Mongolia between Russia and China. And I'm absolutely certain the good people of Mongolia are 100% respecting US copyright laws because the copyright laws are the ones which were at the time were used to prevent Americans to see how the system works. But if you look, really, these systems used in the US, they have foreign origin in most of the cases, even if the marketing company is US or the current holding company is US. So that's one thing. They're also sold internationally. So there is—if there's multiple ways to get your hands on these machines. So the normal wisdom, which is you should always assume that your adversary has full access, is very true in voting systems.

(Joel Beasley at 00:17:05) Every time I get frustrated about the lack of progress here, I just rack my brain—why, why, why. And then I flip on the news and I see Congress, and their average age is, like, 72. And I'm like, oh, that's why. They don't understand this stuff.

(Harri Hursti at 00:17:22) I have been speaking with a lot of members of Congress and Senate and their staffers, and there are a lot of good people there who actually understand regardless of their age deeply. But the question is, for example, the whole time—a number of election security bills which had bipartisan support were prohibited to even be voted in the Senate. And the reason was because they had the votes. So there have been so many efforts in different leaderships to not even allow bipartisan bills improvement security to be voted on. And, of course, there are a lot of, you know, political motivations behind it, but it doesn't make any sense.

(Joel Beasley at 00:18:13) Even have standards. Let's just use—let's just say the company—we won't use the brand name. Let's say the company that controls 80%. Right?

(Harri Hursti at 00:18:21) The companies—two companies control 80%.

(Joel Beasley at 00:18:24) All right. Two companies control 80%. Let's say either one of those companies, let's call it Votingco. Right? So Votingco owns all of these machines and is responsible for 40-plus percent. Who has—if they don't even have standards, if they're voluntary standards, who is the one that's auditing the database transactions and queries to understand that whatever Votingco told the US government is accurate and not just a number Votingco made up?

(Harri Hursti at 00:18:52) So the system works that National Institute of Standards and Technology is accrediting a VSTL test authority test lab. Then the vendor is paying the test lab to do the testing. But the problem is the testing is done with the volunteer guidelines, which means that the vendor can tell, oh, we used the 2005 guidelines. And, also, by the way, we want this testing to do a certain way. I have been involved in making two HBO documentaries, Hacking Democracy and Kill Chain: The Cyber War on American Elections.

(Harri Hursti at 00:19:31) Both were Emmy nominated for investigative journalism. One of the people interviewed in a later movie was a guy who was doing this testing for one state, and he was ex-Air Force, so he was using the Federal Information Processing Standards, which is the federal government standard. Once the vendor found out, "Oh, they are using a real standard," they wanted to cancel everything. "There's no—we want to define how this testing is done." So this is really what the voluntary guidelines comes from.

(Harri Hursti at 00:20:08) United States government has a lot of good standards, and the boys and girls in this, they make an amazing job. They are capable of creating good standards. But since those standards are not implemented as a regulation, and since this whole area is working with the voluntary guidelines instead of standards you have to comply, nothing gets moved along. Nothing gets fixed.

(Joel Beasley at 00:20:36) Okay, so the vendor uses this testing lab, and they're getting some certification. That's great. I can go get my app certified tomorrow from a cybersecurity company that I pay to do it, but then I can release a new feature.

(Harri Hursti at 00:20:51) Right. These companies, these testing companies, are cybersecurity companies. Actually, in one lawsuit I was expert witness, the CEO of another one of these testing companies told that their only cybersecurity guy had resigned few years earlier, and they haven't yet recruited a new one.

(Joel Beasley at 00:21:13) Okay, so just—I wanted to really try to get a direct—I really want to try to get this down. So I'm a voting machine company. I go and I get my approval through—I'm a vendor. I go get my approval through the testing company, whatever that may be. The test comes. Now, say day of election comes, okay? The votes are cast, and now that data has to transmit from my systems to somehow convey that to the state systems or to whoever, whatever the election is. Who is monitoring that database transaction?

(Harri Hursti at 00:21:47) So voting systems—in United States, elections are run by the states. And you have two different kinds of states. You have bottom-up and top-down states. And, actually, you have bottom-up and top-down in election and voter registration. They might be going different directions.

