Is E2E Verifiability a Magic Bullet for Online Voting

John Odum

Voting Village @ DEF CON 33 · Day 1 · Voting Village

Overview

In this compelling talk, John Odum, a seasoned election administrator and former candidate for Vermont Secretary of State, critically examines the increasingly popular notion that End-to-End Verifiability (E2EV) offers a "magic bullet" solution for the inherent security challenges of online voting. Odum, drawing from his extensive experience and a background as a certified ethical hacker, dissects the arguments put forth by proponents of internet voting, particularly those championed by venture capitalists and technology vendors. He argues emphatically that while E2EV is a valuable paradigm in controlled environments, its application to governmental elections conducted over the internet introduces insurmountable risks that undermine the very foundations of electoral integrity and public trust.

Watch on YouTube

Visual summary for Is E2E Verifiability a Magic Bullet for Online Voting by John Odum
Visual summary for Is E2E Verifiability a Magic Bullet for Online Voting by John Odum

Key moments

  1. 0:00 E2E Verifiability: The 'magic bullet' being sold to policymakers
  2. 2:00 Communicating internet voting risks to non-technical policymakers
  3. 4:00 Internet voting for specific groups creates a 'slippery slope'
  4. 5:00 Defining End-to-End Verifiability (E2EV) for elections
  5. 6:30 Expert consensus: E2EV is not suitable for government elections
  6. 7:30 Scientific consensus: No known technology makes internet voting secure

Is E2E Verifiability a Magic Bullet for Online Voting

Speakers: John Odum, Certified Ethical Hacker, Election Administrator, Former Vermont Secretary of State Candidate

Conference: Voting Village

YouTube: https://www.youtube.com/watch?v=gMvNKsl65NA

Overview

In this compelling talk, John Odum, a seasoned election administrator and former candidate for Vermont Secretary of State, critically examines the increasingly popular notion that End-to-End Verifiability (E2EV) offers a "magic bullet" solution for the inherent security challenges of online voting. Odum, drawing from his extensive experience and a background as a certified ethical hacker, dissects the arguments put forth by proponents of internet voting, particularly those championed by venture capitalists and technology vendors. He argues emphatically that while E2EV is a valuable paradigm in controlled environments, its application to governmental elections conducted over the internet introduces insurmountable risks that undermine the very foundations of electoral integrity and public trust.

Odum's presentation is uniquely framed as a guide for communicating complex cybersecurity issues to policymakers, who are often swayed by vendor promises and simplified technical assurances. He highlights the critical disconnect between the theoretical security offered by cryptographic solutions and the practical vulnerabilities introduced by client-side devices, social engineering, and the broader internet ecosystem. The talk serves as a stark warning against minimizing the real concerns of accessibility and convenience for certain voter groups, while simultaneously advocating for policy-based solutions that do not compromise the fundamental security and auditability of elections.

The core message is a resounding "no" to the titular question, emphasizing that no known technology, including E2EV, can render internet voting secure enough for high-stakes governmental elections. Odum systematically dismantles common arguments for internet voting, such as comparisons to banking apps, by exposing their critical flaws and highlighting the devastating potential for widespread vote manipulation or suppression through sophisticated cyberattacks. His analysis underscores the urgent need for policymakers to resist the allure of technological "magic bullets" and instead prioritize robust, auditable systems that safeguard the democratic process.

Background

▶ Watch: E2E Verifiability: The 'magic bullet' being sold to policymakers (0:00)

The push for internet voting is often driven by a genuine desire to enhance accessibility for specific voter populations. As Odum notes, these include disabled voters who face difficulties getting to polling places, voters experiencing natural disasters (like the recent flooding in Vermont), first responders deployed during elections, and Uniformed and Overseas Citizens Absentee Voters (UAVA). While these concerns are legitimate and should not be minimized, Odum warns against the "slippery slope" argument: if internet voting is permitted for these groups, it inevitably leads to its expansion to the general electorate, with the implicit suggestion that these groups' votes are less deserving of security. This creates a civil rights issue if the implemented system is vulnerable.

At the heart of many internet voting proposals is End-to-End Verifiability (E2EV). Odum defines E2EV not as a specific cryptographic style, but as a paradigm characterized by two core properties:

  1. Voters can confirm that their selections have been accurately recorded.
  2. Anyone (voters and observers) can confirm that the recorded votes have been accurately tallied.

While acknowledging that "very cool E2EV systems" exist, particularly in closed-loop, non-internet contexts (such as a small municipal election with paper backups), Odum stresses that the consensus among independent technological professionals is overwhelmingly against its use for government elections over the internet. He cites the creator of the Helios system, a "crown jewel" of remote E2E systems, who explicitly stated, "A government election is something that you don't want to do over the internet. I don't have an expectation that Helios ever becomes the system for government elections." Further, Dr. Andrew Apple is quoted as stating, "According to clear scientific consensus, no known technology can make internet voting secure."

