Hacker Chronicles

Archives
Subscribe
September 5, 2026

Election System Hacking

Welcome to the September issue of Hacker Chronicles!

I'm now live on Instagram as @hackerfiction, posting photos of my cyberpunk and hacker fiction collection. I do also post on TikTok as @hackerfiction but not at the same cadence, at least not yet.

Cybernews has released the first Defcon documentary in over a decade. It's a great half hour about the world's largest, quirkiest, and broadest hacker conference. Watch it on YouTube here: _Inside The Largest Hacker Gathering in the World_ on YouTube.

On November 8, Aaron Swartz would have turned 40 years old, so I intend to dedicate the November issue to him and review the documentary The Internet's Own Boy: The Story of Aaron Swartz: available on YouTube.

Announcing this year's read-along: Snow Crash by Neal Stephenson! Get your copy now if you don't have it, or make sure your local library has it. We'll start reading in November, and my review starts in the December issue. 468 pages of legendary cyberpunk, and the book that introduced the Metaverse.

OK, what about this newsletter issue, John?

Are our voting systems secure enough? High-stakes midterms are coming up in the US. General elections in Sweden and in New Zealand too. And Iceland just voted No to restarting membership negotiations with the EU. I'm reviewing Kill Chain: The Cyber War on America's Elections – an HBO documentary on election system hacking.

/John

Writing Update

August turned out to be a great writing month! I got about 8k words written and am deep into the plot. Based on the target, I'm now more than 2/3 done with the first draft. It would be wonderful to edit during the holiday season.

Screenshot of a progress bar showing how John has written 40,161 words toward his target of 60,000.

Please Help With Ratings

I think Amazon starts showing Goodreads ratings when you have ten of them, and I'm at nine. 😩 Ratings, ratings, ratings. Hard to get, but so important for finding new readers. If you've read Submerged, please consider rating it on Goodreads. That would get me over the hump. You don't have to give me a high rating. An honest one is perfect. 🙂


September Feature: Hacking Election Systems

Yesterday, The New York Times published an article titled Homeland Security Dept. Asks for Inquiries Into Voting Machines (link, likely paywalled). A key piece of NYT's article reads:

Unlike the process of voting by handwritten ballot, ballot-marking devices rely on ballots printed from a touch-screen computer. The ballots, which typically designate a voter's choice in text form and in a bar code or QR code, are then fed into a separate machine that reads the information.

Critics of the devices have claimed that hackers could in theory manipulate the digital codes, though election integrity experts say there are no examples of that happening in an election.

It's certainly not the first time the technical integrity of US elections has been questioned. And this particular vulnerability was raised in a 2020 HBO documentary that I review below.

We live in a world where disinformation, trolling, and fearmongering are common, especially online. People and bots with an agenda try to polarize us, enrage us, and make us lose hope. I have to remind myself of this every time there's a new outpouring.

That's not to say that there aren't real events and posts that polarize, demoralize, and anger. It's just that manipulation is part of the mix and our ability to function as democracies is being challenged. Seriously challenged.

My novel Submerged incorporates this challenge in the international arena.

Longtime readers of this newsletter know that I view fiction as an important way for us to speculate and imagine what the future might hold. Sometimes positive things, but often a future crisis or dystopian state that we have to get out of. Some documentaries contain that same speculative element, especially ones that aim to warn us about something.

The HBO documentary Kill Chain is one of those.

Review of Kill Chain: The Cyber War on America's Elections

Movie poster.

  • Wikipedia link
  • HBO Max link

This documentary was released in March 2020 – the election year in which President Donald Trump was challenged by Joe Biden. Joe Biden won. In the aftermath, there were allegations that Dominion Voting Systems had been compromised, impacting the election outcome. These allegations were deemed conspiracy theories.

My review will follow the arc of the documentary and add commentary.

The Lack of a National or Federal Voting System

The US has no single, national voting system. Voting is managed by the states, and within the states it managed by counties.

