"Fortress Island" Physical Security in Voting Systems

Drew Springall (Professor · Auburn)

Voting Village @ DEF CON 33 · Day 1 · Voting Village

Overview

In his compelling Voting Village 2025 presentation, "Fortress Island" Physical Security in Voting Systems, Professor Drew Springall of Auburn University, alongside collaborators Tripispel, Jenny Ginge, and Jared Hardy, delivers a critical examination of a frequently overlooked yet foundational aspect of election security: the physical safeguards protecting voting machines. Springall challenges the prevailing assumption that locks, seals, and other physical barriers are robust deterrents against malicious actors, revealing systemic vulnerabilities that render many election systems surprisingly susceptible to compromise. His talk draws a powerful analogy to the World War II "Fortress Singapore," which was deemed impregnable but fell swiftly due to a misdirected defense strategy, illustrating how a focus on one type of threat (cyber) can leave another (physical) dangerously exposed.

Watch on YouTube

Visual summary for "Fortress Island" Physical Security in Voting Systems by Drew Springall
Visual summary for "Fortress Island" Physical Security in Voting Systems by Drew Springall

Key moments

  1. 0:00 Introduction to physical security in voting systems
  2. 2:19 Singapore's 'Fortress Island' analogy for perceived security
  3. 4:06 How voting systems' physical security is often misunderstood
  4. 6:01 Explaining protective, detective, and procedural security types
  5. 8:07 Researching keys for 'average attacker' voting system vulnerabilities

"Fortress Island" Physical Security in Voting Systems

Speakers: Drew Springall, Professor, Auburn

Conference: Voting Village

YouTube: https://www.youtube.com/watch?v=yvbe6n82f0I

Overview

In his compelling Voting Village 2025 presentation, "Fortress Island" Physical Security in Voting Systems, Professor Drew Springall of Auburn University, alongside collaborators Tripispel, Jenny Ginge, and Jared Hardy, delivers a critical examination of a frequently overlooked yet foundational aspect of election security: the physical safeguards protecting voting machines. Springall challenges the prevailing assumption that locks, seals, and other physical barriers are robust deterrents against malicious actors, revealing systemic vulnerabilities that render many election systems surprisingly susceptible to compromise. His talk draws a powerful analogy to the World War II "Fortress Singapore," which was deemed impregnable but fell swiftly due to a misdirected defense strategy, illustrating how a focus on one type of threat (cyber) can leave another (physical) dangerously exposed.

Springall's work is particularly significant because physical attacks on voting systems are often dismissed as too difficult or requiring an unreasonable level of access and expertise. However, by demonstrating how readily accessible information and common tools can bypass these defenses, he underscores that such attacks are not only feasible but, in many cases, surprisingly straightforward for even an "average attacker" with modest reconnaissance efforts. The research, primarily conducted in 2023 and referencing 2022 systems, provides an exhaustive catalog of weaknesses in both protective security (locks) and detective security (tamper-evident seals), offering crucial insights for election officials, policymakers, and cybersecurity professionals striving to secure democratic processes.

Background

▶ Watch: Introduction to physical security in voting systems (0:00)

The concept of physical security in voting systems has long been a cornerstone of election integrity discussions, often cited as a robust fallback in the face of cyber threats. Major voting system vendors consistently tout the use of keyed locks and tamper-evident mechanisms as primary defenses. The EAC (Election Assistance Commission), an independent federal agency tasked with assisting election administration, also recommends common best practices that include the widespread use of tamper-evident seals and locks. This pervasive belief was notably challenged by earlier research, such as work by Professor J. Alex Halderman and others, demonstrating that even sophisticated electronic vulnerabilities, like those accessible via a USB port, were often dismissed by officials who believed that physical security would prevent such access. The underlying assumption was simple: "No one can get to the USB port because it's locked and sealed."

However, this reliance on physical security often overlooks the practical realities of its implementation and the inherent weaknesses of many commercial-off-the-shelf solutions. Springall's talk dissects physical security into three distinct categories: protective security, which aims to prevent an action (e.g., a lock preventing access); detective security, which aims to alert officials if an action has occurred (e.g., a tamper-evident seal); and procedural security, which encompasses policies and human practices (e.g., secure storage locations, proper handling protocols). While acknowledging the critical role of procedural security, Springall focuses his extensive investigation on the first two categories, arguing that their foundational weaknesses often render procedural controls ineffective. The core problem, much like the "Fortress Singapore" that focused its massive coastal defenses seaward while neglecting a land approach, is a misallocation of defensive effort and a failure to anticipate alternative attack vectors.

