Georgia's Ballot Secrecy Is Compromised by Predictable Scanner IDs and Requires Fixing Underlying Data, Not Just Restricting Public Access
Source: Mark Davis. "Princeton Study Shows How Bad Actors Can Exploit Georgia Elections To Expose How You Voted." August 6, 2026. thefederalist.com
The Gist
The author argues that Georgia's voting machines create traceable digital fingerprints on ballots, meaning that with enough data, someone could figure out exactly how a specific person voted — breaking the promise of a secret ballot. He says the state's recent fix only hides this data from the public but doesn't actually remove the vulnerability from the internal systems, so officials or hackers could still exploit it; the real solution is a technical fix that eliminates traceability while keeping elections auditable.
Conclusion
Georgia must fix the underlying technical vulnerability that makes ballots traceable to individual voters (by properly randomizing or patching Record IDs at the source), rather than merely restricting public access to the data while leaving the traceable records intact within official systems.
Premises
- A Princeton researcher demonstrated that Georgia's Dominion precinct scanners assign predictable, non-random Record IDs that allow reconstruction of ballot scanning order, achieving near-complete voter-to-ballot linkage in several counties and 98.9% of in-person ballots statewide.
- This vulnerability, combined with other public election records, allows determination of how specific individuals voted, violating Georgia's constitutional and statutory requirement of 'absolute secrecy' for ballots.
- Exposure of individual voting choices creates risks of social pressure, discrimination, intimidation, and doxing, particularly in small communities.
- The traceable voter data has significant commercial and political value for campaigns and micro-targeting firms, creating incentives for insiders to misuse or leak it.
- Georgia's election systems have a documented history of data breaches and security failures (e.g., the 2015 PeachBreach, the 2016-2017 Kennesaw State server exposure), showing that sensitive data held internally is not securely protected from leaks.
- The state's July 2026 remedy only restricts public access to ballot records but does not delete or re-randomize the underlying traceable data still held by officials and vendors, leaving the core vulnerability unresolved.
- A known technical fix exists (proper randomization at data creation, or Dominion's 2022 patch) that would eliminate traceability while preserving auditability, but Georgia has not implemented it.
Assumptions
- The Princeton/Halderman research accurately represents the scope and reliability of the vulnerability across Georgia's voting systems.
- Officials or vendors with access to internal traceable data have both the technical capability and some plausible incentive to exploit or leak it.
- Restricting public access without fixing internal data is meaningfully different from full resolution of the secrecy problem, i.e., 'security through obscurity' is inherently insufficient.
- The described technical fixes (randomization patch) would not compromise the state's ability to audit elections.
- Existing legal and security failures in Georgia's election system are indicative of ongoing systemic risk rather than isolated historical incidents.
- Public disclosure and media publicity of this vulnerability will not itself cause the greatest harm (i.e., that the article's exposure is a net positive for reform rather than a roadmap for exploitation).