A key figure pushing internet voting is Bradley Tusk, a venture capitalist involved with companies like Votes and Democracy Live. Tusk, through his Mobile Voting Project, commissioned the Berkeley Center for Security and Politics to develop best practices for internet voting. However, the resulting paper, authored by approximately 40 experts including cryptographers, security professionals, and election administrators, delivered a "big disappointment" to Tusk, concluding that "when internet ballot return is employed, it may be possible for a single attacker to alter thousands or even millions of votes." Despite this, Tusk continues to promote internet voting, often comparing its security to online banking, a comparison Odum vehemently refutes due to fundamental differences like anonymity and the significantly higher stakes of electoral integrity.

Key Findings

▶ Watch: Internet voting for specific groups creates a 'slippery slope' (4:00)

The central finding of John Odum's talk is that End-to-End Verifiability (E2EV) is unequivocally not a magic bullet for online voting in governmental elections. While E2EV offers theoretical advantages in verifying vote recording and tallying, these benefits are critically undermined by the broader insecure environment of the internet and client-side devices. The expert consensus, even from the creators of E2EV systems, is firmly against implementing internet voting for high-stakes elections due to insurmountable security challenges.

Odum identifies client-side malware and social engineering attacks as the paramount threat to any internet voting system. He demonstrates how sophisticated smishing campaigns, counterfeit apps, and misdirection tactics can effectively disenfranchise voters or manipulate votes long before any cryptographic handshake even occurs. This means that even if the "train tracks" (the cryptographic transit system) are perfectly secure, the "towns" (voter devices and personal environments) are highly vulnerable, rendering the entire system compromised.

Furthermore, the talk exposes the false equivalency between online banking and internet voting. Unlike banking, elections demand anonymity, and the consequences of fraud or system failure are far more severe, impacting democratic legitimacy. Odum highlights the fragility of voter confidence and public trust as a critical vulnerability, arguing that even a single publicized incident of compromise or system failure could have devastating, long-lasting effects on citizens' faith in the electoral process. The difficulty of auditing advanced cryptographic systems, compared to traditional paper ballots, further erodes this trust.

Finally, Odum stresses that minimizing the legitimate needs of accessible voting groups is a tactical error. Instead, the focus should be on developing robust policy-based solutions for these groups that do not introduce systemic risks to the entire electoral system. The ultimate takeaway is a powerful call for policymakers to prioritize the fundamental security and integrity of elections over perceived convenience or technological novelty, acknowledging that certain risks are simply too high for a democratic society to bear.

Technical Deep Dive

▶ Watch: Defining End-to-End Verifiability (E2EV) for elections (5:00)

While End-to-End Verifiability (E2EV) is designed to ensure that voters can confirm their selections are accurately recorded and that all recorded votes are accurately tallied, Odum argues its efficacy is limited to closed-loop, non-internet systems. In such environments, with physical paper backups and a controlled infrastructure, E2EV can be a "very cool" paradigm. However, the moment an election system is exposed to the internet, the attack surface expands exponentially, rendering E2EV's core protections insufficient.

The primary technical vulnerability highlighted by Odum is client-side malware, which he considers "far and away... the biggest threat" to internet voting. This malware operates on a voter's personal device (phone, tablet, computer) and can subvert the voting process long before the E2EV cryptographic handshake ever occurs. The analogy used is that while the "train tracks" (the cryptographic transit system) might be secure, the "towns" (the endpoints where voters interact with the system) are highly vulnerable. Examples of client-side attacks include:

  • Counterfeit apps: Malicious applications designed to mimic legitimate voting apps, capturing or altering votes before they are securely transmitted.
  • Smishing (SMS phishing): Targeted text messages (e.g., "Hey, we're voting electronically, but the system has been changed. Click here to go and verify that you can vote.") redirecting voters to fake voting portals or malware download sites. This can lead to identity theft or simply prevent a legitimate vote from being cast.
  • Misdirection and social engineering: Manipulating voters through various online channels to compromise their devices or trick them into voting incorrectly or not at all.

Odum provides compelling statistics to illustrate the potential impact of smishing campaigns. Based on an analysis of New Hampshire's 1.2 million registered voters, a commercial vendor could provide 129,000 mobile numbers. Assuming 70% are registered voters, this yields approximately 90,163 reachable voters for a smishing campaign. With a conservative high-end click-through rate of 14.5%, attackers could deceive 1.14% of the electorate. Comparing this to the 2016 US Senate vote in New Hampshire, which was decided by a mere 0.14%, demonstrates that even a relatively small-scale smishing attack could decisively alter election outcomes without directly changing a single vote, simply by suppressing or misdirecting voters. Furthermore, Odum points out that demographic information available for purchase can enable targeted smishing campaigns against traditionally marginalized communities, transforming a technological vulnerability into a significant civil rights issue.

