CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

In letter to federal Election Assistance Commission, investigators from CA's unprecedented e-vote review blast the approval of flawed protocols in certification tests for new Diebold e-voting system...

Share article:

A group of computer scientists and security experts from California’s 2007 landmark “Top-to-Bottom Review” (TTBR) of electronic voting systems have sent a two-page letter [PDF] of condemnation to the U.S. Election Assistance Commission (EAC), taking the federal body to task for their approval of misused security findings from the TTBR in recent certification testing for a new e-voting system made by Diebold/Premier.

The voting system, Premier’s Assure 1.2 — made by Premier Election Solutions, Inc. (formerly named Diebold Election System, Inc. and recently purchased by Election System and Software, Inc.) — was granted federal certification by the EAC last August under new test protocols which “should not have received the EAC’s approval,” according to the letter penned by Aaron Burstein and Joseph Lorenzo Hall, and signed by twelve other investigators and participants in the TTBR project.

The letter was addressed to the EAC’s Director of Testing and Certification Brian Hancock, a longtime official at the commission with a disturbing background of helping to hedge test results for other electronic voting systems…

‘Completely Inadequate’

The test plan approved by the EAC’s Hancock for the Assure system, the scientists argue in their letter, allowed iBeta Laboratories to test the Premiere/Diebold combination optical-scan and Direct Recording Electronic (DRE, touch-screen) voting system based on a fundamentally misunderstood interpretation of an important finding from the TTBR study.

“iBeta interpreted the TTBR studies of the Premier system’s predecessor [the older systems made by Diebold] to have ‘concluded that the vulnerabilities within the system depend almost entirely on the effectiveness of the election procedures,'” write Burstein and Hall. “On the basis of this interpretation, iBeta developed a test plan that called for ‘no additional testing’ of the Premier system’s security properties. The EAC approved this plan.”

The EAC’s new testing regime was recently implemented in light of years of disastrous testing in which systems had been tested in secret by labs selected and paid for by the voting system manufacturers themselves. The result was the failed e-voting systems which now litter the nation’s electoral landscape. Those systems, almost every single one of them, have now been found in independent scientific study after study, including CA’s TTBR, “an unprecedented, in-depth evaluation of California’s voting systems, which allowed investigators to gain a better understanding of their vulnerabilities,” according to the letter, to be extraordinarily insecure on virtually every level, frequently unreliable and often inaccurate in their results.

The TTBR resulted in California’s decertification of a number of systems previously approved under the old EAC-overseen testing procedures. It would appear that the new testing system may be as riddled with problems and possible failure as the old one, at least if the EAC’s questionable certification of the Premier Assurance system, as described in the letter from the CA investigators, is any indication.

More from the Burstein/Hall letter:

iBeta’s misunderstanding of the significance of the TTBR findings and the EAC’s approval of a test plan that was designed around this misunderstanding, represent a missed opportunity to use the testing and certification process to improve voting system integrity and reliability.

iBeta misunderstands the results of the TTBR. The TTBR concluded that the number, extent, and severity of these vulnerabilities were so substantial that the technological security mechanisms were completely inadequate to protect the integrity and security of both the systems and of the election.[1] This directly contradicts the statement that “the vulnerabilities within the system depend almost entirely upon the effectiveness of the election procedures.” The vulnerabilities are present, regardless of the election procedures. The team concluded that these flaws were so severe as to render the system’s technological security measures essentially without value; these vulnerabilities could only be mitigated by the strictest of procedures. The California Secretary of State’s response to the TTBR was to decertify two systems until their respective vendors, one of which was Diebold,[2] fixed many problems with their security mechanisms. Even now, these machines are subject to strict new procedural rules designed to mitigate the vulnerabilities which remain. Such drastic measures were necessary precisely because the underlying vulnerabilities were not detected and analyzed during conformance testing.

iBeta’s light treatment of the TTBR results, therefore, should not have received the EAC’s approval.
_________________________

1 Other studies, such as the EVEREST study that the Ohio Secretary of State sponsored, reached similar conclusions.

2 At the time of the TTBR, Diebold, Inc. had yet to change the name of its election systems subsidiary from Diebold Election Systems to Premier Election Solutions.