(Harri Hursti at 00:22:09) When it's top-down, it means that the secretary of state is usually having a uniform system for the whole state. When it's bottom-up, then the counties are in the driver's seats, and the counties make the choice what kind of system they purchase and want to use. So the systems are local. There is no database running on cloud. There is nothing happening in a data center in the area of voting. It's a local server. So all that happens in a way that the voting terminal, whether it is, for example, a paper ballot scanner, that scanner typically stores all the votes on a memory card of sorts. Memory card then gets transferred to what they've called the central tabulator. The central tabulator is making the results. And then, again, during election night, unofficial results are usually taking another memory card or USB drive. That's how the reporting happens, but there are unofficial results, because the official results actually don't happen election night, ever. There's a lot of processes which happen after election night—canvassing boards, et cetera, et cetera. So there are no official results until usually weeks after the election day. When everything is a landslide, everything is clear, there's no reason to believe everything is wrong, it still takes weeks.

(Harri Hursti at 00:23:44) This is—and that will always be. That's a good thing. That is a good thing. So I'm not criticizing that at all. That's a good thing that there are checks, and there are a lot of things what needs to be checked. And there's a lot of misunderstanding how elections work in the US because people think everything happens real-time. It doesn't. So, anyway, the answer to this is the voting systems, the voting machines which are in precincts, if it's not central count state, those are—sometimes they are transmitting results. That's called modemming. They are transmitting the results to the central tabulator. Most common way is a physical transfer of memory card, which is brought over, and then it is the county server which is responsible for tabulating the votes and creating the results, the intermediate results, and then assisting when they are creating the final results when canvassing boards and all of that process is happening.

(Harri Hursti at 00:24:49) This is also interesting because there has been a process in place for the last over twenty years or longer than that, which right now in election denial world have been blown to be nefarious. And one good example is so-called vote dumps, that all of a sudden in the middle of night, massive amount of votes are added in the totals. Well, that's because of the law. The very common law in the US in order to protect voter privacy is that the ballots are divided into batches. Batch is just an artificial selection of 100 ballots, for example. And those 100 ballots, when they are bound together, they have to stay together, which means that in order to protect voter privacy, none of those 100 ballots get reported until all of the ballots get reported. Well, this creates an interesting situation. If there is down the ballot, say, school board or a stray dog catcher, there's a highly contested local race down the ballot with a lot of write-ins. Now that means that none of these 100 ballots for any of the races get released until the canvassing board, which is typically one Republican, one Democrat, and one county person operating, have decided these votes.

(Harri Hursti at 00:26:24) And, for example, in the 2020 election, one of the places I was—one of the counties I was involved and observing—5,000 of these write-ins were holding back tens of thousands of votes. And the canvassing boards are not sitting there all night. The canvassing boards are usually first time called to come in 11 p.m. or midnight, and they are convening certain times. So all of these write-ins are taking the batches out of the reporting, putting them to wait for the canvassing board, Republican, Democrat, to decide these write-in votes, and only after that's done, all of these votes are released. Now, because usually the holdup comes from a local race, it means that they are very tight demographics. And that means that, for example, it might be a deeply red or blue area of the county where you have that school board election or whatnot. I'm just making up an example. And that's why all of a sudden when the dump comes, when the votes are released, they are strongly going, having one demographic or another. So this is actually how it works, and the whole idea of batching has been the protection of privacy, a secret ballot. So it's just blown out of proportion and misreported right now.

(Joel Beasley at 00:27:49) Let's say I'm of VotingCo, and that's the fake company I made up earlier. We control 70%—or 40% of all the ballots. Let's say I'm the CEO of that company, VotingCo. And let's say that this upcoming election is, well, it's just a little bit too important to humanity's survival for us to let go to chance of the people. And I'm going to have one of my most trusted programmers throw some code in there that weights the party of my favor by some percentage. Let's say I was nefarious and that I did do that. What systems are in place to prevent that from happening?

(Harri Hursti at 00:28:35) So first of all, as a security community for twenty years, we have been flagging insider risk and how insider risk is a big problem because the systems don't have proper safeguards against insider risk. And that, again, is part of that the designs are so old that the day came with a lot of these—design systems were designed, there was—the country was not as polarized as it is today, and the threat model was wrong. The threat model was literally a dishonest candidate or supporter of candidate trying to swing the election their way, probably the local election, but there was never a thought thinking about nation-state attack or chaos actors who don't care who—actually, they might have a preferred candidate, but they actually just want to sow distrust.