At a high level, this is viewed as a strength. A diverse system with no single point of failure.

However, as Finnish security expert Harri Hursti explains in the documentary, there are worrisome commonalities that make the system much less diverse. Primarily the use of removable media, such as memory cards and USB sticks, to move and store the votes.

Thoughts:
I think distributed systems with real diversity are harder to break. And I mean that in a very broad sense. But you often hear that unity provides strength – "United we stand, divided we fall."

World War II era American propaganda poster using the phrase 'United we stand, divided we fall.'
World War II era American propaganda poster.

A diverse, distributed election system is one that achieves a shared goal – correct and fair elections based on votes by individual people. It's not one where each county sets its own goals.

Vulnerabilities in the form of single points of failure comes down to failure of imagination. The designers failed to envision what an adversary could do to the system. Or a threat analysis wasn't carried out at all.

My fiction writing explores exactly this. Hackers who look for weaknesses where the other party never thought to look themselves. Harri Hursti talked about this in the documentary – his ability to think like the adversary. That is a core skill when building defenses.

The 2016 Election Had Confirmed Hacks, Attributed to Russia

In 2017, an NSA leak to The Intercept confirmed that voting systems from a vendor called VR Systems had been hacked by Russian actors during the 2016 election. VR Systems served nearly all counties in Florida, among others. Details can be found on Wikipedia. It was eventually concluded that all 50 states were targeted.

The Intercept mishandled the actual paper copies they had received and disclosed that the leaker was a woman named Reality Winner. Part of what pinned the leak on her was printer tracking dots which readers of my novel Identified will recognize.

Photo of Reality Winner.
Reality Winner.

Winner was sentenced to five years and three months in federal prison in 2018. She was portrayed by Sydney Sweeney in the 2023 movie Reality.

Thoughts:
As you've heard me say many a time, attribution is notoriously hard. In general, you can't pin a hack on a specific actor. This is another layer to how truth is challenged. Was it Russia? Was it made to look like Russia? I personally believe it was Russia, but I am not dead certain.

Misattribution is also leveraged in conventional warfare with so-called false flag operations. I have considered using it in my fiction writing, but I waffle between using it as a deception to mislead the reader or presenting it as false off the bat.

The history of governments seeking out the media's sources and punishing whistleblowers continues to make me sad. That is a challenge to a free society in itself. Where would we have been today in trying to protect our election systems if Reality Winner had not leaked?

Every NATO Country Has Been Targeted

Since the 2016 hacks against US, it's been revealed that French elections have been targeted too.

The Russian hack against the 2014 Ukrainian presidential election is the most detailed one that Kill Chain covers. I wanted more details, and it was surprisingly hard to find. But Andy Greenberg at Wired came to the rescue, in his 2017 article Everything We Know About Russia's Election-Hacking Playbook:

In 2014, one pro-Russian hacker group tried a more fine-tuned approach to political web-hacking. A Russian-speaking hacker operation calling itself CyberBerkut compromised the website of Ukraine's Central Election Commission, and changed the election results it was set to display to declare the winner as ultra-right candidate Dmytro Yarosh. Commission officials spotted the attack less than an hour before the results were set to be released, and prevented the fraudulent version from being shown publicly. Russian state media, apparently coordinating with CyberBerkut, broadcast the fake results regardless.

And a YouTube news clip from Ukraine News One:

News on hacked 2014 Ukrainian election, on YouTube.

In the documentary, Republican Senator James Lankford says that every NATO country has had its election system targeted.

Hacking the Election Assistance Commission (EAC)

The US Election Assistance Commission, EAC for short, maintains a database of all the voting practices and operational vulnerabilities in all 50 states.

On December 1, 2016, it was revealed that a hacker had been accessing EAC servers. It was a Russian-speaking actor going by the name Rasputin, according to cybersecurity firm Recorded Future.

Screenshots of EAC's internal systems were used to prove access. Testing protocols, database access, and more.

