Security Vulnerability in a Voting System
CybersecurityPolitical SciencePublic Policy
THE AI ANGLE
Automating an exploit from a research paper to recover ballot order from public datasetsUsing an AI coding agent and a four-year-old vulnerability paper, an analyst recovered the order of ballots cast in Georgia's May 2026 primary without accessing voting machines, code, or non-public systems. The exploit relied solely on public early-voting lists and cast-vote records (CVRs), which are published to ensure election results remain independently verifiable. This demonstrates how accessible AI tools can rapidly turn theoretical, unpatched election vulnerabilities into functional threats against ballot secrecy.
THE TEACHING ANGLE
The tension between election transparency—releasing granular cast-vote records for public verification—and the preservation of secret ballots when data can be combined to re-identify voter choices.Read the original at schneier.com Generate teaching or study materials
More in Cybersecurity
- Europe must build own AI or risk getting cut off by US or China, says ECB’s LagardeThe Guardian — AI · September 15, 2026
- Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedentThe Register · September 15, 2026
- AI, Redistribution, and the Size of the PieMarginal Revolution · September 15, 2026
- RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructureTechRadar · September 15, 2026
- Using AI for Weapons DevelopmentSchneier on Security · September 15, 2026