(Harri Hursti at 00:29:35) So the safeguards are missing. And, actually, I would be also pushing back that changing the code is not needed. The number of security vulnerabilities me and other security researchers have reported don't require code changes. It can all be done locally—manipulating the database, manipulating the memory cards, manipulating the log files.

(Harri Hursti at 00:30:03) So even if you look at the code, there's nothing needed to be in a code. Furthermore, when I, back in 2005, reported the first vulnerabilities in a Diebold system being used, those vulnerabilities would have been undetectable from the source code because it relied on understanding of the hardware. So once you understand how the hardware works, now you can find a vulnerability in the source code, and that's what University of California Berkeley then verified to be there. But a lot of these vulnerabilities, really, you have to understand the system as a whole, and it is—for a nefarious actor, source code manipulation is obviously one way, but I would argue way too complicated way, and there are easier ways to do it. Now, if we look at the nation-state, now we are in a different game because even if you have a source code, even if it runs the source code, when you compile, you have in the binary a lot of libraries, a lot of code which comes from third parties.

(Harri Hursti at 00:31:20) So that is a way for nation-state to compromise the system, is to compromise the software supply chain, and that can be done multiple different ways. And, unfortunately, when twenty years ago, when the security of voting systems in the US were first time questioned, there was a belief that source code review is the holy grail. And now, especially with the Biden White House executive order 14,028, which is underlining the software supply chain security in all of the federal government and everybody doing business in federal government, we should understand that source code review—it can be even misleading. It's not definitely alone what you should do. You should inspect the system as a whole. You should reverse engineer the binaries, and you should understand the hardware because so many of the vulnerabilities are coming from the hardware, derived from hardware. And part of that is that we have two kinds of systems in use. We have old designs, which are old and tired, and some of the old systems are actually more secure ones. And then the new systems are, generally speaking, repurposed consumer electronics and repurposed general-purpose operating systems. I mean, this is just how it is.

(Harri Hursti at 00:32:53) We have documented one of the—

(Joel Beasley at 00:32:54) Slap an Android operating system on there and call it a day.

(Harri Hursti at 00:32:57) Well, Android is used. Android is used. And, actually, one of the big systems, the Android is installed overseas, and they are using the pre-installed Android which comes from overseas. But at the same time, one of the large vendors in new systems, they use a consumer operating system installation. So you have your Fitbit. You have your Netflix. You have all the games still on the central tabulator, including games which come from Russian-owned companies.

(Joel Beasley at 00:33:33) Have you done any estimation, guesstimation, on how many fake or wrong votes are being counted based off of people running these exploits?

(Harri Hursti at 00:33:49) So I and all the security researchers, we welcome every single time when there is a claim that something has been manipulated. We have been investigating this number of times, and we haven't seen an error, malicious or error, which would be changing the outcome of the election. If election results are matching exactly, that is a red flag. Election results never match, and that's because there are so many questionable—people are filling the ballot wrong, and then human board is changing it. There are a lot of reasons. So election results should always be a few votes here and there not matching. But it doesn't change the outcome. In Rockingham County—so this is a reason which I got death threats and all the other fun stuff—in New Hampshire, in Rockingham County, in Windham Township, they had the biggest numerical difference in votes in history. And what happened was down on the ballot, eight candidates, vote for four. Four Republicans won. One Democratic woman was so close that she asked for a recount. And in New Hampshire, they have a great system. We always get a recount. When recount happens in New Hampshire, everybody gets more votes. That's the rule, because people are not interpreting the ballot, they're not filling it right. And now when humans are looking, the voter intent is clear. So everybody should get more votes.

(Harri Hursti at 00:35:33) In this recount, the four Republicans got about 300 votes each more. Three Democrats got 30 to 40 votes more, and the woman who asked for recount lost 99 votes. So first of all, the 30 to 40 votes was expected, not 300. And also losing votes is never heard of in that scale. So New Hampshire passed a new law to do a forensic audit.