SecurityWeek revealed that it was a SQL injection that let Rasputin in:

Rasputin was claiming to have accessed the systems via an SQLi vulnerability, which Recorded Future was able to locate and report. This flaw has now been fixed. (…) there is no suggestion that Rasputin has any direct link to the Russian government.

Thoughts:
This is yet another piece of evidence that the US election system is not as diverse and distributed as some make it out to be. There is one central federal system.

Calling yourself Rasputin sounds like a crude way of (mis)attributing the attack. Or even mockery. But who knows?

Three Main Systems, Not Fifty

At the time of the documentary, the US only had three main election systems:

  • Dominion Voting
  • Election Systems & Software, ES&S
  • Hart Intercivic

A security professional interviewed in the documentary shares how he was allowed to evaluate the security of Dominion and ES&S while working for the State of California. They found multiple vulnerabilities that could compromise the whole machine. This was not well received by those vendors.

The documentary then cuts to Harri finding decommissioned voting machines on eBay and purchasing a few to try to hack them.

One of the security claims is that US voting machines are not connected to the internet and thus cannot be hacked remotely. Harri boots up one of the machines he just bought, and the first thing it asks for is network access.

As Harri and his team acquired more models of US voting machines, they eventually organized a hacking village at the annual Defcon conference. Attendees were invited to try to hack the machines, and every piece of equipment available was "effectively breached," according to the organizers.

Thoughts:
This reminds me of a lecture I went to on cheating among undergraduate students in colleges and universities. The professor said, "There are two types of universities: Those with pretty high amount of cheating going on, and those that aren't looking."

In engineering, the saying goes, "If it's not tested, it's not working."

Machine Number Three in the Georgia Governor's Election of 2018

Two years after the 2016 presidential election with confirmed hacker interference, Georgia elected governor. It was Brian Kemp (R) against Stacey Abrams (D).

Machine number 3 out of 7 in a certain Georgia precinct had significantly higher votes for Kemp than for Abrams as governor.

A statistics research group from UC Berkeley simulated how likely it was that a single machine out of 7 would record that many Republican votes if the total across all 7 machines leaned heavily Democratic. The chance was less than one in a million.

In this 2018 governor's race, Georgia still used AccuVote, which had already been shown to be hackable in 2006.

Kemp won by 54,723 votes, giving him 50.2%. It was Georgia's closest governor's race since 1966. A lot has been said about this election, and lawsuits were filed. You can read about it on Wikipedia.

Paper Trails and Risk-Limiting Audits

Statistics researchers have put forward ways to address this. It all comes down to human-readable paper trails and so-called risk-limiting audits.

Such an audit means you manually examine a statistical sample of paper ballots until you know checking more of them won't change the outcome. The audit will be small and inexpensive if the margin of victory is large. Only when the margin is small do you need a large audit, which totally makes sense.

Here are diagrams on how risk-limiting audits work (I know the image has transparent background and won't look good in dark mode – sorry!):

Diagrams on how risk-limiting audits work. Sample sizes depend on winning margin, number of ballots voted, confidence level, and type of audit.

The voting machines in Georgia 2018 came from Dominion. After a person had tapped in their vote on the screen, the machine printed a paper with a QR code. This was referred to as a paper trail. But humans can't read QR codes, so voters couldn't check that the printed paper matched their votes. The QR code was then scanned into the counting machine.

By US law, all federal ballots have to be destroyed 22 months after an election. In 2018, the ballots from the 2016 election were destroyed, so we can't go back and check that outcome.

Thoughts:
Risk-limiting audits match my understanding of what's needed. This is the level of rigor we need. Is there any democracy that's doing it, though?

My Remarks on Kill Chain

Scale and the Phone Book Example

My personal view is that voting should be done with paper ballots that are collected, counted, and stored by humans. I don't think there exists a computerized system more secure than paper ballots managed by humans, and I've held that view for decades.

