16 States Affected by Newly Discovered ES&S iVotronic Touch-Screen Voting System Virus Vulnerability

Share article:

A commenter over at DU asked which states used the ES&S iVotronic touch-screen voting system found vulnerable to an undetectable countywide vote-flipping virus which can be implanted by a single person, as we reported this morning.

Based on our quick review of a county-by-county database of voting systems, sorted by state, as made available by Common Cause (EXCEL spreadsheet downloadable here) just prior to the November 2006 elections, it looks like the answer is 16 states in total.

Since the EAC refuses, as our report detailed, to do their job in notifying Elections Officials about this incredibly serious vulnerability, it looks like it’s up to you to notify your state’s Secretary of State and/or county Election Officials! Details on the vulnerability and mitigating steps that may be taken are detailed in this brief report at VotersUnite.org as written by a computer scientist and voting system expert well familiar with the newly discovered flaw. Please refer your voting officials to both our original article, and that scientific report for more details at the following URLs:

The states which use the ES&S iVotronic affected (with firmware versions either 8 or 9, with or without a so-called “Voter Verified Paper Audit Trail”) are as follows:

  • Arkansas
  • Florida
  • Indiana
  • Iowa
  • Kansas
  • Kentucky
  • Missouri
  • New jersey
  • North Carolina
  • Ohio
  • Pennsylvania
  • South Carolina
  • Tennessee
  • Texas
  • West Virginia
  • Wisconsin

If we’ve missed any, or any of the states above do not use the system in at least one county, please let us know and we’ll amend the list.

The BRAD BLOG and You – Doing the EAC’s job for them. But without the $15 million budget (or the incomprehensible incompetence).

Share article:

Reader Comments on

16 States Affected by Newly Discovered ES&S iVotronic Touch-Screen Voting System Virus Vulnerability

11 Comments

(Comments are now closed.)


11 Responses

  1. 2)
    Joyce McCloy said on 4/16/2007 @ 8:11pm PT: [Permalink]

    I am wondering how the author applies this statement about Sarasota voting machines to other states that don’t have the same version iVotronic?

    Does the report says all other versions are affected, or is this all conjecture? It could be true, but we DONT know if for a fact that other versions are affected.

    North Carolina and Ohio definitely do not have the same model of iVotronic as the machines studied in Sarasota. Any of the machines with the paper trail will have a different version than Sarasota.

    Differences:

    Sarasota Florida machines are paperless:
    ES&S Unity 2.4.4.2
    Election Reporting Manager 6.4.2.0
    iVotronic DRE Firmware 8.0.1.2
    Certified to 1990 Guidelines
    12″ screen

    North Carolina machines have a paper trail:
    ES&S Unity 3.0.1.0
    Election Reporting Manager 7.1.2.0
    iVotronic DRE Firmware 9.1.4.1
    15″ screen

    You can also see a sample DRE ballot for Sarasota and
    comparison one for Moore County NC here

    http://www.ncvoter.net/download...parison_06.pdf

    Ohio has one of the 9.+ versions as well.

    We had audits, and we had manual recounts in several contests in the state.

    I will be happy to contact my State about this if you can get a credentialed computer scientist to affirmatively state that this bug affects all models.

    I can’t rely upon an anonymous computer scientist as advisor.

    I believe that all voting systems should be examined, and when HR 811 is passed, we will finally have that opportunity.

  2. 3)
    John Gideon said on 4/16/2007 @ 8:53pm PT: [Permalink]

    Joyce,

    The thing you need to do is ignore the information. Don’t warn your BOE that there may be a problem.

    The vulnerability was found on Version 8 machines and there is no reason to believe it is not on Version 9. That’s according to the source.

    But don’t say anything to anyone about it. The state might check and not find anything or they might check and find out the vulnerability is there.

  3. Avatar photo
    5)
    Brad Friedman said on 4/16/2007 @ 9:08pm PT: [Permalink]

    For additional clarity, it was actually eight computer scientists who discovered the bug in the firmware v8.# systems, as opposed to a single “anonymous computer scientist” as Joyce suggested. It was that one scientist, however, who was kind enough to put together the specific warnings about what that bug actually meant, and how states who used both v8.# and 9.# could check and/or mitigate the problem on their own systems.

    It’s a damned serious issue, and as ES&S has known about it, yet waited for someone else to find it (and only after an election contest, for which they fought any examination of their source code!), I’d suggest the onus is on ES&S to demonstrate that the prob isn’t still in v9.# systems and that the likelihood is that it is.

    You guys fought for source code disclosure in escrow in N. Carolina. Your state could do the country a great service at this time by pulling it out of escrow and checking it for this issue.