(Harri Hursti at 00:36:17) I was one of the three guys who conducted the forensic audit. And when we started forensic audit, first of all, there was a lot of claims saying that this is the secret algorithm, it's now going to be all coming to open. Later, it was claimed to be that I was involved in a cover-up, covering the secret, blah, blah, blah. Long story short, when we started the audit, the first thing is we might never know what happened, but we will try to find. We found. And the story was actually fairly simple. Back in 2020, when during COVID, when people were asking for mail-in ballots, the election office was falling behind. And in order to recover from falling behind, someone had remembered, "Hey, we have a paper folding machine in DMV. So let's get that DMV machine here." So they brought the machine in. First of all, the machine was a little bit broken, but they didn't know it. The second thing is they didn't adjust the settings of the machine. And as a result, the paper folding machine did two things. First of all, it didn't fold the paper completely horizontally. If it would have been folding completely horizontally, it would have damaged the timing marks, and the voting machine would have rejected these ballots, and they would have had the hand-count problem would have been non-existing. The second part is that the ballot had a grace line so that human bending is always folding the paper in the safe zone, but the machine is strong enough to fold it right off. So it actually folded the paper through that Democratic woman's vote target. Now, even funnier is that the secretary of state office had considered and tested if a paper folding through a voter candidate creates a false vote, and they have determined it doesn't. Well, there was a thing which was not considered: that whether you fold the paper up or down makes a difference.

(Harri Hursti at 00:38:45) So they most likely only folded in one direction, not both directions. Long story short, if somebody voted straight party line Republican and the folding went through her target, in 14% of chances, that folding created a phantom vote for her, which created five votes instead of four, which tossed the Republican votes out. If somebody didn't vote for her and didn't vote already for four, it created a phantom vote for her. So this explained both directions. Even further funny is that because it was a high turnout, Windham was the name of the township, had brought a spare machine they don't usually use to be used in that. And that spare machine, even when they have paid for annual maintenance, probably had never been cleaned. And inside of the machine was a residual from printing process, powder, and that powder didn't create the problem, but it amplified the problem. So we found the reason—completely non-nefarious, absolutely nothing to do with the voting machine itself. And we also did verify—we audited also the Senate and governor race, and we actually recounted every other votes from the presidential race. I think the difference was two votes.

(Harri Hursti at 00:40:14) So, again, even when the error was the largest numerical error in history there, 300 votes, it didn't change the outcome. And we found out the reason why the error happened, which was absolutely not nefarious.

(Joel Beasley at 00:40:30) If you wanted to be nefarious and change the outcome of elections, what would you do?

(Harri Hursti at 00:40:35) Well, there are a number of security recommendations which have come out of my own security studies where we have identified what are the key weaknesses. And, for example, in certain systems, that is the memory card. So you have to put the physical security in place to guard the memory cards because that is the weakness. Every system has their own weakness. So you just have to identify the weakness and then mitigate against it.

(Harri Hursti at 00:41:08) A common misconception in the US, which is often repeated, is the US system is protected by the reason that, possibly in 2020, I believe 52 different kind of voting systems were used across the US, that it's protected by diversity. That's not true because nobody needs to manipulate all of the systems to attack the system. They just need to attack one system they know how to manipulate. So when you have a diversified system, you have to learn the vulnerabilities of all of them and protect all of them. Anyway, every single time when we find a vulnerability, we try to develop a mitigation strategy for that, and we try to make certain that the counties and the states who are operating that system are aware that the vulnerability exists and how to mitigate against it.

(Joel Beasley at 00:42:11) So how would you steal an election?

(Harri Hursti at 00:42:14) As I said, every single time when we have been finding a severe vulnerability, we have been documenting what the vulnerability is, but also looking at how to defend against it so that it cannot be used. And the good thing about the US elections is that there's more eyeballs right now looking into the system. More eyeballs is always better, and more security studies have been conducted.

(Harri Hursti at 00:42:48) Unfortunately, the last huge studies were done in 2008, and then the financial crisis took the spotlight. So right now, we need a new comprehensive study to look into all the new systems which have been starting to roll in and look at how it's operated to develop new mitigation strategies. But every single system, you just have to find what are the weaknesses which are easy to or which can be attacked. Then you determine who would be the attacker, is it an insider risk, where it is, and then you develop a mitigation strategy. And the most important thing here is that the most vulnerable systems have been going out.

(Harri Hursti at 00:43:36) Back when I started in 2004, 2005, a lot of jurisdictions used touchscreen voting. You use the touchscreen, you vote it, there's only an electronic record of how you voted. And if that electronic vote record gets manipulated, there's no remedy.

