DEF CON 33 - Voting Village - Reflections on TTBR & Everest - Bowen, Blaze, Clark, Hoke, Mulligan

DEF CON 33 - Voting Village - Reflections on TTBR & Everest - Bowen, Blaze, Clark, Hoke, Mulligan

Source: YouTube · DEFCONConference · published Nov 4, 2025 · 29:02

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The Top-to-Bottom Review and subsequent studies revealed critical vulnerabilities in early electronic voting systems, demonstrating the necessity for rigorous, independent security audits to ensure public trust in elections 0:09.

Key Takeaways:
• The Top-to-Bottom Review provided privileged access to voting system source code and hardware, allowing researchers to identify significant security flaws that had previously been hidden from the public 0:36.
• Researchers found that election officials were often trained by vendors and believed computer security had nothing to do with voting machinery, leading to a lack of scrutiny for decades 12:34.
• Even with improved systems today, the "chase the last bug" approach is obsolete, as sophisticated adversaries are less constrained than academic researchers, making software independence and architectural design crucial for security 23:22.

The visionary approach of the Top-to-Bottom Review, which prioritized scientific integrity over political pressure, serves as the essential model for future election technology oversight 11:44.

Sources:

  • 0:09 Introduction of the Top-to-Bottom Review and the Everest study.
  • 0:36 Details on the access provided to source code and hardware.
  • 12:34 Discussion on the disconnect between election officials and computer security.
  • 11:44 Emphasis on the integrity of the scientific product during the review.
  • 23:22 Critique of the "chase the last bug" methodology and

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

going to start us off, but uh this is this is intended to be an open-ended discussion. So I'm hoping this will just be a conversation among uh veterans of the top tobottom review and then another study that was inspired by the top tobottom review in Ohio uh called Everest. Uh so a uh uh the top bottom review was the first official opportunity that uh technologists were given to get privileged access to a voting system including looking at the source code and with the promise of being allowed to publish results unedited and without the approval of the vendors. And uh that was a hugely important uh opportunity. So I um was got a call from David Wagner who's a professor at UC Berkeley who was leading the source code review of the various um systems in uh uh uh in California. and he asked me i…