    It would be a service for the country whether the bug is there or isn’t there. So thank you in advance for pushing the NC folks to find out since they’ve got the access!

  4. 6)
    the_zapkitty said on 4/16/2007 @ 9:35pm PT: [Permalink]

    … Joyce McCloy pandered thusly…

    “I believe that all voting systems should be examined, and when HR 811 is passed, we will finally have that opportunity.”

    Actually, we can have the opportunity without enacting something as badly written as “Holt II” into law and screwing things up even worse than they are now for years to come.

  5. 7)
    MarkH said on 4/17/2007 @ 5:04pm PT: [Permalink]

    I copied the post and sent it to my WV SoS.

    She’s Republican, so there’s no telling whether it will be read, but there’s no excuse now for not knowing of the problem.

  6. 9)
    Dredd said on 4/21/2007 @ 5:54am PT: [Permalink]

    Senator Nelson’s S. 559 would assist in finding bugs in EVM software:

    `(9) PROHIBITION OF USE OF UNDISCLOSED SOFTWARE IN VOTING SYSTEMS- No voting system used in an election for Federal office shall at any time contain or use any software not certified by the State for use in the election or any software undisclosed to the State in the certification process. The appropriate election official shall disclose, in electronic form, the source code, object code, and executable representation of the voting system software and firmware to the Commission, including ballot programming files, and the Commission shall make that source code, object code, executable representation, and ballot programming files available for inspection promptly upon request to any person.

    `(10) PROHIBITION OF USE OF WIRELESS COMMUNICATIONS DEVICES IN VOTING SYSTEMS- No voting system shall contain, use, or be accessible by any wireless, power-line, remote, wide area, or concealed communication device at all.

    `(11) PROHIBITING CONNECTION OF SYSTEM OR TRANSMISSION OF SYSTEM INFORMATION OVER THE INTERNET- No component of any voting device upon which votes are cast shall be connected to the Internet at any time.

    (Section 247, emphasis added).

  7. 10)
    the_zapkitty said on 4/21/2007 @ 8:04am PT: [Permalink]

    Funny, that’s the exact same text as in Holt’s hr.811… so what’s up with that?

    Oh, right… It’s Holt II part 2!… the two bills are almost identical in text, with s.559 having a couple of good ideas that hr.811 doesn’t have… neither of which applies to the text above.

    The problem with that text, Dredd, is that it immediately decertifies every form of electronic voting machine in use in the U.S… every EVM. And every electronic voting aid as well…
    http://www.bbvforums.org/forums...591/46677.html
    …which means it becomes a multi-billion dollar unfunded mandate that requires technology that doesn’t currently exist to be implemented immediately.

    ain’t gonna happen.

    So the question becomes “What will the bill they actually pass do to fix this impossible demand?

    And the answer is: remove the impossible provision. And the “e-voting or no voting” people at ACCURATE have already given their oh-so-helpful guidance on how to accomplish this… restrict any disclosure of source code to “qualified” people.

    Do you want to place bets on just how qualified you’ll have to be to be allowed a glimpse of the machinery that runs our supposed democracy?

  8. 11)
    Joyce McCloy said on 5/8/2007 @ 12:12am PT: [Permalink]

    John Gideon said:
    “COMMENT #3 [Permalink]
    … John Gideon said on 4/16/2007 @ 8:53 pm PT…

    Joyce,

    The thing you need to do is ignore the information. Don’t warn your BOE that there may be a problem.

    The vulnerability was found on Version 8 machines and there is no reason to believe it is not on Version 9. That’s according to the source.

    But don’t say anything to anyone about it. The state might check and not find anything or they might check and find out the vulnerability is there.”

    John, why don’t you send your big news to the North Carolina State Board of Elections???

    Do you think that I have to send it for you?

    There’s no way that the NC SBOE is going to act upon information that no computer scientist will put his name on.

    But please by all means, YOU should send it in. You have an organization, you send out daily news, you are the one that believes that your information is all that is needed in order for my SBOE to act. You know the computer scientist….

    When computer scientists like David Jefferson have put their name to the information, like his opposition to the VVPAT on the ES&S iVotronic I have sent it to our SBOE and followed up.

    Brad, you said:

    “You guys fought for source code disclosure in escrow in N. Carolina. Your state could do the country a great service at this time by pulling it out of escrow and checking it for this issue.”

    And Brad, I advised you that the only computer scientists who wanted to review our source code in NC were not willing to work pro bono, they weren’t willing to follow the requirements of our law, and they weren’t willing to come to NC to do the work.
    Everyone wants to do it if: we will pay them, they can publish a report on what they find, if they can do it in their home state, etc.

    My SBOE is not going to give creditability to nameless sources for problems that exist with a different version machine. This same SBOE has already responded to my inquiries about other issues about Sarasota’s machines, and our SBOE has already made it clear to me that they consider these machines to be quite different.