(Harri Hursti at 00:43:55) There's no way of proving that this was a rigged election or recovering. Today, almost all jurisdictions use paper ballots, which allows, first of all, if there's a question about the election results, you can go and use either a recount as Windham did, or risk-limiting audit, which is a very labor-efficient way, a statistical method, to prove that the outcome of the election is right. It doesn't mean that every vote is exactly right because that's never—every last vote is never right—but it shows that the outcome is correct. So these are the methods, and that's why paper ballots is the way to do it. And especially with paper ballots, even that is two different things.

(Harri Hursti at 00:44:45) The voting system vendors have been pushing ballot marking devices, and ballot marking devices are typically touchscreens which are printing the ballot for you. That is not as good and not nearly as good as a hand-marked paper ballot where the voter is using a pen and marking the ballot themselves. There was a recent study by University of Michigan where voters were told that a new voting method was being tested, and they had been asked in different instances to verify their ballot. What the voters didn't know is that the machine was cheating every time, and every ballot was wrong one way or another. And only 7% of the voters actually caught that the ballot was wrong even when they were asked to verify.

(Harri Hursti at 00:45:42) And the reason is ballots are long, they are complex, and we humans—the voter shouldn't be responsible for checking the system if the system is right. And if you are putting the voter to say, "Oh, this machine is printing your ballot, and now check how it works," it actually puts the task to the voter to be responsible for testing the system, which is not the voter's job and role. So hand-marked paper ballots is the safe way. And when you have hand-marked paper ballots, if there's any question about the legitimacy of the results, you can always go and verify from the paper ballot.

(Joel Beasley at 00:46:22) Have any countries done this really well, as far as made it a really good, transparent, technologically advanced voting mechanism for their country?

(Harri Hursti at 00:46:35) Every country has their own flavor of democracy. The United States elections are almost uniquely complex. My original country where I come from, Finland, we have a single race on a ballot. Only one race. That's the whole ballot.

(Harri Hursti at 00:46:55) And usually you have only one race per day when the election day. So now you can hand count with very low error rate because there is no complexity on a ballot. In the US, you can have 30 races, 40 races, 50 races, and you have narrow margins. This means that unless it's a very small jurisdiction, you cannot do hand count. Absolutely impossible because the human error rate is higher than the expected margin of victory. So in the US, you have to use a machine you cannot trust. It is really, instead of trust but verify, it's never trust and always verify. Because when the machine works properly, it is probably producing more accurate results than humans can do.

(Harri Hursti at 00:47:47) But you have to be safeguarding against, again, the mitigation. You cannot trust today's voting machines. You cannot trust tomorrow's voting machines. There is no foreseeable future where you can trust the voting machine. So hence, you have to be able to verify the results.

(Harri Hursti at 00:48:07) And again, I just gave a lecture and talk at DEFCON about international ways of doing voting. And the key part is you cannot go and say, "Well, this country is doing it. Let's copy them," because there's always reasons why they are doing good elections for themselves. But there's historical reasons, there are legal reasons, there are multiple reasons why they do it a certain way that works for them.

(Harri Hursti at 00:48:36) You can always study and try to find if there's a lesson to be learned, but you cannot go and say, "Oh, they do it well. Let's copy them." Because our democracies are vastly different, and we have very different requirements.

(Joel Beasley at 00:48:49) Interesting. And so I would imagine that a technology would emerge that it's like a blockchain type technology, immutable ledgers, something that would come out and people would see it and they'd say, "Yes, voting needs to happen that way because I can see the code actually running. It's fully transparent, and it's publicly available for review." There's got to be some type of system like that in the future, right?

(Harri Hursti at 00:49:21) So first of all, blockchain voting is a wonderful example. There have been a number of things where blockchain voting has been proposed, and it's every single time been immediately hacked. Because blockchain is a solution looking for a problem, and it hasn't yet found a problem it can solve. It's just useless for a lot of things. In blockchain in elections, it might be a partial solution to one out of ten problems, but it creates three more problems on the way.

(Harri Hursti at 00:49:53) So we haven't found any way to use blockchain that it will even be net positive as a partial solution. Now, if you look internationally, a number of European countries in the constitution, they say that a common person has to understand how election is conducted and results are counted with no special training or tools.

(Joel Beasley at 00:50:24) Wow. They should look at the IQ distribution curve. That's going to be a challenge.