Another significant technical concern is Distributed Denial of Service (DDoS) attacks. Vendors often dismiss this threat, claiming their systems are too robust or utilize advanced load balancing. However, Odum counters that DDoS attacks are a persistent and evolving threat. He cites the Amazon mega-DDoS attack in 2019 as evidence that even the most sophisticated cloud infrastructures are not immune. The availability of botnets for hire on the dark web (known as "stressers") makes launching such attacks accessible. Past incidents where DDoS attacks have successfully taken down election websites further underscore this danger. While not directly manipulating votes, a DDoS attack can prevent eligible voters from casting their ballots, leading to disenfranchisement and eroding trust.

Odum also briefly touches upon Election Management System (EMS) hacks, acknowledging that while these are a concern even for traditional systems, they add another layer of vulnerability when coupled with internet voting. He mentions vulnerabilities found in various implemented systems, including those in Estonia, Australia (experimental), and West Virginia. However, he emphasizes that the social engineering vector (smishing/phishing) is more readily understood by policymakers and thus a more effective point of engagement.

A critical comparison frequently made by internet voting proponents is with online banking apps. Odum thoroughly debunks this analogy:

  • Anonymity: Banking apps are inherently non-anonymous, linking transactions directly to identified individuals and accounts. Elections, especially in democratic systems, often require voter anonymity to protect against coercion.
  • Security Incidents: Despite robust security, banking apps are not infallible. Odum cites statistics that 29% of US adults have experienced some form of account takeover attack, with 42% of those being banking accounts, equating to approximately 8.5 million incidents. The stakes for losing money, while significant, are fundamentally different from losing faith in the integrity of an election. The recovery mechanisms for banking fraud are also far more robust and centralized than what could be implemented for a compromised election.

Finally, Odum highlights the immense challenge of auditability in advanced cryptographic systems. Unlike traditional paper ballots, which can be manually recounted by "a couple people sitting down at a table," auditing complex cryptographic proofs is "impossible for the average person or even the average advocacy group to have any real faith in." This lack of transparent, easily verifiable auditability directly impacts voter trust and confidence, which Odum argues is "probably the hugest thing." The inability to conduct straightforward recounts, as seen in his own experience with a four-vote margin election, means that a compromised internet election would likely necessitate an entire "revote," an entirely different and problematic scenario compared to fixing a paper-based error.

Demo / Proof of Concept

▶ Watch: Expert consensus: E2EV is not suitable for government elections (6:30)

The talk by John Odum focuses on a critical analysis of the theoretical and practical vulnerabilities of internet voting systems, particularly in the context of communicating these risks to policymakers. While he employs compelling analogies and statistical data to illustrate potential attack vectors and their impact, the presentation does not include a live demonstration or a proof-of-concept of an exploit against an internet voting system. Instead, Odum's approach relies on expert consensus, real-world examples of cyber threats (like the Amazon DDoS attack), and hypothetical scenarios of social engineering campaigns to convey the dangers.

Defensive Implications

▶ Watch: Scientific consensus: No known technology makes internet voting secure (7:30)

The primary defensive implication from John Odum's talk is a strong recommendation for policymakers and election administrators to reject internet voting for high-stakes governmental elections. This is not to say that the underlying needs for accessibility are invalid, but rather that the "cure" of internet voting is far worse than the "disease" of current accessibility challenges. Instead, defensive strategies should focus on:

  1. Prioritizing Policy Solutions for Accessibility: Do not minimize the legitimate concerns of disabled, overseas, or disaster-affected voters. Instead of resorting to internet voting, invest in robust policy solutions that enhance traditional voting methods, such as extended vote-by-mail options, secure in-person absentee voting, or localized, secure electronic ballot delivery without internet return. The goal is to "make it policies that make it easier to vote," potentially allowing ballots to come in late if needed, rather than introducing systemic vulnerabilities.
  1. Educating Policymakers on Social Engineering: Defenders must effectively communicate the dangers of client-side malware and social engineering (especially smishing) to non-technical audiences. The "trains and towns" analogy is a powerful tool to explain that even cryptographically secure transit systems are useless if the endpoints (voter devices) are compromised. Policymakers, who are often trained on phishing awareness, can grasp these concepts more readily than complex cryptographic arguments.
  1. Maintaining and Enhancing Paper-Based Auditability: The ability to conduct simple, transparent recounts of physical paper ballots is crucial for voter confidence. Policymakers should resist systems that replace or complicate this fundamental audit trail with advanced cryptography that is inaccessible for public verification. If an election is "screwed up," the goal should be to "fix it" through auditable means, not force a problematic "revote."
  1. Challenging Vendor Claims and False Equivalencies: Election officials and advocates must be prepared to counter misleading arguments, particularly the comparison of internet voting to online banking. Emphasize the fundamental differences in anonymity requirements and the catastrophic stakes of electoral compromise versus financial fraud. Allow proponents to bring up the banking analogy, as Odum suggests, as it provides an opportunity to highlight its flaws.
  1. Protecting Voter Confidence and Public Trust: Recognize that voter confidence is "fragile" and easily eroded. Any decision to implement internet voting must weigh the potential for a single high-profile incident to shatter public trust in the entire electoral process. Defensive measures should prioritize systems that are not only secure but perceived as secure and transparent by the public.
  1. Avoiding the "Slippery Slope": Resisting the initial implementation of internet voting for even small, targeted groups is critical. The argument that "sauce for the goose is sauce for the gander" will inevitably lead to broader deployment, exposing more voters to risk and creating a civil rights issue if the system proves insecure.

In essence, the defensive strategy is to advocate for prudence, transparency, and proven security measures, prioritizing the integrity of the democratic process over the allure of unproven or inherently risky technological solutions.

Key Takeaways

  • E2E Verifiability is Not a Magic Bullet for Internet Voting: While E2EV is a valid cryptographic paradigm, its application to governmental elections over the internet introduces insurmountable security risks that cannot be mitigated by the technology itself.
  • Client-Side Malware and Social Engineering are the Primary Threats: The greatest danger comes from compromised voter devices and sophisticated smishing campaigns, which can manipulate or suppress votes long before any E2EV protections are engaged.
  • Expert Consensus Opposes Internet Voting: Leading cryptographers, security experts, and even the creators of E2EV systems like Helios strongly advise against using internet voting for governmental elections due to the high stakes and inherent vulnerabilities.
  • Banking App Comparison is Misleading: Online banking is not analogous to internet voting; elections require anonymity, and the consequences of compromise are far more severe and impactful on democratic legitimacy. Banking systems also face significant account takeover rates (29% of US adults).
  • Voter Confidence and Auditability are Paramount: The complexity of auditing advanced cryptographic systems undermines public trust. Easily verifiable paper trails and transparent recount processes are crucial for maintaining faith in election outcomes.
  • Policy Solutions, Not Technology, for Accessibility: Legitimate concerns for disabled, overseas, and other vulnerable voters should be addressed through robust policy changes that enhance traditional voting methods, rather than by adopting insecure internet voting systems.

About the Speaker(s)

John Odum is an experienced and highly qualified professional in election administration and cybersecurity. He holds a certification from the International Institute of Municipal Clerks and a certificate in election administration from the University of Minnesota Humphrey School of Public Affairs. Furthermore, Odum is a Certified Ethical Hacker, a credential he humorously acknowledges gives him "a lot of mileage to talk to the rubes with," emphasizing his practical understanding of cybersecurity threats, even if he doesn't consider himself a deep "crypto guy."

Beyond his administrative roles, Odum is a politically engaged advocate for election security. As a 2022 candidate for Vermont Secretary of State, he championed crucial issues such as election cybersecurity, rank-choice voting, and universal vote-by-mail. His unique blend of hands-on election management experience, a technical security background, and a political perspective allows him to dissect complex issues like internet voting with a practical understanding of both their technical feasibility and their policy implications, particularly when communicating with elected officials. He is vocal in his opposition to internet voting for governmental elections, having successfully helped to delay such implementations in Vermont, and remains a strong proponent of secure, auditable electoral processes.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent policy-lane talk that makes a clear, defensible argument against internet voting using accessible analogies and real statistics. The smishing math is the sharpest moment — quantifying how a 14.5% click-through rate dwarfs a 0.14% election margin is the kind of concrete framing policymakers actually need. Nothing here will surprise anyone who's read the NASEM report or followed the Helios debates, but Odum knows his audience and stays in his lane.

Heather Calloway (CISO) — SOLID

Odum knows this territory and the core argument is correct — E2EV doesn't solve the endpoint problem, and the expert consensus against internet voting for governmental elections is real and well-grounded. But this is a policy advocacy talk aimed at helping administrators push back against vendors and legislators, not a talk that advances the understanding of security leaders or changes how a security program operates.

→ Top-rated talks at Voting Village @ DEF CON 33

All talks from Voting Village @ DEF CON 33