The 101-page iBeta test plan [PDF] was approved earlier this year by the EAC’s Director of Testing and Certification, Brian Hancock, who notified [PDF] iBeta on April 7, 2009 “that the tests proposed, if performed properly, appear to be sufficient to fully test the system.”

The Assure 1.2 voting system was then officially certified by the EAC [PDF] on August 6th of this year, as the third “to achieve federal certification” under the EAC’s new “Voting System Testing and Certification Program.”

Hancock’s Dubious History at the EAC

It should be noted here that Hancock played a key role at the EAC in 2004, by improperly giving a “qualification number” (the phrase the EAC now uses to describe successful federal certification testing under the previous test regime) to the Sequoia Edge with Verivote Printer touch-screen voting system. The number was officially granted for the system even though testing had not been fully completed by the test labs — where the system had been failing miserable — in violation of the EAC’s own “qualification” procedures at the time.

The sleight-of-“qualification”-hand was essentially carried out in apparent hopes of legitimizing Nevada’s illegal use of that particular voting system in 2004, for the first time, where it had been used without a “qualification number,” in violation of state law, in the September primary. That, even though then-SoS, now U.S. Congressman Dean Heller (R) had lied to the press and public by telling them, in July of that year, that the system “has passed federal certification with flying colors.”

Between the September Primary and the November Presidential General Election, Hancock issued the “qualification number,” commonly known as “federal certification” back then, to the Sequoia Edge with Verivote system. The completion of the paperwork by the test lab, allowing for the qualification to be issued, would not officially be completed until December 21, 2004. The system would not be officially certified in the state of Nevada until January 12, 2005, as documents obtained by The BRAD BLOG’s long efforts at public records requests has revealed.

The entire EAC/Nevada/Sequoia scam described above is documented at length in “The Selling of the Touch-Screen ‘Paper Trail’: From Nevada to the EAC,” an investigative report we contributed with Michael Richardson and John Gideon as a chapter for Mark Crispin Miller’s 2008 book Loser Take All: Election Fraud and The Subversion of Democracy, 2000-2008.

In requesting a comment from Hancock and EAC spokesperson Jeannie Layson in regard to the letter from the CA investigators, we were told that the commission is preparing a formal reply to the authors. We will update this item appropriately when we receive a copy of that reply.

UPDATE 10/22/09: The EAC has finally responded today, with a letter in reply [PDF]. The reply from Hancock seems to attempt to rebut Hall/Burstein’s assertion that iBeta’s tests did “‘no additional testing’ of the Premier system’s security properties.” The scientists tell us they’re reviewing the letter and may be preparing their own response in turn. If they do, we’ll update again.

The BRAD BLOG covers your electoral system, fiercely and independently, like no other media outlet in the nation. Please support our work with a donation to help us keep going.Please CLICK HERE to help support our work today!

Share article:

--- COMMENTS follow below Ad Content ---

Reader Comments on

CA Computer Scientists Charge U.S. EAC Misused Security Findings from Landmark E-Voting Study

2 Comments

(Comments are now closed.)


2 Responses

  1. 1)
    David Jefferson said on 10/16/2009 @ 6:08pm PT: [Permalink]

    Just a note of clarification, the signers were computer scientists and scholars involved in the TTBR from all over the U.S., not just from California.

  2. Avatar photo
    2)
    Brad Friedman said on 10/17/2009 @ 10:55am PT: [Permalink]

    Thanks for helping to clarify, David. I had the most difficult time explaining clearly who the authors/signatories exactly were in this story for some reason!

    BTW, any particular reason you were not one of the signatories? I was surprised to see your name NOT on the letter.

(Comments are now closed.)


--- Ad Content ---

SEARCH FUNCTIONALITY
Okay. Just finished up a weekend of work on Search functionality here. Search should now be much faster and more accurate! But I could use your help in testing. Please try it out and let me know how it works or if you find any problems I should try to fix! Thanks! — Brad

Thanks to you, The BRAD BLOG has been trouble-making and muckraking for … 22 YEARS!!!

Please help The BRAD BLOG, BradCast and Green News Report remain independent and 100% reader and listener supported in our 23rd YEAR!!!

ONE TIME
any amount...

MONTHLY
any amount...