(Harri Hursti at 00:50:27) Well, in the US, the average—the joke is that the average age of poll workers goes up one year every year because it's hard to recruit younger poll workers. So one of the most promising technologies for the future is homomorphic encryption. I know personally one of the great men in that area, and he truly believes that one day, homomorphic encryption might solve this problem, but not in his lifetime. And he still has 40 years to go.

(Harri Hursti at 00:51:03) We don't have any technology today on the horizon which we know can solve the problem. Again, there's the other problem is that if you have to be able to understand how it works, until we live in a Star Trek universe where teenagers are casually talking about quantum mechanics, I'm not going to spend time trying to explain homomorphic encryption to an 80-year-old poll worker. That's not going to work. And at the same time, when people are distrusting everything, how you are going to be proving that something so complex as homomorphic encryption, that the code is actually doing what it's supposed to do? There are not many thousands of people on the planet Earth who actually can do that audit reliably and understand everything there.

(Harri Hursti at 00:51:56) So that's one big part of the problem. But even a bigger problem is, let's say that we have blockchain voting. Today, some of the blockchain voting systems, how it works is at the end of the day, the voting system company is printing paper ballots and shipping them to the jurisdictions. Nobody is verifying if the ballots coming out of the printer are the same as the voters wanted to vote. So the blockchain doesn't go to the end. That's one big part of the problem. Then the other problem is the secret ballot. So we could do internet voting if we don't have secret ballot or if we don't need to audit. What makes elections a unique problem is that you have to have a secret ballot, and you have to be able to audit.

(Harri Hursti at 00:53:01) A secret ballot means that you as a voter cannot, even if you want to help, you cannot prove how you voted. That's very important. Secret ballot came—the secret ballot was invented in Tasmania, Australia, and it was first time used in 1854. For some reason, good people of Tasmania and Australia didn't trust each other, maybe because the whole place was a penal colony, maybe that way. But they created the secret ballot.

(Harri Hursti at 00:53:23) Secret ballot took a long time to come to the US, and it was basically first time used in 1896 elections in the US. Voter coercion was a big problem, and it still is everywhere in the world. When we live in big cities, we don't see the vote coercion. It is more in areas with smaller communities, and there are a number of different pressure groups who can do the voter coercion. But anyway, the problem was that if you voted wrong, you got feedback.

(Harri Hursti at 00:53:57) The reason why we have electronic voting today, the grandfather is called the lever machine, a mechanical calculator where you press a button, you pull a lever, and it mechanically calculates the votes. Lever machines were not invented to make faster results or better results. The intention was let's destroy the evidence of how you voted by not having a paper ballot, not being able to audit. But this way, people don't get beaten up. So it was never—when we look at modern electronic voting, it all comes from the idea that the secret ballot and stop coercion is the number one goal. Otherwise, you cannot have free elections.

(Harri Hursti at 00:54:44) And still today, I mean, I travel internationally, I travel to the US. Voter coercion is a real problem in the US, across the world. It never went away.

(Joel Beasley at 00:54:54) What's a specific example so I understand it better?

(Harri Hursti at 00:54:57) So first of all, if you can be coerced to vote a certain way by whatever is your neighboring area, so that's what coercion is. You get beaten up if you don't vote a certain way or, alternatively, vote buying and selling, which both are felonies in the US. If you can prove how you voted, now you can sell your vote because you can prove you get your own end of the bargain. Because why would somebody pay you if they don't know you are handling your end of the bargain?

(Joel Beasley at 00:55:36) That's interesting.

(Harri Hursti at 00:55:37) And by the way, vote buying and selling is a lesser problem. Again, when I'm helping so many secretaries of state, when you are speaking with a secretary of state, almost every single place, sooner or later, voter coercion comes as one of the topics. It is a real problem.

(Joel Beasley at 00:56:01) Help me. I'm still not getting it. I'm sorry. I'm slower than some of the other kids in the class. So what's—is it me telling someone? I don't know how anybody votes because you do it in the booth and you can't see.

(Harri Hursti at 00:56:14) If you do mail-in voting, now you're voting at home. Now your friend can check your ballot.

(Joel Beasley at 00:56:22) But people do that?

(Harri Hursti at 00:56:23) Oh, so in one country where they have been trying internet voting, they have an idea that you can vote as many times as you want, but your last vote counts. And after internet voting, you can still go in-person vote, and it will delete your internet vote. So in that country, when I was doing a security review, I did what I do in that kind of places. I go to ask a taxi driver how this works. Well, the taxi driver told, "Well, the last day of internet voting, we have voting parties. Everybody goes to the bar, all put their mobile phones in a big bowl, and everybody votes with one laptop, and your friend is checking out that you did the right choice." Good. Now the election day happens to be Sunday.

