Georgia: Lawsuit says new Georgia voting system should be stopped | Mark Niesse/The Atlanta Journal-Constitution

Voters who want paper ballots filled out by hand asked a federal judge late Friday to prevent Georgia from using the $107 million voting system the state just bought. The request comes a day after the judge ruled that voters must use some type of paper ballots next year, but her decision didn’t address the legality of the state’s new voting system.Election officials plan to replace Georgia’s 17-year-old electronic voting machines with a system that combines touchscreens with paper ballots. Voters will pick their candidates on a 21.5-inch tablet that’s connected to a ballot printer starting with the March 24 presidential primary.The lawsuit, filed by voters and election integrity advocates, alleges the new voting machines will remain vulnerable to hacking, malware, bugs and misconfiguration.But state election officials have said that paper ballots will ensure the accuracy of results during recounts and audits.In addition, the lawsuit said the printed ballots aren’t truly verifiable. Although voters will be able to review ballots before casting them, the ballots embed voters’ choices in bar codes that are only readable by scanning machines.“No elector can visually review and confirm whether the bar code accurately conveys their intended selections,” according to the amended complaint.

National: America faces a voting security crisis in 2020. Here’s why – and what officials can do about it. | Emily Goldberg/Politico

Paperless voting machines are just waiting to be hacked in 2020. And “upgrading” to paper-based voting machines may sound like an oxymoron, but it’s something cybersecurity experts are urging election officials across the country to do. A POLITICO survey found that in 2018, hundreds of counties in 14 states used paperless voting machines — and almost half of the counties that responded to the survey said they don’t plan on changing that ahead of 2020. Security experts said paperless voting machines are vulnerable to hacking because they leave no paper trail and there’s no way to reliably audit the results when an error occurs. Thousands of Redditors joined us as cybersecurity reporter Eric Geller and voting security expert and University of Michigan professor J. Alex Halderman took on Reddit’s most pressing questions about the weaknesses in America’s election systems. We chatted about voting methods in various countries from the U.S. to India, how much the transition to paper ballots would cost, and even “Star Wars.”

National: Most states still aren’t set to audit paper ballots in 2020 – Despite expert recommendations | Colin Lecher/The Verge

Despite some progress on voting security since 2016, most states in the US aren’t set to require an audit of paper ballots in the November 2020 election, according to a new report out this week from the Brennan Center for Justice. The report notes that experts and government officials have spent years recommending states adopt verifiable paper ballots for elections, but a handful still use electronic methods potentially vulnerable to cyberattacks. In 2016, 14 states used paperless machines, although the number today is 11, and the report estimates that no more than eight will use them in the 2020 election. But the report also found that most states won’t require an audit of those paper records, in which officials review randomly selected ballots — another step experts recommend. Today, only 22 states and the District of Columbia have voter-verifiable paper records and require an audit of those ballots before an election is certified. The number will increase to at least 24 states by the 2020 elections, according to the report. “However,” the report notes, “there is nothing stopping most of these remaining states from conducting such audits if they have the resources and will to do so.”

National: Russian hackers, town budgets, Windows updates: Officials grapple with realities of election security | Ben Popken and Kenzi Abou-Sabe/NBC

The nation’s highest agency dedicated to election administration convened a security summit on Thursday to figure out how to confront a problem: The majority of the country’s 10,000 voting jurisdictions still run outdated software. In July, Associated Press reported that many counties still use Windows 7, initially released in 2009, or even older software in their back office election management systems used by officials to administer elections, but not on the machines where voters cast their ballots. It’s so old that Microsoft announced last year it will soon stop supporting it — shipping free updates to bugs or fixing security issues. After 2020, updates will require a fee. But inside a 21-seat conference room in Silver Spring, the discussion of the Election Assistance Commission — which included state election directors, secretaries of state and representatives from the Department of Homeland Security, election system manufacturers and testing laboratories — the hastily organized meeting also touched on broader frustrations over challenges local election officials face in trying to secure their voting systems as well as inaction from politicians in Washington. “We are talking about local communities having trouble funding roads and water bills, and now we want them to take part in defense against foreign and state actors,” said Kentucky State Election Director Jared Dearing.

National: Election Security in 2020 Comes Down to Money, and States Aren’t Ready | Kartikay Mehrotra and Alyza Sebenius/Bloomberg

The front line to protect the integrity of the U.S. presidential election is in a Springfield strip mall, next to a Chuck E. Cheese’s restaurant. There, inside the Illinois Board of Elections headquarters, a couple dozen bureaucrats, programmers, and security experts are furiously working to prevent a replay of 2016, when Russian hackers breached the state’s voter registration rolls. For 2020, Illinois is deploying new U.S. government software to detect malicious intrusions and dispatching technology experts to help local election officials. Even the National Guard, which started its own cyber unit several years ago, is on speed dial for election night if technicians needed to be rushed to a faraway county. Still, Illinois officials are nervous. The cash-strapped state remains far short of the resources needed to combat an increasing number of nations committing geopolitical breaches. “We’re in an unusual time, and yes, there is concern about whether we have enough to go into 2020 totally prepared for what the Chinese, Russians, or North Koreans or any enemy of the United States may do to influence our elections,” says Governor J.B. Pritzker, a Democrat. “We’re securing our elections with state resources, but there is a federal need. This is a national crisis.”