OR VIA SNAIL MAIL
Make check out to...
Brad Friedman / BRAD BLOG
7095 Hollywood Blvd., #594
Los Angeles, CA 90028

RECENT POSTS

The Horses Races AND The Track Conditions: ‘BradCast’ 6/23/2026

The real reason Trump endorsements matter; SCOTUS v. VRA again; Judge blocks Admin vote suppression tool; GOP meddling in Dem primaries; Senate Repubs to finally stand up to Trump?...

‘Green News Report’ – June 23, 2026

with Brad Friedman & Desi Doyen...

Scandals and Vandals, Memoranda and Referenda: ‘BradCast’ 6/22/2026

Trump pretends Reflecting Pool vandalized; U.S.-Iran negotiations won't end well; Controversial Billionaire Tax qualifies for CA ballot; Callers ring in...

Sunday ‘White Flag, Green Pool’ Toons

THIS WEEK: The editorial cartoonists reflect upon a loser...

‘Iran Wins’: Trump Loyalists Rebuke Pathetic Iran ‘Deal’: ‘BradCast’ 6/18/2026

Also: Admin to restore ocean monitoring system; $350M quietly diverted to White House ballroom; 'American Flag Blue' paint now peeling off Trump's neon green reflecting pool...

‘Green News Report’ – June 18, 2026

With Brad Friedman & Desi Doyen...

The Trouble With Trillionaires (and Billionaires): ‘BradCast’ 6/17/2026

Guest: Michael Mechanic of Mother Jones; Also: Trump's Iran deal is great for Iran; GA Repubs punt new gerrymander (for now); Primary and Special election results from GA, AL, OK, DC, CA...

‘Just a Flat Anti-Trust Violation’: DOJ Defies Career Staff to Okay Paramount-Warner Deal: ‘BradCast’ 6/16/2026

Guest: John Bergmayer of Public Knowledge on the corrupt merger and threat to CNN; Also: Return of the fake electors! In NV, GA primaries and criminal arraignments in WI...

‘Green News Report’ – June 16, 2026

With Brad Friedman & Desi Doyen...

Deal or No Deal in Iran, Trump is Losing his War on America: ‘BradCast’ 6/15/2026

One court loss after another (but not for the Knicks!) over an otherwise very distracting weekend; Plus: Callers ring in!...

80-Year Old President Now Underwater in Almost Every State

Including Florida, Texas, Ohio...

Sunday ‘Happy Birthday’ Toons

THIS WEEK: 80 47 ... Deal or No Deal? ... FIFA on ICE ... Trump 💖 Inflation ... Platner and Pigs ...

Trump’s Name Removed from Kennedy Center Building

UPDATES: Court rejects last minute appeal, rules name must come down off building; Workers build scaffolding solely to obscure removal; By Saturday morning, name is reportedly down, sign still curtained off...

Trump Policies Imperiling Social Security, Depleting Trust Fund; ‘BradCast’ 6/11/2026

Guest: Nancy Altman of Social Security Works; Also: FL Supremes okay GOP's unconstitutional U.S. House map; Ebola outbreak explodes amid U.S. leadership vacuum...

‘Green News Report’ – June 11, 2026

With Brad Friedman & Desi Doyen...

About Brad Friedman...

Brad is an independent investigative journalist, blogger and broadcaster. Full Bio & Testimonials… Media Appearance Archive… Articles & Editorials Elsewhere… Contact…

He has contributed chapters to these books…
…And is featured in these documentary films…

BRAD BLOG ON THE AIR!

THE BRADCAST on KPFK/Pacifica Radio Network (90.7FM Los Angeles, 98.7FM Santa Barbara, 93.7FM N. San Diego and nationally syndicated, Monday-Thursday, on many other affiliate stations! ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneIn | Apple Podcasts/iTunes | iHeart | Amazon Music
GREEN NEWS REPORT, nationally syndicated, with new episodes on Tuesday and Thursday. ALSO VIA PODCAST: RSS/XML feed | Pandora | TuneIn | Apple Podcasts/iTunes | iHeart | Amazon Music
Media Appearance Archives…

--- Ad Content ---

ADDITIONAL STUFF

Brad Friedman/
The BRAD BLOG Named...

Buzz Flash's 'Wings of Justice' Honoree
Project Censored 2010 Award Recipient
The 2008 Weblog Awards