(Harri Hursti at 00:57:27) And on election day, it's so important a day, the church services start very early in the morning, and there's a special program on church until the polls have to be closed. So I literally went after this taxi driver advised to see the voting party. I hoped to see in my own eyes, is this real? And it was real. It was real. And this is still a very advanced country, a very advanced country.

(Harri Hursti at 00:57:42) When I'm speaking with different secretaries of state, it comes with different flavors. Whether it is your workplace, whether it's your religious group, whether it's whatever is the group, but it's always a group effort in that sense. But also, unfortunately, a lot of things happen. Not only is it a close group, but it comes in your family. When you look for the coercion, you are looking for people closest to you.

(Joel Beasley at 00:58:21) This is complete news to me. I guess my personality type doesn't yield itself well to this because I'm involved in a church. No one would ever do anything like that culturally at our church. Getting beat up, it's hard for me to even imagine that. It's like somebody getting in a fight over a vote.

(Joel Beasley at 00:58:46) And then at work, you know, I own a business, and we've got employees and things like that. The idea that we would ever pressure anybody to vote any specific way is completely foreign. I believe you. I believe this happens. There's cultures I don't understand. There's weird, there's unique and different stuff everywhere, right? So I'm not saying I don't believe you. I believe you.

(Harri Hursti at 00:59:06) Yeah. It's really, if you look at the history, the reason why secret ballot and voting in a polling location came was to stop vote buying, selling, and coercion. That was the whole idea. If you vote in a booth alone, now you know how you voted, but you cannot prove. Somebody cannot come after and say, "Prove to me how you voted," because that's—so the reason we vote in person in a booth, that's the reason. And when you look again, in one study when in one state where they increased access to mail-in ballot, mail-in ballot is not bad.

(Harri Hursti at 00:59:54) But when there was a study conducted asking, "What do you feel about it?" the most common answer is, "I don't know. My husband took the ballot." That was the number one answer.

(Joel Beasley at 01:00:05) Really?

(Harri Hursti at 01:00:06) Yeah.

(Joel Beasley at 01:00:11) That's interesting.

(Harri Hursti at 01:00:12) So again, it is—it's the people closest to—so personally, my belief is voting in person with a hand-marked paper ballot is the best way to vote. And then second best is mail-in ballot because there are still safeguards. In mail-in ballot, the problem becomes vote buying and selling and coercion, not ballot harvesting, which is—because actually, a number of states, ballot harvesting is legal. It's not illegal at all. You can actually help deliver ballots.

(Harri Hursti at 01:00:50) But mail-in ballots do have certain problems, but their problems are really closest to your home. And mailing ballots were used in Iraq War, in Vietnam War, in Korean War, in World War II, World War I, and in the Civil War of the US. So yeah, mailing ballot is not bad, but it is—again, the problem—you have to understand what is the problem, and the problem is mainly closest to you. It comes from vote buying and selling, and it enables the coercion of the voters. That's the problem. And again, I said it's—every community is different, and every country is different. And as a European, I had a perception that voter coercion is not that common. I knew it happens in smaller communities in Europe, but I thought it is a marginal problem until I started getting involved with elections, and I understood, no, it's not a marginal problem.

(Harri Hursti at 01:02:07) And no, it's not a marginal problem in the US.

(Joel Beasley at 01:02:12) So as we start to wrap up, just trying to—

(Harri Hursti at 01:02:15) And again, let me just say one thing. If you could vote on a mobile phone or internet, it creates, again, more ways of voter coercion, more ways to vote buying and selling. And that is the problem. We have already US websites where you can trade your vote. So basically, I'm living here, you are living there. Let's swap the votes because I cannot vote there and you can vote here. Is this legal? Absolutely not legal, but it's happening. And the moment when you are giving more means for people to prove that they held their bargain, that fuels this kind of crime.

(Joel Beasley at 01:03:01) How have these websites not been shut down?

(Harri Hursti at 01:03:07) I think the problem right now is that those are still marginal.

(Joel Beasley at 01:03:13) Mhmm. They're not mainstream.

