View as Webpage

FOR IMMEDIATE RELEASE

November 15, 2023


Contact: Marilyn Marks

Coalition for Good Governance

Marilyn@uscgg.org

704 292 9802


Federal Court Order Details Secretary of State Raffensperger’s Lax Responses to Coffee County Voting Software Breaches and Failures to Address Security Lapses


Judge denies Georgia’s Secretary of State’s Motion for Summary Judgment in the Curling v. Raffensperger lawsuit, while highlighting State's repeated failures to secure Georgia’s voting systems.


Citing the Secretary’s conflicting statements, the order also raises questions about the Secretary’s response to Coffee County voting system breach; what the Secretary knew and when he knew it.  



ATLANTA- --In a condemning 135 page order issued Friday, US federal Judge Amy Totenberg of the Northern District of Georgia denied the Georgia Secretary of State’s Motion for Summary Judgment on central claims against Georgia’s use of computerized Ballot Marking Devices (BMDs) for all in-person voters in the long-standing lawsuit, Curling v. Raffensperger. The order also granted Fulton County’s motion to be dismissed from the suit, concluding that the decision to use the BMDs for all in person voters rests with the state not the county; and dismissed certain other claims. A trial is set for January 9, 2024. 


The Court’s order invests a considerable amount of space to provide scathing evidence of the repeated failures by the Secretary of State to address known security issues in Georgia’s election system, both with the previous Diebold touchscreen machines and the current Dominion touchscreen BMDs.


Citing frequently from previous orders issued by the Court, the order catalogues details of significant voting system security vulnerabilities that have been ignored or dismissed by the Secretary of State; recounts the 2017 events in which Georgia’s election system servers were found to be accessible over the internet and then improperly destroyed by the Secretary’s office; offers several instances in which the Court expresses skepticism (or outright distrust) of the State’s claims; highlights the Secretary’s lack of interest to seek or implement cybersecurity guidance from expert consultants (also noting that, where consultants were engaged, they were expressly directed not to report security findings in writing); and devotes an entire section to the Secretary’s lax response to the voting system software breach in Coffee County. 


“The Order summarizes numerous decisions by Secretary Raffensperger and the State Election Board showing a continuing pattern of willfully ignoring serious security concerns, and misleading the public, the press, and the Court as they defend the indefensible computerized BMD voting system,” said Marilyn Marks, Executive Director of Coalition for Good Governance, a plaintiff in the long-running case. “At the upcoming trial, we will update the record with Secretary Raffensperger’s latest misguided efforts to mislead the General Assembly, county officials, and voters as he attempts to conceal the irrefutable design flaws of the unreliable touchscreen system. We will demonstrate the State Election Board’s refusal to adopt election rules that would improve election security, or even secure voters’ rights to cast a secret ballot.” 


Key excerpts from the Court’s Order are detailed below for reference. 


Coalition for Good Governance is a non-profit non-partisan 501(c)(3) organization focused on election security, voter privacy and government transparency. 

# # # 


State’s response to the Coffee County voting system software breaches.

In section IV (B)(4), the Court reviews in detail the Coffee County voting system breach, suggesting skepticism that the Secretary’s office claims it did not become aware of the breach until February 2022, even though its investigators were actively investigating related incidents in Coffee County more than a year before. Page 61. 


·      The Court lists the related incidents: “the Secretary of State’s investigations into Hampton’s December 2020 posting of a YouTube video about manipulation of Dominion software; the State’s investigation into Coffee County’s handling of the 2020 presidential election recount; and the Secretary of State’s communications with the new replacement Coffee County Elections Supervisor about EMS server passwords no longer working and the related discovery of a business card for Doug Logan’s Cyber Ninjas on the base of Misty Hampton’s computer.”


·      The Court remarks that, because of a different ongoing investigation, one of the Secretary of State’s investigators visited the Coffee County election office the same day that Jeffrey Lenberg, (an unindicted co-conspirator to the Coffee County breach), was in present when the investigator entered the office. Page 63. (This encounter never appears in the investigator’s reports and was discovered by CGG’s review of the video surveillance.)


·      The Court order notes that the Secretary of State’s office issued an investigation summary that “does not reference any events of the Coffee County breach that began on January 7, 2021 — or system irregularities that might have been suggested by the evidence collected during the investigations.”(Page 63)


·      The Court found it noteworthy that the election supervisor for Coffee County that took office after the breach, James Barnes, found that he was unable to access the election management server because the password had been changed without any record, and that Doug Logan of Cyber Ninja’s business card was found at the base of the former election supervisor’s computer. Barnes told the Secretary’s office that “part of my concern was that, you know, potentially somebody had done something to that server.”Page 63, 64. 


·      The Court recounts that an official from the Secretary’s office told Barnes that the information would be passed on to the investigations unit. The Secretary’s office replaced the server but no other follow up appears to have occurred. Page 65.


·      In February 2022, the State Defendants are provided a recording of a phone call with Scott Hall boasting about the breach, but the Court recounts, 


“Despite this knowledge, the State Defendants continued to deny that there was any cause for concern. For example, in a Discovery Statement that was submitted to the Court on April 6, 2022, the State Defendants represented that, “State Defendants are investigating several issues related to Coffee County but at this time do not believe any of them demonstrate a breach of actual equipment.” (Joint Discovery Statement, Doc. 1360 at 5.) And several weeks later, the Secretary of State’s COO Gabriel Sterling went a step further, claiming at a public forum that the breach “didn’t happen.” (See Carter Center Panel Video, Doc. 1633-17) (“So we are still dealing with that here and we still have to prove negatives in all these cases. It’s similar across the board. But like, we had claims . . . even recently there was people saying: ‘We went to Coffee County. We imaged everything.’ There’s no evidence of any of that. It didn’t happen.”). Page 66 .