Key Findings

▶ Watch: Singapore's 'Fortress Island' analogy for perceived security (2:19)

The central discoveries of Springall's research reveal a pervasive and alarming lack of robust physical security across a wide array of U.S. voting systems. The team's exhaustive investigation into thousands of publicly available documents, videos, and images yielded two primary, interconnected findings:

  1. Widespread Use of Common and Easily Acquirable Keys: A surprisingly limited number of distinct key codes are used across numerous voting system vendors and states. Crucially, these keys are often easily identifiable from publicly available training materials and can be acquired online through commercial locksmiths or e-commerce platforms like eBay, frequently for minimal cost. This means that an "average attacker," without specialized lockpicking skills, can obtain functional keys with relatively simple reconnaissance.
  2. Systemic Flaws and Misapplication of Tamper-Evident Seals: Tamper-evident seals, intended to detect unauthorized access, are frequently rendered ineffective due to design flaws, improper application, or a lack of understanding by poll workers. From easily defeated seal designs to common human errors like forgetting to apply seals or incorrectly installing them, these detective measures often fail to provide reliable indicators of tampering.

Springall's team recovered and cataloged key information from an estimated 38 U.S. states, representing a significant cross-section of the nation's election infrastructure. Their work demonstrates that the security of many voting machines relies on a false sense of impermeability, akin to the "Fortress Island" analogy, where defenses are strong against anticipated threats but critically weak against less obvious, yet equally effective, approaches.

Technical Deep Dive

▶ Watch: How voting systems' physical security is often misunderstood (4:06)

The technical core of Springall's presentation lies in the meticulous methodology employed to identify and acquire keys, coupled with a detailed analysis of common seal vulnerabilities.

Key Recovery and Acquisition Methodology

The research team embarked on an incredibly wide and long-term search for images and descriptions of keys related to U.S. voting systems. Their reconnaissance phase was extensive, involving:

  • Public Documentation: Thousands of PDFs, training manuals, and certification documents from state election offices, county election officials, and the EAC. These often contained explicit images of keys or detailed descriptions.
  • Online Videos: Thousands of YouTube videos, particularly poll worker training videos, were scrutinized. These videos frequently showed keys in use, sometimes in clear enough detail for identification. Springall noted instances where a single clear frame in a blurry video provided crucial data.
  • News and Media Archives: AP images and Getty Images were searched, often yielding photographs of voting equipment that inadvertently displayed keys.
  • Vendor Websites: Some vendors even posted images of keys for sale, providing direct identification.

Once key depictions were found, the team employed two primary methods for key data recovery:

  1. Recovery via Key Code: Many keys have a key code (e.g., "J236") stamped directly onto them. If a clear image was obtained, this code could be read, allowing for direct purchase from locksmiths.
  2. Recovery via Key Cuts: For keys without visible codes or where images were less clear, the team recovered data by analyzing the key cuts (the bitting pattern). Drawing an analogy to Boy Scouts measuring tree heights using known reference points, Springall explained that keyways themselves have known dimensions. By using these known dimensions as reference points in a clear image, the relative depths and spacing of the key cuts could be measured and reconstructed. This detailed information was then used to either identify an existing key code or to have a key cut to specification.

With the key data recovered, the next step was key acquisition. The team proactively purchased a vast array of these identified keys from various online sources, including eBay and specialized online locksmiths. Springall mentioned that any key shown in the presentation with a green background was one they had successfully acquired. In some unique cases, such as an unidentified latch on the Hart InterCivic Verity Touch Writer/Scan, they purchased the entire low-cost latch assembly (a SouthCo $3 latch), which came with its standard key (later identified as S010). This proactive acquisition allowed for direct comparison and validation of their findings.

Common Key Codes Identified

The investigation revealed a surprising commonality in key usage across different vendors and systems:

  • ES&S (Election Systems & Software):
  • J236: A ubiquitous blade key used for multiple components, including the DS200 ballot boxes, the rear door, and other access points.
  • 301 tubular key: Found on the ExpressVote for all three of its tubular locks and, by default, also on the DS200.
  • Hart InterCivic:
  • S010: A standard key for the SouthCo suitcase latch, widely used on the Verity Touch Writer/Scan systems.
  • RS0001: Another SouthCo-specific key mechanism.
  • CH751: This key was highlighted as particularly egregious. It's used for ballot boxes on the Verity Scan and other systems. Springall noted its extreme commonality, stating that if you've been around an RV or visited the Defcon vendor area for penetration testing kits, you've likely encountered this key, as it's included in many pre-made kits due to its widespread use in low-security applications.
  • Dominion Voting Systems:
  • F229: Used for the ICP IC ballot box.
  • 542 dimple key: This was one of the harder keys to locate, used for the VDP printer (not the main ICX system itself, which typically lacks locks). Springall eventually found and purchased it for $7 from Italy, illustrating that even "hard-to-find" keys are often commercially available.

