Maxine Dexter has repeatedly and forcefully defended Oregon’s all-mail system as safe, secure, and effectively unhackable (“you can’t hack paper ballots”). The New York Times has characterized many of President Trump’s election-integrity critiques as baseless. Both positions amount to a high-confidence claim about system resilience. High-confidence claims in security invite rigorous, authorized testing — not just official assurances or low historical prosecution rates.
The U.S. Department of Defense already demonstrated the value of this approach with “Hack the Pentagon” (2016), the first federal bug-bounty program. Roughly 1,400 vetted ethical hackers participated in the six-week pilot. The first valid vulnerability arrived in 13 minutes. Ultimately 138 unique, legitimate vulnerabilities were confirmed and fixed. Defense Secretary Ash Carter noted that a traditional private-sector audit would have cost more than $1 million; the crowdsourced effort was far cheaper and more effective. It became the model for ongoing DoD vulnerability disclosure.
Mail-in voting systems are not identical to public-facing DoD websites, but the principle transfers. Oregon’s system, California’s, Washington’s (and similar long-chain mail systems) relies on an extended physical and procedural custody path: printing → mailing/drop-box → intake → signature verification → tabulation → storage → audit. That chain multiplies points of human access. Security professionals call the residual risk the insider threat — people with legitimate Motive, Opportunity, and Means (MOM). Federal guidance from CISA explicitly treats insider threats to election infrastructure as a real and ongoing concern; authorized testing is one recognized mitigation.
A “Hack the Mail-In System” program modeled on the Pentagon effort would therefore prioritize:
Legal safe harbor and clear rules of engagement so participants who stay inside scope are protected. Unauthorized access remains illegal.
Public-facing technical layer (voter portals, tracking sites, registration systems) — the closest parallel to the original Pentagon challenge.
Authorized insider / custody-chain red-team exercises in non-production or tightly observed environments. Realistic scenarios include temporary workers with signature-verification access, collusion thresholds needed to affect meaningful numbers of ballots, privilege retention after role changes, effectiveness of chain-of-custody logs/cameras/dual-control rules, and whether audits can be delayed or misdirected by someone who understands the process.
Process and privilege audit track examining who holds elevated access, how often privileges are reviewed/revoked, background-check depth for temporary staff, and time-to-detection metrics.
Transparent scoring and remediation ranked by required privilege level, collusion needed, opportunity window, detection probability, and potential impact. Publish redacted findings and fix status so the public can evaluate the work without handing adversaries a complete playbook. Monetary or recognition incentives scaled to severity, as in the Pentagon program.
Oregon already employs paper ballots, signature verification, barcode tracking, risk-limiting audits (or hand counts), bipartisan observation in many steps, and air-gapped tabulation equipment. Official reviews report extremely low prosecution rates for fraud. Those controls matter. They do not eliminate the value of deliberately stress-testing the higher-privilege, higher-trust human and procedural layers under controlled conditions. Systems that claim high resilience improve public trust most effectively when they invite authorized adversarial scrutiny rather than treat skepticism as illegitimate.
The challenge is straightforward: if the system is as robust as claimed, an authorized, time-boxed, scoped program modeled on Hack the Pentagon will demonstrate it. If gaps surface, they can be fixed before a motivated actor exploits them. Either outcome strengthens the system and the public’s ability to evaluate the confidence claims made by officials and major media outlets. That is how mature institutions treat security assertions.
Mail-In Vote Security Challenge
(Modeled on the 2016 Hack the Pentagon bug-bounty program)
Specific Technical Scope Boundaries
1. Public-Facing Technical / Vulnerability Disclosure Layer
(Closest parallel to the original Hack the Pentagon program)
In scope:
Out of scope:
2. Authorized Insider / Custody-Chain Red-Team Exercises
(The distinctive mail-in focus)
In scope:
Out of scope:
3. Process and Privilege Audit Track
Agree/Disagree with the author(s)? Let them know in the comments below and be heard by 10’s of thousands of CDN readers each day!
The interstate migration of Americans has been happening for decades, but is it giving the…
Former Republican Texas Rep. Kay Granger, the first woman of her party elected to represent…
The Democratic establishment could lose its stronghold in Michigan as candidates are set to face…
Every summer it happens. The weather turns hot, the lawn starts looking a little tired,…