Voting Machine Cybersecurity: What Voters Should Know

Modern voting equipment sits at an odd intersection: it has to be simple enough for a nervous first-time voter to use without instructions, and secure enough to withstand scrutiny from security researchers actively looking for weaknesses. That’s a genuinely hard design problem, and it’s worth understanding a little about how the systems actually work before drawing conclusions about how safe — or unsafe — they are.

The first thing worth knowing is that the vast majority of voting machines in use today are not connected to the internet while polls are open. That single fact surprises a lot of people, since we’re used to thinking of “hacking” as something that happens remotely, over a network connection. Election officials generally treat air-gapping — physically isolating voting equipment from any outside network — as a baseline requirement precisely because it closes off the most common attack vector used against ordinary computers.

That doesn’t mean the machines are risk-free. Security researchers have identified vulnerabilities in various voting systems over the years, usually through controlled testing environments rather than real-world attacks. Finding a flaw in a lab, however, is a different thing from that flaw being exploitable during an actual election, given the physical security, chain-of-custody procedures, and pre- and post-election testing that surround the equipment in practice. We’d argue this is a point that gets lost in a lot of public conversation: a theoretical vulnerability and a practical, exploitable attack path are not the same thing, and treating them as identical tends to generate more fear than clarity.

This is also where the physical safeguards we’ve discussed elsewhere — sealed transport, logged custody, bipartisan witnesses — do a lot of quiet, unglamorous work. A machine that’s been properly secured and monitored the entire time it’s in use is a much harder target than the same machine sitting unattended. Cybersecurity and physical security aren’t separate conversations; for voting equipment, they’re really the same conversation viewed from two angles.

Independent testing matters too. Most jurisdictions require voting systems to be certified against federal or state security standards before they’re ever deployed, and many states also conduct their own pre-election logic and accuracy testing on every machine that will be used. None of this is a guarantee against every possible failure mode, but it does mean the systems aren’t simply taken on faith — they go through a testing pipeline before a single vote is cast.

We think the most useful posture for voters isn’t blind trust or blanket suspicion, but informed skepticism: understanding that these systems are tested, monitored, and — critically — backed up by paper records that let officials verify results independently of the software itself. That combination of layered defenses is a far more realistic picture of voting machine security than either the “totally safe” or “totally rigged” narratives that tend to dominate the loudest parts of the conversation.