While these are considered "default" keys, Springall clarified that they are not universally present in every single jurisdiction. He cited New York State as an exception, where contracts explicitly specified "key differently" line items, leading to the use of unique key codes (e.g., 003, 004). However, even these custom keys were recoverable from New York's public training materials, demonstrating that customization alone doesn't guarantee secrecy if documentation is publicly accessible.

Tamper-Evident Seal Vulnerabilities

The research also extensively covered detective security mechanisms, specifically tamper-evident seals. While harder to catalog due to their frequent replacement, the team identified numerous weaknesses:

  • Human Error: A common issue is simply forgetting to apply seals to equipment.
  • Improper Application: Poll workers often cut the tails off pull-tight seals to make them less cumbersome. While seemingly benign, this removes a visual indicator of proper tension and length, making it harder to detect if a seal has been removed and replaced with a slightly shorter one without a ruler for measurement. These pull-tight seals were described as "babies first defeat" in the tamper-evident village, indicating their ease of bypass.
  • Misplaced Seals: Tapes were sometimes applied to flat, non-opening plastic surfaces, rendering them functionally useless as a tamper indicator.
  • Residue Normalization: Some tapes leave a residue when removed. However, if this residue becomes a common sight due to frequent legitimate opening and closing, it ceases to be an effective indicator of malicious tampering.
  • Plunger Seals: A particularly detailed vulnerability was demonstrated with plunger seals, which consist of a plastic body and a braided wire, secured by pushing a plunger into the body. The team discovered two critical flaws:
  1. Force Requirement: Proper engagement requires significant force to drive the plunger deeply enough for an internal flap to catch. Many poll workers (especially older individuals) struggle to apply this force, resulting in partially inserted plungers. These can be easily disengaged with a piece of wire or a lock pick from the back side.
  2. Single-Sided Catch: When the team cut open a plunger seal, they found the internal catch mechanism was only on one side. This means that if the plunger is re-inserted incorrectly (a 50% chance if not specifically taught the correct orientation), it will never engage, regardless of how much force is applied.
  • "Vampire Seals": Springall briefly mentioned another type, "vampire seals," as having major problems, indicating further seal vulnerabilities that he didn't have time to detail.

These findings collectively paint a picture where both preventative and detective physical security measures on voting systems are often far less robust than generally assumed, creating significant avenues for compromise.

Demo / Proof of Concept

▶ Watch: Explaining protective, detective, and procedural security types (6:01)

While the talk did not feature a live, real-time demonstration of a specific exploit against a voting machine, the "Demo / Proof of Concept" was inherent in the presentation of the research itself. Springall and his team demonstrated the profound vulnerabilities in physical security through:

  1. Presentation of Acquired Keys: The green-backed images of numerous actual, physically acquired keys served as a powerful proof of concept. These were not theoretical keys but tangible items obtained through publicly available information and online purchases, directly demonstrating the ease with which an "average attacker" could gain access.
  2. Visual Evidence of Key Recovery: The slides showing how key codes were read from images or how key cuts were measured from photographs illustrated the practical methodology for compromising protective security.
  3. Deconstruction of Seal Weaknesses: The detailed explanation and visual aids (e.g., the cut-open plunger seal) provided a clear demonstration of how common tamper-evident seals fail due to design flaws, improper application, or a combination of both. The speaker even offered to have various seals available for attendees to "play with" at Defcon, further emphasizing the practical, hands-on nature of their findings.

The strength of this "demonstration" lay in its systematic and comprehensive nature, revealing widespread, rather than isolated, vulnerabilities across a broad spectrum of election equipment and jurisdictions. It wasn't about a single hack, but about proving a systemic failure of physical security assumptions.

Defensive Implications

▶ Watch: Researching keys for 'average attacker' voting system vulnerabilities (8:07)

The findings from "Fortress Island" carry profound implications for election officials, security professionals, and policymakers responsible for safeguarding the integrity of voting systems. The talk serves as a stark warning that physical security cannot be treated as a mere "fallback" or an assumed impenetrable barrier.

