I’m currently working not just in IT security but IT elections security, and I can unequivocally say without a single shadow of doubt that you nor anyone else should EVER trust a fully electronic election system, EVER.
There literally is no possible way to secure it.
Paper has problems. Computers have those multipled by thousands of times. Networked computers, tens of thousands.
There’s no operating system secure enough, and layering the rest of even lower quality software on top of an already completely insecure foundation, is nothing but an unmitigated disaster.
Our stuff is nearly zero risk to anybody and we are in endless meetings with numerous overlapping agencies. There’s even a few States who’ve already been burned by hackers so bad (non-election related) that they feel joining money grubbing private “security” orgs who literally ONLY publish what to do AFTER you’re hacked, is somehow saving them from harm.
Until the software industry has regulatory standards as strong as building codes with deep fines for ignoring them, it’s not engineering. It’s crap. We are decades away from that if ever. Nobody writing code in the landscape that shifts as much as the languages do daily, wants to be forced into any form of security discipline or rigidity. It would mean the code was never completed in time. Take ten plus years to write secure elections code that would still sit on top of insecure OSes and networks.
Let alone that 80% of losses are estimated to be inside jobs by people with legitimate access to the data... bribes and USB sticks are way cheaper than hacking. And the vast majority of businesses, someone with a clipboard and a fake badge will walk right in behind everyone else during the lunch rush.
My fave is the guy who repeatedly successfully attacks multi-national companies (he’s hired for testing their security, not a bad guy) by walking into their smaller locations pretending he’s there to fix the printer.
There almost isn’t a business on the planet that doesn’t drop their guard when someone says they’ll get the mother-effing printers working right. LOL. Printers are the true spawn of hell in IT.
No no no fully electronic voting EVER. It should send shivers up your spine.