Bigger, Badder Election Fraud  

Guest post by Laura Downing 

Many people, but not enough of them to change anything, are concerned about the millions of illegal aliens coming across the southern border of America.  In addition to their receiving immediate SSI benefits, debit cards, phones, housing, and medical care that Americans cannot receive, illegal aliens are registering to vote.  According to The New York Post, “welfare offices and other agencies in 49 US states are providing voter registration forms to migrants without requiring proof of US citizenship.”  Does anyone see a problem?

Representative Chip Roy of Texas sponsored a Bill in the U.S. House known as the SAVE Act, or Safeguard American Voter Eligibility Act.  Contrary to the screaming by the left about voter suppression, the Bill simply requires that anyone registering to vote through the DMV, welfare offices, or other government agencies must provide documentary proof of U.S. Citizenship before receiving the voter registration form.  Sounds reasonable because anyone who wants to do anything in a civilized society must provide valid identification, but cue liberal outrage.  The SAVE Act passed in the House 221-198, with 5 Democrats voting Aye.  Who are the 198 that voted to let illegal aliens register to vote?  What are they thinking? 

Senators Mike Lee and John Kennedy introduced the SAVE Act in the Senate, but the Democrat “elected representatives” defeated it.  President Biden said he would veto the Bill if it was passed.  Just who do the Democrats think they are REPRESENTING?  Surely, they don’t believe they represent American citizens?  In what clown world do NON-CITIZENS get to vote for anything? 

There are groups in our country that are actively targeting illegals to register them to vote.  Who are these people and how could they possibly think that is ok?  Yet, here we are.

The most likely plan with illegal aliens being registered to vote is that these illegally-registered voters do not even need to cast a ballot, but their registrations can be used by bad actors to create fake ballots.  Watch and see.

We have done little to nothing to secure our elections since the mess of 2020 and 2022, and this is just another step in the process of allowing election fraud risk.  So, let’s just sit here and let our country be taken over from the inside because we did NOTHING to prevent NON-CITIZENS from voting in our elections.  Fools, all.

Implications of the Crowdstrike Outage on our Election Infrastructure

On July 19th, Crowdstrike performed a global update to their software.  Performing this kind of an update is generally business as usual and does not cause issues.  For example, many people have probably heard of “Patch Tuesday” when Microsoft issues their weekly patches/updates to Windows computers. 

What was different about this, however, is that this update deployed by Crowdstrike had not been properly tested and resulted in a Windows “blue screen or death”, which means crash.  The company released a fix fairly quickly, but one of the problems was that the original file that caused the issue had to be manually removed, significantly slowing the ability of companies to repair their systems.  Most companies were ultimately able to deploy the fix and get back up and running.

There are ongoing questions about how this could have happened. Many companies, including Crowdstrike, use a process called “DevOps” to deploy their code/updates to live, production servers.  Devops aka DevSecOps brings developers (who write the code), IT operations (who deploy the code) and cybersecurity teams (who secure the code) together to create a collaborative, automated and secure “pipeline” for pushing updates out to live production servers.   Part of this process include quality assurance testing as well, that is designed to ensure code is fully tested so it functions correctly and as designed.  

The issue is, what happened should not have been able to happen.  There are many guardrails that are implemented as part of these processes to ensure that all code is tested before it goes into production.  The fact that an update that caused such obvious and widespread computer crashes could have been deployed indicates either that either there was significant negligence/incompetence or there was something malicious at play.  Crowdstrike has indicated that the issue came from a bug in a validation program that was supposed to test the new code before it was released.  This coupled with other issues in their process (were not doing staggered releases, but routinely released the updates globally, and testing amount and quality were not adequate) created this massive IT outage.  Of course, any company can make a mistake that can cause issues, but this was so obvious it is still hard to believe, in spite of the company indicating it was a number of process mistakes and failures, that there wasn’t malfeasance involved in some way.  A test or “canary” deployment to even 10 machines would have discovered it.  If it is malfeasance, the question of “why?” still remains. 

Who is Crowdstrike?

Crowdstrike is a publicly traded American company, founded in 2011 and has headquarters in Austin, Texas. Crowdstrike is a major player in the cybersecurity industry providing endpoint detection and response (EDR) software products which are deployed on workstations and servers. EDR products are designed to identify and block malicious activity on those endpoints and provide alerts on this activity.  Crowdstrike is the leader in this area and is utilized by most major banks as well as other multi-nationals, in addition to many smaller companies.

George Kurtz, Dmitri Alperovitch and Gregg Marston were co-founders of Crowdstrike.  Many of the founders and some employees originally worked at McAfee, a large anti-virus vendor.   Dmitri Alperovich, born in Moscow, was formerly Chief Technology Officer of Crowdstrike and has strong ties to the intelligence community, with connections to both the Department of Defense and the Department of Homeland Security.   In addition, there are strong ties with the FBI; Crowdstrike hired Shawn Henry who was formerly an executive assistant director there.  Other former FBI officials also work for the company. 

Some other interesting data points and background:

The Center for Information Security (CIS) has an agreement with Crowdstrike to provide endpoint security for all CIS managed endpoints.  

The Albert sensors, that are the intrusion detection system managed by CIS and deployed to the state and counties, run on CIS managed endpoints.  It is a reasonable conclusion that Crowdstrike is running on the machines that are hosting the Albert sensors, because CIS has an agreement with Crowdstrike to provide EDR services. 

EAC conformance/certification documentation indicates that Crowdstrike is not deployed to ES&S voting computers (Tabulators, ballot marking devices, EMS), but there are a number of questions:

  • Do South Carolina and county workstations/servers use Crowdstrike and is data from those computers being sent to the CIS Security Operation Center for analysis and alerting?
  • Epollbooks are not certified as part of the EAC certification process referenced in above, so is Crowdstrike running on the computers that are running the epollbook software or voter registration software?  To wit, during the Crowdstrike outage, Arizona epollbooks and voter registration were taken offline.

Crowdstrike was the company tapped by the DNC and Perkins Coie to investigate a “breach” of the DNC server which they ultimately claimed was “hacked by the Russians.”  This became part of the Russia collusion hoax related to Donald Trump.  Subsequent investigations by non-leftist investigators have called their conclusions into serious question and the Russia collusion narrative has been debunked.  The implications of this are concerning because Crowdstrike was at the center of this targeting of Donald Trump and potentially falsifying forensic reports and data to support this narrative.  What else they would be willing to do is an open question, particularly in this crucial election year. The timing of this mishap is concerning and notable.

    Security Implications of the Crowdstrike Outage for Elections

    This outage has some very serious implications for elections in the United States. 

    1. Availability and Disaster Recovery.  Arizona was in early voting for a July 30th election and this outage took most of their voter registration and epollbook computers offline.  The question to ask is whether or not the South Carolina state and counties have resiliency plans in place in the event this kind of outage were to happen during an election.  If citizens can’t be checked in, or if lines are very long, then it will not be possible for them to vote and they will be disenfranchised.   It is known that Republicans tend to vote on election day – in the 2022 election in Arizona, there were many technical glitches in largely Republican areas that occurred on that day.  Given what just happened, a Crowdstrike like outage could heavily impact election day voting.   
    2. Surveillance and 3rd party dependencies:  Security professionals need visibility into systems and user activities in order to protect their companies.  Crowdstrike software (and others like it) is installed on the workstations and servers to provide this visibility.  It is highly privileged software that is constantly monitoring the endpoints including what is installed on them, and what users/software are doing.  This software has the capability and permission to stop activities that it considers to be malicious.  This means that any company using this software is trusting companies like Crowdstrike to not be malicious and to protect the company information.  There are contracts in place and vendor security assessments are done to ensure the company is protected, but the fact remains that these companies have a great deal of power and visibility into what the company and its employees do.  The potential impact on elections is:
      • If South Carolina election officials are using computers that are running Crowdstrike then they are running software with that immense power and surveillance capabilities.  What data could potentially be sent to the Center for Internet Security’s Security Operations Center?
      • Albert Sensors, mentioned above, run on computers that are protected by Crowdstrike. Albert sensors collect network data and send it to the Center for Internet Security’s Secruity Operation Center, but an endpoint detection and response product will also send information on what is happening on the workstation/server itself – this data will also be going to the CIS Security Operations Center.  It is not supposed to be sending any election related data there, but could this happen
    3. Attack Detection – Albert sensors run on computers that have Crowdstrike installed.  If those computers are taken offline, then that also takes down the intrusion detection capability so any ability to detect an attack is seriously impacted.  This means the election infrastructure would be wide open to an attack and the ability to detect and respond to it significantly diminished.

    Here are some questions to ask of your election officials in your area:

    1. What specific components of the ES&S election system utilize CrowdStrike? Our ES&S system has Windows servers which should utilize CrowdStrike. What about Epoll books which are connected to the internet? What about laptops or central county computers that house Electionware or the computer that reports results to SCYTL/Clarity (ENR) from the Electionware central county computer? Election IT professionals should check for the following: On Windows Operating System Crowdstrike files will be in C:\Windows\System32\drivers\CrowdStrike
    2. What specific data is being sent to the Center for Internet Security’s Security Operations Center and is this a uni-directional or two-way path for data transfer?
    3. Were the computers running the Albert sensors in the state/county environments impacted by the July 19th Crowdstrike outage?  If so, has any forensic investigation been done to validate that there were no cyber-attacks during that time that could impact the state/county networks and potentially the election equipment?
    4. Please provide information on your emergency plan. At a minimum, poll workers should be trained on the use of paper poll books/rosters as a backup or redundant check in methodology.  What would be better is if poll workers could be trained on the use of paper ballots and how to hand count them in the case of an even bigger outage. If there is not a plan in plan our group SC Safe Elections has developed one that would be a great way to mitigate this risk. See https://www.scsafeelections.org/the-gold-standard-for-elections/. We could train poll workers who will find it wasy and efficient.
    5. If Crowdstrike is in the environment, is it set for automatic updatesAre Microsoft updates set to be deployed automatically?  If updates are not being tested by the county or state IT departments before deployment into their environments, then this type of outage could happen again.   

    Computers are infiltrated every day and our election systems do have some connectivity to the internet AND our electronic voting systems can also be penetrated via flash drives, cell phone “man in the middle attacks, wireless, and hidden modems. It is essential that our election officials take cybersecurity seriously. Our current system hasn’t even updated antivirus updates and patches for over 4 ½ years. Our state Legislative and Audit Council stated in their report of January 24 that cybersecurity had not been prioritized nor had funds that were provided by HAVA money been spent to upgrade security. If our SC State Elections board is serious about securing our vote, they need to take action and provide more transparency to our citizens. Not having an emergency backup plan would be a dereliction of duty. Our legislators also need to take this seriously and sound the alarm and partner with citizens to make the necessary changes in our law and our processes and procedures to enhance confidence in our system.

    Special thanks to guest contributor cyber expert Julie Baker for her expertise and assistance with this post.

    An appeal to the RNC

    Laura Downing a forensic auditor and election investigator penned the letter below to the RNC to share her concerns about election integrity in South Carolina and the nation. Here are some of her salient points:

    • All states need to ensure that no ineligible voters especially illegal immigrants are registered to vote. How can we be assured that our rolls are clean?
    • Transparency must be increased by providing key data and reports to citizens and inexpensive voter rolls as well as the ability for poll observers to have full access to all stages of the eleciton process. For example, currently observers aren’t even allowed to view the ballots during the hand-count audits so how can they confirm that the count is correct if it is not done publically like our constituion calls for.
    • Third party vendors should be eliminated where possible as they aren’t subject to citizen FOIA (Freedom of Information Act) requests.
    • Ideally electronic voting should be replaced with handmarked, handcounted paper ballots.

    Read the full letter below:

    Why election transparency is important

    Why can’t our state allow access to records to help enhance confidence?

    According to Rasmussen, approximately 66% of likely voters don’t trust our electronic voting systems.  Could this be the reason for our state’s abysmal turnout in the primary of roughly 13%?

    This should concern every election official and legislator. Instead, they excoriate those who question the elections and who request information to confirm the validity of the election process. To wit, our own SC Election Commission is still trying to sue SC Safe Elections, our grassroots group, for daring to ask for information about the 2020 election (namely Cast Vote Records). They won’t give up on their counterclaim that basically wants to prevent us from obtaining, via the South Carolina Freedom of Information Act, ANY information from the 2020 election as well as pay thousands of dollars of their legal costs. This is harassment in the form of overzealous lawyers spending our tax dollars to punish citizens for requesting records that help us validate our elections. We certainly hope that Judge Coble sees this for what it is and either dismisses (again) their counterclaim; or better yet, awards us our legal fees and admonishes the otehr side for their brute force tactics.

    Dr. Daugherity, one of our expert witnesses, wrote an excellent article, “Balancing Ballot Secrecy Versus Transparency”, that succinctly underscores the importance of Cast Vote Records.  In this must-read article, he provides the history of the secret ballot and emphasizes the importance of voter transparency. It is essential that states not only comply with our federal and state laws but that they also provide access to these records to ensure increased confidence in our election results.

    He states:

    “Every CPA or financial officer knows what is necessary for a complete and verifiable audit—physical security, inventory, chain of custody, separation of duties, a complete audit trail, and so on. In everyday language, there must be sufficient data to reconstruct and trace all transactions, in effect to be able to make a “movie” after the fact of everything that happened before, during, and after an election.”

    When our election officials ask us to trust the system but don’t provide key reports and records it only foments distrust and suspicion. See the article below:

    Things are getting hot in Pennsylvania

    Several lawsuits are heating up and new ones being filed that underscore multiple issues in the Pennsylvania 2020 election. In particular, we are finding out that the state didn’t properly investigate compelling evidence of fraud.

    In this must-see interview (start around 23 minutes) Greg Strenstrom and Leah Hoopes discuss their multiple suits and the shocking evidence that demonstrates how Bill Barr told the PA officials to stand down and not look into the 2020 election anomalies and evidence of potential fraud.

    A new suit was filed by United Sovereign Americans, Inc., a nonpartisan, all-volunteer election validity advocate group, and two Pennsylvania residents directed to the Secretary of the Commonwealth, the Bureau of Elections, the Bureau of Election Security and Technology, the Department of State, and the state Attorney General. They have also named Attorney General Merrick Garland and the United States Department of Justice as additional “Respondents.”

    They claim that federal voting standards are not being followed.

    Click here for the article

    Note that it appears we now have several states whose outcome of the 2020 election is indeterminate at best due to the evidence–GA, Wisconsin, and PA!

    Why are we using machines if they are neither secure nor verifiable?

    Auditing is the key to verifiability of the machine vote, but can we even trust an electronic system?

    Auditing is a key component of the election process and thus needs to be robust, observable, and trustworthy. Unfortunately, our state procedures don’t inspire confidence.  As stated in many prior articles, South Carolina citizens aren’t able to gain access to ANY meaningful reports such as cast vote records and security logs. Hand count audits are often done with small samples that aren’t statistically representative of an entire race and aren’t random, nor is the process viewable by observers. This does not align with the spirit of our law.

    How can someone observe the process and feel confident about the results when they aren’t allowed to view the ballot content or reports derived from them? The secrecy of the ballot is meant to be during the process of casting a vote. Once cast, the ballot, which has no personally identifiable information, should be able to be viewed in its entirety. The only way to audit our elections is to do a full hand-count of all races. We can do this in an efficient manner using our hand count method as outlined in our gold standard elections whitepaper pages 14-20. https://www.scsafeelections.org/the-gold-standard-for-elections/

    Better yet, why are we even using the machines? If we utilize a full handcount to audit to check the accuracy of the machine tabulation than why not just return to hand-counting hand-marked paper ballots?

    Here is a truth-telling video that “red pills” the masses from Scott Adams. He makes a great point!

    How secure are these machines?

    CISA, the Center for Infrastructure and Security Agency, has been hacked. Multiple government agencies have been hacked and recently the Federal Reserve was hacked. If this can happen, we can’t fully trust that the most important currency we have (which is our vote) to an insecure system. From the article,

    Josh Jacobson, Director of Professional Services at HackerOne says the threats made by LockBit speak to the fact that “even our most integral governmental entities are not infallible to ransomware attacks.”

    “If the Federal Reserve is impacted, that could have global implications. This is not a siloed infrastructure where a finite number of customers are impacted. The potential for residual impact definitely factors in, as well as long-term reputation and trust,” he said.

    Wake up America, are your elections clean or are your leaders selected for you? Who owns these system manufacturers? Who is in charge of monitoring them? The people need to take back their elections. We have developed a gold standard method for doing so. Let’s join other Euorpean nations who have returned to one day of voting on paper ballots which are hand-counted.

    How to ensure only legitimate voters vote

    Here the Gold Standard team discusses the second phase of the election process or voter validation. Why is it important? We discuss several disturbing examples where Epoll book numbers jump, voters are erased in the middle of early voting, dead people voting, and many more.

    We also discuss why it is near impossible to delete illegals as well as people who have passed away, moved. What happens when the machines go down? When should provisional votes be used? Why don’t the states allocate more funding to ensure there are no illegals registered?

    3:00-12:15 Poll Book reconciliation with paper voter rosters
    14:55-15:43 Poll book numbers jumping in Dallas County
    13:41- 14:54 Obstruction of citizens receiving records
    16:00- 17:04 Problems with poll books
    17:09-19:36 Lost or incorrect votes/duplicate voters in two states
    19:37-21:12 Names erased from the early voting database
    22:55-24:10 Was it a hack?
    24:20- 25:30 Are names removed or re-classified?
    25:34- 27:00 Mail forwarding to avoid taxes
    28:08-30:44 Election misinformation/gaslighting
    31:01-33:33 Ohio cleans up non-citizen voters? Not so fast
    36:13-37:21 How can they detect non-citizens voting?
    45:00 Solutions and fascinating stories

    Here is the GP article on the poll pads jumping in number in Dallas

    Here is the Gold Standard Elections website which contains the whitepaper that the team wrote on how to optimize the election process:

    Goldstandardelections.com

    Frankspeech interview- how to get transparent elections and re-engineer the entire process

    In this interview with our colleague from South Dakota, Rick Weible, Laura discusses the importance of Cast Vote Records and why they are required by law to ensure an auditable trail. More importantly, they discuss the absolute GOLD STANDARD for elections which is one day of voting on hand-marked, hand-counted paper ballots, why we can no longer trust the current electronic voting system, and what you can at least do now to help mitigate the issues involved in electronic voting.

    A must-see interview chocked full on information.

    Election interference at the local level: Part 3

    Laura sits down with Lisa Bracewell and Patti Black from the Greenville area who experienced election issues with the Blue Ridge Rural Water Board election October 10, 23.

    The machine broke and the ballots were counted in secret behind closed doors. This is a violation of the SC constitution Article II section 1.

    They requested information about the election under the Freedom of Information Act and were denied. In order for trust in elections to be restored we need transparency as well as respect for the FOIA laws in South Carolina. There are far more states in our country who do a better job. This is a disgrace and needs to be taken care of.

    Here is a copy of the summons that was filed for the case:

    Persuasive evidence proves South Carolina citizens should have access to Cast Vote Records (CVRs) but judge punts

    The Epoch Times recently had an article on how the FOIA law is broken. We couldn’t agree more. They primarily look at examples and cases related to national issues. This broken system is being experienced at the local level. In August of 2022, the South Carolina Safe Elections group and Michael Funderburk (plaintiffs) filed a lawsuit against the SC Election Commission (SEC) and 8 county Boards of Elections in SC (Aiken, Beaufort, Charleston, Dorchester, Greenville, Lexington, Spartanburg, and York), as well as a Temporary Restraining Order (which was granted) to preserve all 2020 election data. 

    The defendants had denied Freedom of Information Act (FOIA) requests for an important audit report, the Cast Vote Record (CVR). Prior to September 2020, our election offices provided these reports, and they were even used for analysis in national whitepapers.  But in August of 2020, just prior to the 2020 election, the then executive director of our state election commission, Marci Andino, decided that, because the new machines produce ballot images, these reports should not be provided. Not to mention the fact that she changed the definition of a cast vote record in her request to include not only the actual CVR report but also the ballot image and the physical ballot. She asked Alan Wilson’s SC Attorney General’s (AG’s) office to provide an “opinion letter” responding to the facts she presented.

    The AG’s office issued a letter agreeing with her, as they could only make their determination based on the facts provided by her. This was despite the fact that 28 other states and the District of Columbia provide Cast Vote Records to their citizens. Some counties even provide them online so that they can be conveniently downloaded for review and analysis.  Curiously, she also decided at that time to ask the AG’s office for guidance on preventing citizens from accessing security reports, and the AG’s office complied with that request. Reminder– many states allow public access to all of the aforementioned reports!

    Why the sudden change and why just prior to the 2020 election? Also, why would the supposedly conservative state of South Carolina withhold valuable information from citizens who desire clarity and transparency in their elections?

    UPDATE: The judge dismissed the case after a year and a half of “lawfare” and after it was designated “complicated.” Our ability to present the facts has been denied.  Note that our state FOIA law, set out in Title 30, is clear that FOIA lawsuits are intended to be heard and concluded within 6 months. This is a travesty of justice and a total lack of respect for our state’s Freedom of Information Act.

    This delay cost regular citizens copious legal fees (around $90K) and frustration (note that the defendants also countersued us for a FOIA request), as well as the inability to properly analyze not only the 2020 election data but also the 2022 midterm data. This should never happen. In a free society, transparency is the government’s obligation to share information with citizens. It is at the heart of how citizens hold their public officials accountable. If our government tries to withhold information from citizens, how can we trust it?

    Now, into the specifics of the case and our arguments. First, what is a CVR or cast vote record? From NIST (National Institute of Standards and Technology) manual, Nov 2019 Publication 1500-103 Cast Vote Records Common Data Format specification Version 1.0:

    A CVR is an electronic record of a voter’s selections, with one CVR usually created per sheet (page) of a ballot (a markedly different definition from Andino’s). Election results are produced by tabulating the CVRs, and audits can be conducted by comparing the paper ballots or paper records of voter selections against the CVRs. 

    Here is an example of a CVR from Arkansas:

    The NIST manual even states that these were meant for election officials and the public alike. Federal standards developed by NIST were done at the direction of the Federal Election Assistance Commission (EAC).

    There are many complex operations performed by voting devices when voters submit their paper ballots to be scanned. These operations are mostly invisible to voters but are necessary to determine whether contest selections have been marked adequately and whether voter intent is reflected by what is marked on the ballot. This specification includes the necessary detail to capture these operations so that CVRs can be better audited and adjudicated as necessary to include write-in candidates or other issues. This specification is geared towards the following audiences:

    • Election officials • Voting equipment manufacturers • Election analysts and auditors • Election-affiliated organizations • The public

    CVRs are an itemized receipt for our vote. Cast Vote records have been around since the mid-2000s yet the counties and the election commission claim to have no knowledge of these reports. The whole point of obtaining machines with physical ballots, ballot images, and a CVR database audit trail is to instill more public confidence in the process. If we can’t view the images or a record of how the vote was tallied for that election, how can we feel confident about our election results from our electronic voting system? Yes, we can review our ballot post-vote, but the tabulator isn’t reading our selections; it is scanning a barcode at the top of the ballot. How can we ensure that the barcode is not corrupted or that our vote changes once it is input into the machine?

    Currently, we only receive the final vote count post-election, but we don’t receive the details of the vote. How was it counted over time? Were there any duplicate ballots? Was the adjudication done accurately? Due to the black-box nature of our tabulators and the fact that we only receive the final vote counts, we are currently counting our ballots in secret. This violates our state constitution.

    The South Carolina Constitution states in Article II, Section 1:

    “All elections by the people shall be by secret ballot, but the ballots shall not be counted in secret. The right of suffrage, as regulated in this Constitution, shall be protected by laws regulating elections and prohibiting, under adequate penalties, all undue influence from power, bribery, tumult, or improper conduct.”

    Secrecy of the ballot refers to the casting of the ballot. Once cast, the ballots should be counted or publicly viewed. Andino’s memo to the AG’s office in August of 2020, which asks for their opinion, states that the ballots are “cast” when inserted into the tabulators. Marci Andino, herself, in old poll worker manuals, states that the counting should be public per the federal and state constitutions. How can we count the ballots if the machine tabulates in secret and we only receive the final result? Her memo states that Title 7 references the public’s right to observe processes associated with ballot counting, but then leaps to the conclusion that this suggests the legislature did not intend for voted ballots to be subject to public disclosure! This is counter to exactly what has been stated in our poll managers’ handbooks for years. Also, our federal and state regulations and laws mandate that no identifying information appear on the ballots themselves. Ken Paxton, Texas Attorney General, and former Arizona Secretary of State Ken Bennett are on record as saying these records and images should be available to the public.  Most of these states have ES&S systems like ours, so why does South Carolina view this issue differently? In addition, our federal and state laws require a voting system with audit capabilities. Dr. Daugherity, another one of our experts, cites this law in his affidavit.

    The statewide voting system currently used in the State has the necessary audit
    capacity,” namely, that “The voting system shall produce a record with an audit capacity
    for such system.” The CVR report is such a record.

    The voting system shall produce a permanent paper record with a manual audit
    capacity for such system” and “The statewide voting system currently used in the State
    produces an image of each vote cast; however, these votes cannot be associated with
    any particular voter.” Thus, disclosure of these images cannot compromise voter
    privacy, and neither can the ballots from which these images were produced, nor can the
    CVR produced from the ballots and/or ballot images

    Here are the facts that the plaintiffs have that dispute the election commission and the counties’ weak arguments:

    Argument 1- There is Personally Identifiable Information (PII) on the ballots; i.e., an individual’s ballots could be identified.

    Counterargument- During depositions and discovery, the defendants admitted that there is no PII on the ballots, and our experts claim the same and that there is no way to tie a voter to a ballot. Other than the voter’s selections, the only information on the ballot about the voter is their precinct and their ballot style. One way the SEC believes a voter can be identified by their voting (and this is also very improbable, if not impossible) is if there are just a few people with the same ballot style who all voted for the same candidate. There are roughly 950 people across our entire state with fewer than 10 ballot styles, and these could be easily redacted or filtered from a CVR report. This is how other states handle this issue.

    Furthermore, ES&S guarantees privacy in their own documents. In the Michigan Request for Proposal No. 007116B0007029 for Election Systems and Software on page 33 of 152, it states the following:

    “Every ballot is assigned a random 16-byte identifier, and all the ballot CVRs and Ballot images are stored on the inserted memory media with exactly the same timestamp. This effectively decouples any association of the ballot to the voting order to guarantee voter privacy.”

    See Affidavit Rick Weible Supplemental Addendum below

    Argument 2- They use the SC constitution ballot secrecy clause to keep us from seeing the ballots.

    Counterargument: The ballots lack identifying information, and they overlook the issue of public counting, which is the second part of that clause. The casting of the vote is secret, not the counting. This is why safeguards are put into place to ensure that no identifying information is on any ballot.  Note that if they believe that there is a way to tie ballots to voters to determine how they voted, we would need to abolish the current system entirely, since it doesn’t meet federal requirements that mandate secret ballots, AND that means that they (the SEC as well as ES&S) know how people voted.

    Argument 3- The counties and election commission have limited knowledge of CVRs and have no way to “produce them” and shouldn’t have to, given that our state FOIA law states they don’t need to “create” data to provide to citizens. The defendants admit they didn’t retain or don’t have these records. This is a violation of federal laws: Reference 52 US Code 20701-2

    Counterargument: This is concerning. These are important records required by federal and state law that have been around since the mid-2000s. They are essential to auditing elections, and they are also mentioned in their manuals and the system certificates in multiple places.  It is their job to know about these reports and understand how to export/print them. Furthermore, they don’t need to create anything. The Cast Vote Records are created during tabulation.  In Boone County, MO, in their County Commission Meeting document dated 7/16/2019, it states:

    Safeguards voter intent. The system captures and retains digital images and cast vote records of every scanned ballot for auditing and adjudication. ES&S does not alter a single digital image.

    Again, see Affidavit Rick Weible Supplemental Addendum above

    To further emphasize this point, one of our other experts, Donnie Scroggins from Arkansas, who gets CVR reports by request (Arkansas has the identical ES&S system to South Carolina), has videotaped how easy and quick it is to download a CVR report that has been uploaded via a flash drive into the Electionware system with just a few clicks of a button. Here is his video:

    Argument: The Mickey Mouse defense- The Cast Vote Records could be used to promulgate fraud

    Counterargument: This is the most ridiculous and inane claim. The defendants and Attorney General Alan Wilson argue that if a nefarious candidate or their proxy wanted to commit fraud, they could pay people to vote for them and use an alias as a write-in for another race to confirm their vote. So, for example, one would vote for Tom Smith for Treasurer and tell him that they will write in “Mickey Mouse” in another race to prove they voted for him. They are basically using this excuse of fraud, which they admit they never encountered, to disenfranchise citizens who are serious about checking for potential issues or fraud. Seriously? And by the way, the cast vote record reports can remove the “write-ins” with a click of a button, so this isn’t even an issue.

    Argument: Small votes can be determined; for example, Provisional and UOCAVA

    Counterargument:

    Provisional votes – These are already potentially exposed, because if you have a few votes and someone attends the provisional hearings, they may be able to go to scvotes.gov and see how that person voted. If there is only 1 provisional in a precinct, and I attended the hearing and know who that person is, then the one provisional for that precinct will be disclosed by just looking at how the provisional voter voted in that precinct. Once again, this is a stretch, as most people are not trying to determine how people vote in a provisional hearing. The CVR itself is not the pathway for determining votes, as that can be done through the state’s reporting system.

    Overseas votes/UOCAVA—These votes are already viewed by election staff as they come in via email and are then transcribed onto a ballot and then scanned. We are not sure how a CVR would expose a particular individual and how they voted, since the designation of who is UOCAVA isn’t disclosed anywhere.

    Finally, Andino uses the 1939 Corn vs Blackwell case as a precedent for why the secrecy of the ballot is important but this has no bearing with our situation given that the ballots and the overall system is markedly and profoundly different from today’s system and the ballots don’t have sequential numbering on them nor can we determine order given the randomization and identical timestamps for each day that there is a tabulator in use; i.e. each cast vote record regardless of the time of the day will have an identical timestamp equivalent to the start of the machine, usually 7 AM in SC.

    From Dr. Daugherity’s expert affidavit:

    This case is inapposite and irrelevant to the CVR report, as it contains no voter ID. voter registration number, ballot number, social security number, driver’s license number, name, address, birthdate. or any personally identifiable information whatsoever.

    He further states:

    AG Opinion’s conclusion that these public records … are not required to be disclosed is conditioned by the phrase “To the extent that the disclosure of materials related to a cast ballot would lead to the identification of a voter.” Since neither ballots, nor ballot images, nor CVR reports contain any personally-identifiable information whatsoever, the conclusion that they are not required to be disclosed fails.

    Sorry, but the judge got it WRONG!!! Here are additional expert affidavits that rebut the facts presented in Marci Andino’s letter, as well as the 2 AG opinions issued.  The facts are on our side. This case should not have dragged on this long, and this information should have been provided long ago. The people deserve to know how their vote was counted. Trust in the veracity of our elections is the cornerstone of our republic. Election integrity and FOIA law are not being respected, and something must be done about it.