  1. Re-evaluate Physical Security as a Primary Layer: Election officials must shift their mindset from viewing physical security as a secondary concern to recognizing it as a critical, and often weakest, link in the chain of trust. This means moving beyond mere compliance with minimum standards to actively seeking and mitigating vulnerabilities.
  2. Implement Robust Key Management Programs:
  • Abolish Default Keys: The widespread use of common, default key codes must cease immediately. Jurisdictions using these keys should implement comprehensive re-keying programs, replacing generic locks with unique, high-security alternatives.
  • Secure Key Documentation: All training manuals, videos, and public documents should be reviewed to ensure they do not inadvertently expose key codes or clear images of keys. If such details are necessary for training, they should be presented in a way that obscures identifying features or restricted to internal, secure access.
  • Strict Key Control: Implement stringent protocols for tracking, storing, and distributing keys, treating them with the same level of sensitivity as cryptographic keys or ballot materials.
  1. Strengthen Tamper-Evident Seal Protocols:
  • Use Stronger Seal Designs: Invest in seals that are demonstrably more difficult to defeat or circumvent (e.g., those with multiple, complex failure indicators). The ease of defeating pull-tight and plunger seals suggests a need for a fundamental re-evaluation of seal types.
  • Comprehensive Poll Worker Training: Provide rigorous, hands-on training for poll workers on the proper application, inspection, and verification of seals. This training should explicitly cover common vulnerabilities, such as the risks of cutting seal tails or the correct orientation for plunger seals, and how to identify signs of tampering (e.g., measuring seal length, checking for full plunger insertion, understanding legitimate residue vs. tampering residue).
  • Regular Audits and Spot Checks: Implement procedures for independent verification of seal integrity before, during, and after elections. This includes physical checks and photographic evidence to document seal numbers and conditions.
  1. Embrace Layered Security: While physical security is critical, it is only one layer. It must be integrated with robust cyber security, strong procedural controls, and comprehensive audit mechanisms (like post-election audits and risk-limiting audits) to ensure that even if one layer is breached, others can detect and mitigate the impact.
  2. Acknowledge the "Average Attacker": The findings highlight that an attacker doesn't need to be a "wizard" lockpicker. Instead, an individual with moderate resources, a willingness to conduct reconnaissance on public information, and the ability to acquire common keys online poses a significant threat. Defenses must be designed to withstand such realistic attack scenarios.

By proactively addressing these vulnerabilities, election officials can significantly enhance the resilience of voting systems against physical threats, moving away from the illusion of an "impregnable fortress" towards genuinely secure and verifiable elections.

Key Takeaways

  • Physical security is a critical, often underestimated, and frequently weak layer in the overall security posture of voting systems.
  • Common, low-security keys are widely used across multiple vendors and states, making them easily identifiable from public sources and acquirable online by "average attackers."
  • Tamper-evident seals are systematically flawed, suffering from design weaknesses (e.g., plunger seals, easily defeated pull-tights) and widespread improper application or inspection by poll workers.
  • The "Fortress Island" analogy highlights a dangerous strategic error: focusing defensive efforts on anticipated cyber threats while leaving physical access points dangerously exposed.
  • Election officials must urgently re-evaluate and significantly strengthen physical security protocols, including implementing unique, high-security keys and robust, well-trained procedures for seal application and verification.
  • Publicly accessible information, such as training manuals and videos, inadvertently serves as a blueprint for attackers, inadvertently exposing critical security details like key codes and seal vulnerabilities.

About the Speaker(s)

Drew Springall is a Professor at Auburn University and a longtime participant and friend of the Voting Village. He is renowned within the election security community for his exceptional ability to uncover vulnerabilities in election equipment, humorously described by the introduction as having a "rare superpower to look at election equipment and it just gives up without even a fight." His work consistently focuses on practical, hands-on security research that exposes real-world weaknesses in election infrastructure. This particular project was a collaborative effort with Tripispel, Jenny Ginge, and Jared Hardy, whose contributions were integral to the extensive research and findings presented.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Springall's physical security audit of U.S. voting systems is exactly the kind of unglamorous, systematic work the field needs more of: real keys purchased, real seals defeated, real evidence across 38 states. It won't make the mainstream news cycle the way a remote-code-execution would, but it methodically dismantles the 'physical security as backstop' assumption that vendors and election officials have been hiding behind for years.

Heather Calloway (CISO) — STRONG ACCEPT

Springall delivers systematic, evidence-grounded research that dismantles a foundational assumption in election security — that physical controls are a reliable backstop to cyber risk. The work is operationally credible, the findings are cross-jurisdictional, and the defensive path forward is clear enough for election officials to act on. It stops short of a five because it doesn't engage the institutional accountability question: who at EAC, the vendors, or the state level owns the failure to address what is, frankly, not a new class of problem.

→ Top-rated talks at Voting Village @ DEF CON 33

All talks from Voting Village @ DEF CON 33