It’s been a topic of debate ever since hackers – presumably working for Russia – stole thousands of private emails from the Democratic National Committee and leaked them on the net. Could a nation state or other adversary hack our elections and determine the next president of the United States? The answer depends on how they try to go about it, says Avi Rubin, computer science professor at Johns Hopkins University and technical director of the university’s Information Security Institute. Election hacking is highly unlikely, he says. Attackers reaching into the ballot box from thousands of miles away won’t happen, simply because the vast majority of election machines are not connected to the internet. Some 31 states offer voting via internet, email, or fax, but nearly all only allow it as an option for military families and Americans living overseas – a very small percentage of the electorate. Only Alaska allows any voter to cast a ballot across the net, according to Verified Voting. But election rigging is a potential threat, says Rubin. That’s where adversaries attack the electronic voting machines themselves, altering the software inside the machines to favor one candidate. “There are a thousand points of vulnerability,” says Rubin. “Anyone with access to the machines at any stage could attack them.”
… Rubin says the best defense against election rigging is having the ability to audit the results using a voter verified paper trail. The problem is that 16 states have electronic voting machines but inadequate paper records. Potential swing states that lack voter verified paper trails in at least some counties include Pennsylvania, Virginia, Indiana and Florida, according to Verified Voting.
Attackers determined to alter the US election would likely focus on counties in those swing states where the final result will be likely be close and unverifiable, says Rubin. Still, initiatives to allow internet voting for all US citizens are a bigger problem, he says. “Internet voting is a terrible idea,” he says. “The best thing you can do is write to Congress and tell them you want verified paper ballots in your precinct, not the internet.”