National: Only One Republican Supported That Divisive Election Security Bill. Here’s Why He Voted in Favor | Robert Hackett/Fortune

Last week we discussed election security. Let’s dig a little deeper into divisions provoked by one of the major pieces of proposed legislation, the Securing America’s Federal Elections Act. The bill has lately become a political flashpoint, blocked by Senate Majority Leader Mitch McConnell of Kentucky, who ostensibly fears further federalizing elections more than he fears the subversion of American democracy through hacking, foreign interference, or other hi-jinx. The bill primarily aims to require states to use voting machines that are up-to-date, not Internet-connected, made in America, and produce paper-based, voter-verifiable ballots. These are all sensible criteria, and it’s hard to argue against their adoption. In addition, the bill would earmark federal funds to help states get the new gear in place by 2020—a more contentious component. (See also this Wall Street Journal editorial which lays out other gripes.) While the Democratic House passed the bill with 225 votes in June, only one Republican voted in favor: Representative Brain Mast of Florida. It’s worth noting that Mast is not Republican in name only, as an analysis by the data junkie blog FiveThirtyEight makes clear. As of the end of last year, Mast had voted in line with President Donald Trump’s policy initiatives 92.7% of the time.

National: Windows 7 woes crash into 2020 election cycle | Derek B. Johnson/FCW

Thousands of jurisdictions are relying on a nearly obsolete operating system to run their election systems, and it’s not clear they will have the money or time to wean themselves off before the 2020 elections. At an Aug. 15 election security forum hosted by the U.S. Election Assistance Commission (EAC), state officials, vendors and experts warned that a lack of money and resources as well as technical and logistical hurdles are preventing them from migrating their election systems from the Windows 7 operating system to Windows 10. Lousiana Secretary of State Kyle Ardoin illustrated the costs and complexities associated with replacing outdated operating systems on election equipment like voter registration systems, e-pollbooks and other software. He said Louisiana will have spent more than $250,000 to replace computers using Windows 7 in clerks of court and voter registration offices. An additional $2 million has been spent to temporarily lease voting machines that require Windows 10 while the state waits for a new batch to go through the procurement process. He estimated the cost of updating to Windows 10 to be around $670 per machine, not including the costs associated with testing, configuration and deployment.

Editorials: There’s no excuse for failing to secure election systems from Russian meddling | St. Louis Post-Dispatch

More than a dozen states are still using electronic ballot systems that leave no paper trail — an invitation to Russia and anyone else who wants to hack into and disrupt America’s next national election. This gaping security hole is being blamed on lack of money in state and local budgets, and a lack of urgency among some Republican officials. Both reasons are unacceptable. Americans may be divided about the veracity of some aspects of the report and testimony from special counsel Robert Mueller, but those who think that renders debatable his conclusions about Russian election interference are simply not paying attention. Mueller’s unambiguous warning that Russia hacked into the election systems of all 50 states in 2016 and is planning to do so again next year has been confirmed on both sides of the aisle. U.S. intelligence agencies have long insisted it happened and will happen again. Even the Republican-controlled Senate Intelligence Committee reached the same conclusion in a recent report. “Russian activities demand renewed attention to vulnerabilities in U.S. voting infrastructure,” the report found. “In 2016, cybersecurity for electoral infrastructure at the state and local level was sorely lacking. … Aging voting equipment, particularly voting machines that had no paper record of votes, were vulnerable to exploitation by a committed adversary.”

Georgia: Judge blasts Georgia officials’ handling of election system | Kate Brumback/Associated Press

Georgia election officials have for years ignored, downplayed and failed to address serious problems with the state’s election management system and voting machines, a federal judge said in a scathing order this week. U.S. District Judge Amy Totenberg said those problems place a burden on citizens’ rights to cast a vote and have it reliably counted. She called Georgia’s voting system “antiquated, seriously flawed, and vulnerable to failure, breach, contamination, and attack.” Despite those findings, Totenberg ruled Thursday that Georgia voters will use that same election system this fall because of concerns about the state’s capacity to make an interim switch while also implementing a new system. Plaintiffs in a lawsuit challenging Georgia’s system had asked Totenberg to order an immediate switch to hand-marked paper ballots for special and municipal elections this fall. But she declined, citing worries about the state’s capacity to manage an interim switch while also implementing a new system that is supposed to be in place for the March 24 presidential primaries. ″(T)he totality of evidence in this case reveals that the Secretary of State’s efforts in monitoring the security of its voting systems have been lax at best — a clear indication that Georgia’s computerized election system is vulnerable in actual use,” Totenberg wrote in a 153-page ruling that devotes considerable space to chronicling those shortcomings.