(Harri Hursti at 01:03:15) Yeah, they're not mainstream. But again, we have to understand the history, where we come from. The way elections have been conducted is for a reason, and the reason is that the current system was addressing problems encountered before. And if we want to change, one of the key things to understand: human nature hasn't changed. If we enable a problem to come back, chances are very good that the problem will come back because we humans are still the same as we were 150 years ago.

(Joel Beasley at 01:03:52) So knowing what you know about the security of voting systems and all of the history that you have, what do you think is going to happen in the 2024 elections in relation to the security of the systems and all of that?

(Harri Hursti at 01:04:10) Still, my biggest worry is misinformation and disinformation, malinformation campaigns, and undermining the trust. Apathy is as dangerous to democracy as a problem. And misinformation, disinformation campaigns—the primary motivation is to get certain Democrats to distrust the system enough that they won't participate. They will stay home and not vote. So no matter—we need to study, we need to improve the system, and nothing should discourage you from voting because, again, democracy is participation. And if you don't participate, it's not that you are damaging and throwing your own vote away. You're also damaging everybody else who is voting the same way and want to have their voice heard. This is the same reason why it's a false way of thinking saying, well, if I accept the risk to vote internet, why can't I—if I accept the risk, an insecure way of voting, why can't I just accept that risk and vote insecurely myself? The problem is there's only one result. And if you vote insecure method, it pollutes the whole pool and it disenfranchises everybody else because there's only one result. It's not your personal vote. It is the result, which is the combination of all the votes cast. So again, participation is very important. My biggest worry is, again, claims of rigging, claims of hacks, claims of everything which didn't happen.

(Joel Beasley at 01:06:02) I think that'll happen on both sides, to be honest with you.

(Harri Hursti at 01:06:05) What do you mean, both sides?

(Joel Beasley at 01:06:06) Uh, I'm sorry. I think that'll happen on both sides. Regardless of who wins, I think there will be accusations thrown around either way.

(Harri Hursti at 01:06:16) And again, that's why we need hand-marked paper ballots that you can go and verify the results and say, alright, it doesn't matter which way you claim it is a false result. You can always get back to the ground truth by recounting the paper ballots.

(Joel Beasley at 01:06:34) Is it—because of the secret ballots, but like, is that paper ballot always disconnected from a voter registration, from somebody who has a proof of citizenship, or is it completely disconnected where it's just a physical card with a vote on it?

(Harri Hursti at 01:06:51) So there are in a number of states, there is actually a prohibition—it's prohibited to have secret markings on the ballot. So that is to protect the anonymity. There are certain systems which allow you to print a barcode on the ballot where the idea is that the barcode itself is preventing that ballot to be counted more than once. But again, then it is introducing the question of how it's safeguarded that the ballot remains anonymous. Paper ballot, basically, in a way, almost everywhere it's done in the US, is anonymous because it's dropped in the box, box is shaken. You can't reconstruct back which ballot belonged to which voter, and that's a good thing. So I have been personally involved in a number of places where the voting machine, which is a touchscreen voting machine, has claimed that the ballots are in random order. They are not. We can reconstruct the order. And after that, if we get access to the poll book, which is a public document in a number of states, now you can reconstruct how everybody voted. Paper ballot, they all fall to the box in any order they want. So by falling in any order, well, it's very hard to imagine how to reconstruct how you voted. So paper ballot.

(Joel Beasley at 01:08:23) Yeah. Alright. Well, Harri, thank you so much for doing this. As an American and with the elections coming up and as spending my entire life building and supporting technology, I had a million questions, and you gladly answered them all. So thank you so much.

(Harri Hursti at 01:08:41) Oh, thank you. And please, you know, go vote. And because that is the most important thing in elections: participate. And again, a number of countries from Australia to Argentina to Belgium, voting is mandatory, and you actually will get fined if you don't vote. So in the US, the idea is voting is voluntary and you can choose not to vote. But even that is—in certain, in some very notable and respected democracies, they have mandatory compulsory voting.

(Joel Beasley at 01:09:17) Yeah. I'm not a history buff, but I've looked into the rise and fall of empires enough to know that it has to get really, really, really bad and have a lot of pain before people make it a priority to change.

(Harri Hursti at 01:09:31) Yeah. Human mind has a certain amount of inertia.

(Joel Beasley at 01:09:34) Yeah. Yeah. Well, thank you, Harri. Thank you. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.