·      The Court goes on to point out contradictions in Secretary Raffensperger’s comments regarding the breach, citing statements he made to 11Alive claiming Sterling insisted the breach didn’t occur because the Secretary’s office had been misled, while simultaneously claiming the Secretary’s office had learned about the breach “early on,” and continued to investigate the matter. Page 66. (11 Alive story is available here: Coffee County Georgia election breach timeline questions | 11alive.com)


·      The Court importantly notes that though the Secretary ultimately replaced the election equipment in Coffee County, none of it has been examined for malware. Page 68. 

·      The Court also suggests the State Defendants’ dismissal of the security vulnerabilities found by Halderman and Springall - based on the argument that the experts had unfettered access to voting systems - are persuasively discredited by the Coffee County software breaches. Page 92-93.


Georgia State Defendants’ failure to adequately address election security issues


·      The Court notes that the State had failed to implement critical software patches to defend against a flaw that the State Defendants’ own expert described as “‘one of the most severe security flaws ever discovered in a voting system,’ up to that time.” Page 23. 


·      The Court remarks that the then-election center director at the Secretary’s office has no cybersecurity training. Page 19. 


·      In a footnote, the Court notes that during the 2019 hearing, evidence was presented that outside contractors for the Secretary of State’s election unit used their home computers to create ballot files to be loaded onto computerized voting machines, and that it was unclear what security protocols, if any, these contractors had been following. Page 22. 


·      Though the Secretary of State did engage an outside cybersecurity firm to assess its security posture and recommend mitigations, the Court admonished the Secretary for severely limiting to the scope of the firm’s assessments to exclude the state and county voting systems writing, “the surface of SOS cybersecurity issues was barely scratched.” Page 26. 


·      Nonetheless, the outside firm did identify “an astonishingly grave array of deficits,” but found the Secretary of State failed to mitigate most of them, despite the majority being low or no cost. Page 26. 


·      The Court recited its conclusion from a 2018 order that “the State had ‘stood by for far too long’ in failing to address the ‘mounting tide of evidence of the inadequacy and security risks’” posed by the Diebold touchscreen voting machines (used before the Dominion BMDs). Page 26,27. 


·      The Court commented that further reviews by the Secretary’s outside expert, Fortalice, found that insecure practices persisted. Yet there was no evidence Fortalice’s recommendations were being implemented. Page 48. 


·      The Court also found it noteworthy that the Secretary of State’s office instructed its security expert, Fortalice, to stop provide reports in writing, and to report findings over the phone. Page 48 footnote, 31. 


Georgia State Defendants’ response to the election server vulnerabilities discovered in 2017 


·      Section IV (A)(2)(c) of the order describes in detail the “slow and ineffective” response by the Secretary of State to the 2017 discovery that key elements of Georgia’s voting system was exposed to the internet and “mismanaged.” The discovery, by an outside expert, revealed that outsiders could access critical data because of the use of “grossly outdated” software, and modules known to be susceptible to malware. Page 23. 


·      The Court notes that even though there was a “gaping breach” uncovered, that the Secretary of State insisted “nothing amiss happened,” remarking, “The Court found that this position “contradict[ed] the evidence.”” Page 25.


·      The Court highlights the fact that the Secretary’s election center director was aware of the expert’s warnings and Secretary staff had confirmed these serious software threats, website holes, and data-security exposures months before, without taking any action. Page 23, 24. 



·      The Court also expressed skepticism of the Secretary’s excuses for destroying the impacted servers – a mere four days after the Curling lawsuit was filed- stating “The Court found that this was not credible.” Page 25. 


Court comments regarding the Dominion BMD system at issue


·      The Court makes a point of stating that the QR codes produced by the Dominion BMDs are not encrypted, contradicting assertions made by the Secretary of State in Court and in the public. Page 31. 


·      The Court states that, “a number of critical software updates related to the operation of Dominion’s software and equipment have not been purchased or installed in Georgia as of the date of this Order.” Page 46. 


·      The Court also notes that though DHS’s CISA confirmed vulnerabilities identified by plaintiffs’ experts, Professors Alex Halderman and Drew Springall, and CISA recommend mitigations there is no evidence the State Defendants adopted CISA’s recommendations. Page 47. 


·      The Court underscores that in its 2020 order it concluded that “[t]he substantial risks and long-run threats posed by Georgia’s BMD system, at least as currently configured and implemented, are evident,” and “that Plaintiffs had “shown demonstrable evidence that the manner in which Defendants’ alleged mode of implementation of the BMD voting system, logic and accuracy testing procedures, and audit protocols deprives them or puts them at imminent risk of deprivation of their fundamental right to cast an effective vote (i.e., a vote that is accurately counted).” Page 87, 88. 


·      The Court also reiterated that “that the risks presented by the BMD system as it was then configured “are neither hypothetical nor remote under the current circumstances. Instead, the Court emphasized that “[t]he Plaintiffs’ national cybersecurity experts [had] convincingly present[ed] evidence that this is not a question of ‘might this actually ever happen?’ – but ‘when it will happen,’ especially if further protective measures are not taken.”  Page 90.


·      The Court makes note that the State Defendants have not presented a single cybersecurity expert that endorses the Dominion BMD system as it’s used and configured in Georgia. Page 91.


·      The Court also notes that the state’s expert specializes in “disability access issues” [italics in origin] and that he explicitly stated that he does not disagree with the plaintiffs’ experts’ (Halderman and Springall’s) findings related to security of the BMDs, and that he would defer to Dr. Halderman on issues of cybersecurity. Page 91 footnotes 52 and 54.