Pennsylvania: Most Pennsylvania counties pick paper ballots | John Finnerty/CHNI

Counties buying voting machines that allow voters to fill out paper ballots are paying half what counties buying tablet-based voting technology are paying, according to an analysis released Thursday by the University of Pittsburgh. Researchers examined the costs paid by 31 counties for voting machines, as counties across the state move to replace their election equipment before the 2020 presidential election. In total, the counties are calculated to spend $69 million on those systems. The state has told the counties to replace their voting machines with new equipment that provide a paper record of votes cast before the 2020 presidential election. That move was prompted by a settlement to a lawsuit filed by former Green Party presidential candidate Jill Stein after the 2016 election.

Wisconsin: Election security threats and the proposed solution | WXOW

Outdated Windows systems could impact election security in Wisconsin. Officials say the Wisconsin Elections Commission (WEC) has started a pilot program to address concerns. The proposal, prepared by Election Security Lead Tony Bridges, cites concerns over aging computer systems. He states, “the strength or weakness of any one work station could affect the security of the entire state’s elections infrastructure.” Bridge then explained at least a handful of computers that access WisVote no longer receive security updates; that includes Windows XP which hasn’t been updated since 2014. WEC won’t specify which users are vulnerable due to privacy concerns. “We always want to be careful when we’re talking about elections security,” said WEC PIO Reid Magney. “We don’t want to divulge where there might be vulnerabilities in the system.”

Belarus: Belarus to use semitransparent ballot boxes, e-voting | BelTA

Belarus plans to use semitransparent ballot boxes and electronic voting in the future, Chairperson of the Central Election Commission (CEC) of Belarus Lidia Yermoshina said in an interview to the STV channel, BelTA has learned. “We are gradually introducing different standards. Some things we have not introduced yet are no longer used in other countries. For example, we have always been pressurized to use transparent ballot boxes everywhere. I can say that this is no longer in fashion. Moreover, it contradicts the international standards. Transparent ballot boxes do not secure the secret expression of voters’ will. Today’s trend is to use semitransparent boxes and apply e-voting. I believe we will be introducing this in the future,” Lidia Yermoshina said. Speaking about the rotation of the parliament, the CEC chair said that the head of state insists on some one third of MPs to stay for the second term. At the same time, the term of office for every MP should not exceed two terms in a row. “We support and select future candidates taking into consideration all the proportions,” she stressed.

Russia: Blockchain Voting System in Moscow Municipal Elections Vulnerable to Hacking: Research Report | Trevor Holman/CryptoNewsZ

A recent research report by a French cryptographer demonstrates that a blockchain voting framework utilized in Moscow’s municipal elections is susceptible to hacking. The researcher at the French government research establishment CNRS, Pierrick Gaudry, have examined the open code of the e-voting platform dependent on Ethereum in his paper. Gaudry inferred that the encryption plan utilized by a portion of the code is “totally insecure.” The research report titled, “Breaking the encryption scheme of the Moscow internet voting system” by Pierrick Gaudry, a researcher from CNRS, French governmental scientific institution had examined the encryption plan used to verify the open code of the Moscow city government’s Ethereum-based platform for e-voting. Gaudry concluded that the encryption scheme utilized by a portion of the code is entirely insecure by clarifying –

We will show in this note that the encryption scheme used in this part of the code is completely insecure. It can be broken in about 20 minutes using a standard personal computer and using only free software that is publicly available. More precisely, it is possible to compute the private keys from the public keys. Once these are known, any encrypted data can be decrypted as quickly as they are created.

United Kingdom: Subcontractor’s track record under spotlight as London Mayoral e-counting costs spiral | Kat Hall/The Register

Concerns have been raised over a key supplier of an e-counting system for the London Mayoral elections in 2020. The contract, split between Canadaian integrator CGI and Venezuelan-owned Smartmatic, will cost nearly £9m – more than double the procurement cost of £4.1m for the system at the last election in 2016. During a July hearing about the 2020 elections at the London Assembly Oversight Committee, members heard that Smartmatic, which builds and sells electronic voting tech, had worked on the Scottish elections. However, the London Assembly has since confirmed to The Register that Smartmatic was not involved. The company was also recently blamed for a number of technical glitches in the Philippine elections. The London Assembly was told costs had increased because the new vote-counting system offered better functionality than the previous procurement.