Risk-limiting audits are a sound way of minimizing the amount of human work needed.

A key thing I learned early in my career is that computers let adversaries scale attacks. That's one of the things computers do really well – scale what humans can process by a million, a billion, a trillion times, etc. The example that taught me this was the phone book. According to a professor I spoke to, Norway by policy stopped the phone book from being published online. The reason was to prevent data processing at scale. That policy was a late 1990s thing, and would have worked reasonably well if not for allowing the phone book on CD-ROMs. Nowadays, computers digitize physical books at blazing speed.

For a hacker to compromise all systems of a specific version is usually easy compared to compromising the first one. Even that dynamic has now changed with modern AI making it significantly easier to compromise a single system.

Using pen, paper, and human counting is to deliberately deny the attacker scale. Deny them the advantage of asymmetry. Require them to physically go to every precinct and steal, destroy, or change every ballot. Such an attack would be noisy and easy for voters to understand. By contrast, a computer attack from a foreign country that silently changes the votes is science fiction to most people.

The Kill Chain documentary makes that very same argument: don't depend solely on computer systems for how we elect leaders with the power to change laws, confiscate property, and go to war.

The Double-Edged Sword of the Warning

I think the HBO documentary wanted to make sure that the 2020 presidential election wasn't hacked. What ended up happening was the losing side claiming the election was manipulated, hacked or not.

This can be seen in broader ways today. Generative AI has made it easy and accessible to fabricate photos, videos, and audio. We've all been warned of this. But that has also enabled everyone to dismiss photos, videos, and audio recordings as fake.

Sowing doubts about election integrity is not a good way forward. We have to re-establish integrity and test our systems based on threat models.

The Truth Is Escaping Us

Humans want to know what's true, at least as long as it doesn't challenge any deeply held beliefs. Computers and their scale are increasingly invalidating our old ways of seeking the truth. Manual photo manipulation has been possible for a century but was not scalable. Here's a censorship example from Soviet times:


The photo with Stalin center and Nikolai Yezhov to the right.


The photo with Nikolai Yezhov removed after he was purged.

"Photoshopped" images have been part of everyday life for decades, but Photoshop still required significant skills and time at the computer.

With generative AI, fabrication scale is here. We just haven't internalized it yet.

Questioned Truth or Multiple Truths in Fiction

Our inability to know what is really true is fertile ground for fiction.

Gaslight is a 1944 American psychological thriller in which a husband manipulates his wife to think she's going insane. He makes it look like she's stealing his things, moving things in the house, and hallucinating that the gaslights dim. It won Ingrid Bergman an Academy Award for Best Actress. "Gaslighting" entered public discourse much more recently.

A case of multiple perspectives presenting multiple truths is the movie Vantage Point. In it, there's an assassination attempt on the US president, and we get to see the event multiple times from different vantage points. The truth, or what we believe to be the truth, changes along the way.

In the craft of fiction writing, authors have to be careful with what's known as an unreliable narrator. Readers trust the author to take them on a fulfilling and entertaining journey in their mind. The investment is not only time to read but also suspension of disbelief – allowing the story feel real. When the author turns on the reader by lying, all of that is at risk.

Final Thought on Kill Chain

What lingers with me after watching Kill Chain from early 2020 is that it was right about insufficient security in US election systems, but it was too narrow-minded on how and from where the attacks would come. Election integrity has been publicly challenged from within to achieve political goals, and not just in the US. Bad security enables such claims.

Other Noteworthy Documentaries

  • The Great Hack, a 2019 documentary about the Facebook–Cambridge Analytica data scandal.
  • Hacking Democracy, the 2006 HBO documentary that preceded Kill Chain.

Currently Reading

I'm still reading Three Men in a Boat by Jerome K. Jerome. It's unfortunately not as good as I remember it from high school, and 1800s language always slows me down.

Don't miss what's next. Subscribe to Hacker Chronicles:
Older → Happy birthday to me 🎉😄