• 5 mins read
  • Published
  • Updated

Federal Election Security Review Halted After Voting Machine Findings

Nina Halbrook Business & Technology Writer Farmington Voice

Post by Nina Halbrook

Federal Election Security Review Halted After Voting Machine Findings Farmington Voice © farmingtonvoice.com
Federal Election Security Review Halted After Voting Machine Findings © farmingtonvoice.com

A federal review of Dominion voting systems in Puerto Rico was abruptly stopped after researchers found serious vulnerabilities but no evidence of vote tampering, raising questions about political pressure on election security work ahead of the 2024 midterms.

A federal effort to examine the security of voting machines used in Puerto Rico's 2024 elections was unexpectedly halted after researchers uncovered significant vulnerabilities but found no evidence that votes had been altered, according to Mojave Research, the cybersecurity firm leading the review.

Mojave Research, a small firm specializing in cybersecurity, spent about six weeks analyzing Dominion voting systems at the request of the Office of the Director of National Intelligence (ODNI). The team identified at least a dozen high- or critical-severity software flaws, including reused passwords, disabled firewalls, and weak cryptographic protections. In Puerto Rico, the presence of active cellular modems in the machines created additional potential entry points for attackers.

Despite these findings, Mojave Research reported that it found no indication any of the vulnerabilities had been exploited or that any votes had been changed. The company requested more time to continue its investigation, but federal officials initially appeared ready to expand the project, asking Mojave to increase its team from about 10 to 60 people and providing funding for additional equipment and personnel.

According to Mojave executives, the expansion was abruptly canceled as the company prepared to move forward. The decision came after pressure from individuals described as "White House-adjacent," who were reportedly dissatisfied that the research did not support claims of widespread election fraud in the 2020 presidential election. Mojave's CEO, Jason Wareham, and Chief Technology Officer, Manbir Gulati, discussed the episode at the DEF CON Voting Village in Las Vegas, where they presented their technical findings and described the political challenges they faced.

Political Pressure and Contract Termination

Mojave's involvement began when ODNI, under then-director Tulsi Gabbard, asked the firm to examine voting machines and data from Puerto Rico. The review was part of a broader federal investigation into allegations of foreign interference in U.S. elections, including claims that Venezuela had hacked Puerto Rico's voting systems. However, the probe found no evidence of foreign tampering.

Wareham said ODNI officials overseeing the technical work supported continuing the research, but a separate group linked to the White House pushed back when Mojave did not produce evidence of election manipulation. According to reporting by Reuters, Trump adviser Kurt Olsen, a prominent figure in efforts to challenge the 2020 election results, pressured Mojave to expand its search for evidence and later advocated for terminating the company's contract when no proof of hacking was found. Olsen also reportedly accused Mojave of receiving funding from billionaire George Soros, a claim the company denied and documented to federal officials.

The contract was ultimately ended as the government prepared to expand Mojave's work, with the company receiving a stop-work order and no additional funding. Mojave executives said they were told Olsen played a key role in the decision to halt the project, though they did not have direct proof that White House officials ordered the termination.

Vulnerabilities Identified, No Evidence of Tampering

During their analysis, Mojave researchers found at least 12 major vulnerabilities in the commercial software running on the voting systems. These included easily cracked passwords, embedded credentials, disabled firewalls, and open network ports. The cryptographic protections were described as inadequate for critical infrastructure. Mojave was able to successfully exploit five of the vulnerabilities, though none were newly discovered and fixes were already available before the systems were used in the election.

The company's review focused on a single system from one manufacturer in one jurisdiction, but Mojave suspects similar issues may exist in other voting systems. The firm produced a 100-page report detailing its findings and has been in discussions with Liberty Vote, which acquired Dominion's election business. Liberty Vote stated it had not received Mojave's report and did not plan to make changes before the November elections.

Despite the extensive technical issues, Mojave emphasized that it found no evidence the vulnerabilities had been exploited or that votes were changed. The company had sought an additional six months to a year to conduct a deeper analysis but was unable to continue after the contract was terminated.

Next Steps and Ongoing Concerns

With the federal review halted, Mojave Research has filed paperwork to establish the Machine Assurance Institute, an organization aimed at bringing together cybersecurity experts and election technology companies to independently verify voting infrastructure. The company has also pushed for its report to be made public, and it may be released through a Freedom of Information Act request.

The episode highlights ongoing concerns about the security of voting systems and the influence of political pressure on election security work. As the 2024 midterms approach, Mojave's findings suggest that while technical vulnerabilities exist, there is no evidence to support claims of widespread vote manipulation. The company's experience also underscores the challenges faced by independent researchers working in a highly politicized environment.

Election security reviews like the one conducted by Mojave Research are typically overseen by federal agencies such as ODNI and the FBI, often in response to concerns about foreign interference or technical vulnerabilities. These reviews can lead to recommendations for system improvements, but their findings and continuation may be affected by political considerations, especially in the context of disputed election results.

Related Stories