    You are welcome to send your information to the NC State Board of Elections if you wish. Its not a private organization, and I even link to their site from mine.

    Brad, notice this nasty comment posted along with the others?

    the_zapkitty said on 4/16/2007 @ 9:35 pm PT…

    .. Joyce McCloy pandered thusly…

    Its that type of nasty and low brow comments that have caused many people to stop dealing with you or fooling with this blog.

    You let people trash other people in your comments section, you let it happen before, and people lose trust in you because of it. You lose part of your audience. I know I don’t forward the Brad Blog articles any more. I have had enough.

    Its all about trust. When you allow people to trash others on your blog, YOU are responsible for it.

    Unlike “the_zapkitty”, who smeared me on your blog, I use my real name.

    I used to make it a point (over a year ago) to refer people to your blog, but not anymore.

    Anyway, I saw the insults and smears (not new here) and in disgust posted this comment. I know that things wont change, I spoke to you about similar problem a year ago, and its still going on.

(Comments are now closed.)


BB SIDEBAR NOTICE

Thanks to you, The BRAD BLOG has been trouble-making and muckraking for … 22 YEARS!!!

Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman / BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

More GOP Vote Rigging Underway. Hey, Maryland Dems! Time to Get Crackin’!: ‘BradCast’ 5/14/2026

Also: GA GOP rigs Atlanta D.A. elections; MT's new voter suppression law nixed by state court; Much more...

‘Green News Report’ – May 14, 2026

With Brad Friedman and Desi Doyen...

Do Dems Have the Courage Required to Restore and Reform American Democracy? (Do You?): ‘BradCast’ 5/13/2026

Guest: Kate Riga of Talking Points Memo; Also: SC Senate leader blocks U.S. House gerrymandering; Primary results from WV, NE...

Offshore Oil Rig Fire in SoCal a Preview of Trump’s NEXT Huge Failure: ‘BradCast’ 5/12/2026

Guest: Brady Bradshaw of Center for Biological Diversity; Also: Inflation spiked to 3-year high in April; Dems still favored to win House, despite GOP map rigging...

‘Green News Report’ – May 12, 2026

With Brad Friedman and Desi Doyen...

Virginia Supremes Void Special Election on Redistricting Referendum in Huge Gift to Vote Rigging GOP: ‘BradCast’ 5/11/2026

Voting rights disappearing, Jim Crow returning before our eyes in GOP-controlled state after state; Callers ring in...

Sunday ‘Redlining Democracy’ Toons

THIS WEEK: The Voting Whites Act ... Iran and Iran We Go ... Happy Mother's Day! ...

Repubs Seek Immunity Law for Big Oil; White South Rising Again After SCOTUS Ruling: ‘BradCast’ 5/7/2026

Guest: Laura Peterson of Union of Concerned Scientists; Also: Trump panel calls for FEMA cuts as MS slammed by another tornado swarm...

‘Green News Report’ – May 7, 2026

With Brad Friedman and Desi Doyen...

Time to Reform our Illegitimate Supreme Court: ‘BradCast’ 5/6/2026

Guest: Alicia Bannon of NYU's Brennan Center for Justice; Also: Primary and special election results in OH, IN, MI...

The Corrupt Hypocrisy of SCOTUS’ VRA Ruling in the Middle of Primary Election Season: ‘BradCast’ 5/5/2026

Also: 'Project Deadlock' in Strait of Hormuz as Admin pretends ill-fated, unlawful, continuing Iran War is over; The conflict's very real, if ironic, upside...

‘Green News Report’ – May 5, 2026

With Brad Friedman and Desi Doyen...

Billionaires Spending Millions to Fight Against, Lie to Voters About CA’s Proposed, One-Time Billionaires Tax: ‘BradCast’ 5/4/2026

Guest: Harold Meyerson of 'The American Prospect'; Also: GOP states scramble to write Black districts out of existence; A warning for CA vote-by-mail voters...

Steyer Facing Deceptive Fire in CA Gubernatorial Race for Call to Eliminate ‘Trump Loophole’

Trump-allied GOP opponent lying about progressive billionaire's proposal to end state's corporate 'property transfer loophole'...

Sunday ‘Dead to Rights’ Toons

THIS WEEK: RIP VRA ... '86 47' by the Seashore ... Ballroom Grift ...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster. Full Bio & Testimonials… Media Appearance Archive… Articles & Editorials Elsewhere… Contact…

He has contributed chapters to these books…
…And is featured in these documentary films…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneInApple Podcasts/iTunesiHeartAmazon Music

Media Appearance Archives…

AD
CONTENT

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards