Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Elections topic

No spam. Unsubscribe anytime.

Witness tells House committee Internet voting remains insecure, urges caution before Michigan rollout

3131146 · April 15, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CJ Coles of Verified Voting told the House Committee on Election Integrity that current technology cannot guarantee the secrecy, security and verifiability of ballots returned over the Internet and urged Michigan to delay or reconsider implementation of electronic ballot return.

CJ Coles, representing the nonprofit Verified Voting, told the House Committee on Election Integrity that Internet voting — also described in the hearing as electronic ballot return — cannot be secured with current technology and remains incompatible with the safeguards election experts consider essential.

Coles defined Internet voting as the return of voted ballots to an election office by electronic methods such as a website, app, phone or fax, and said that while technology can improve access, it creates client-side and server-side vulnerabilities that cannot be mitigated today. "Internet voting is fundamentally incompatible with the defenses that I talked about," Coles told the committee. He said those defenses are voter‑verified paper ballots and robust post‑election audits.

Why this matters: Michigan passed a statute in a recent session to permit electronic ballot return, and Coles told the committee an implementation date is set for September (the year was not specified in his remarks). He said the state therefore has "a unique opportunity to do something that no other state has done" by stopping electronic ballot return before it becomes functional in the state election process.

Coles summarized the main threats. On the voter (client) side, he listed compromised personal devices, credential theft and imposter websites that can trick voters into submitting credentials to malicious actors. He warned this also raises voter‑coercion and vote‑selling risks because ballots returned electronically may not preserve the secrecy of the ballot: "When Internet voting is enacted, voters typically are required to sign away that right," Coles said.

On the server side, Coles described remote intrusions, insider threats, supply‑chain attacks and denial‑of‑service incidents that could prevent votes from being received. He cited a range of recent cyber incidents to illustrate the risk and described an overseas example in New South Wales, Australia, where researchers found flaws in an online voting system and later the site crashed on Election Day; the state abandoned the system for later contests.

Coles cited the consensus of technical and national‑security experts and formal reports: a 2018 National Academies report concluding that "no known technology guarantees the secrecy, security, and verifiability of a marked ballot transmitted over the Internet," and subsequent reviews by federal agencies and expert organizations that, in his words, found the conclusion still applicable in 2024 and 2025. He pointed to ongoing research on end‑to‑end verifiability and cryptographic approaches (including Microsoft’s ElectionGuard work), but said those cryptographic approaches currently do not resolve the fundamental privacy and security tradeoffs for Internet voting.

Members of the committee pressed Coles on specifics. Representative Song said she favored honoring voter initiatives and questioned whether the incidents Coles cited were primarily due to "human error" rather than technology; Coles responded that both the technology itself and human factors contribute to risk and that the technology cannot be secured sufficiently to remove those risks. Representative Altman asked whether electronically returned ballots can be audited; Coles answered that the typical workflow prints and duplicates received electronic ballots at the election office and that, once a voter stops interacting with a digital ballot, verifiability and auditing are fundamentally harder than with hand‑marked, voter‑verified paper ballots.

Coles also addressed certification and standards. He told the committee there are currently no federal standards to certify Internet ballot‑return systems and that, to his knowledge, no federal agency is certifying those systems because adequate standards do not exist.

The presentation concluded with Coles recommending caution: given current evidence and expert consensus, he told the committee that Internet voting "is not a secure solution in any form and that it will not be in the foreseeable future," and that Michigan should reconsider or delay the planned implementation until the security and verifiability problems are demonstrably solved.

The committee followed with questions from several members; the hearing then moved on to other business.