Georgia's Ballot Secrecy Is Compromised by Predictable Scanner IDs and Requires Fixing Underlying Data, Not Just Restricting Public Access

Source: Mark Davis. "Princeton Study Shows How Bad Actors Can Exploit Georgia Elections To Expose How You Voted." August 6, 2026. thefederalist.com

The Gist

The author argues that Georgia's voting machines create traceable digital fingerprints on ballots, meaning that with enough data, someone could figure out exactly how a specific person voted — breaking the promise of a secret ballot. He says the state's recent fix only hides this data from the public but doesn't actually remove the vulnerability from the internal systems, so officials or hackers could still exploit it; the real solution is a technical fix that eliminates traceability while keeping elections auditable.

Conclusion

Georgia must fix the underlying technical vulnerability that makes ballots traceable to individual voters (by properly randomizing or patching Record IDs at the source), rather than merely restricting public access to the data while leaving the traceable records intact within official systems.

Premises

  1. A Princeton researcher demonstrated that Georgia's Dominion precinct scanners assign predictable, non-random Record IDs that allow reconstruction of ballot scanning order, achieving near-complete voter-to-ballot linkage in several counties and 98.9% of in-person ballots statewide.
  2. This vulnerability, combined with other public election records, allows determination of how specific individuals voted, violating Georgia's constitutional and statutory requirement of 'absolute secrecy' for ballots.
  3. Exposure of individual voting choices creates risks of social pressure, discrimination, intimidation, and doxing, particularly in small communities.
  4. The traceable voter data has significant commercial and political value for campaigns and micro-targeting firms, creating incentives for insiders to misuse or leak it.
  5. Georgia's election systems have a documented history of data breaches and security failures (e.g., the 2015 PeachBreach, the 2016-2017 Kennesaw State server exposure), showing that sensitive data held internally is not securely protected from leaks.
  6. The state's July 2026 remedy only restricts public access to ballot records but does not delete or re-randomize the underlying traceable data still held by officials and vendors, leaving the core vulnerability unresolved.
  7. A known technical fix exists (proper randomization at data creation, or Dominion's 2022 patch) that would eliminate traceability while preserving auditability, but Georgia has not implemented it.

Assumptions

View this argument on LogicFirst.ai