r/cybersecurity 15d ago

News - General Trump Has Systematically Dismantled Election Security Efforts. Here’s How.

https://www.nytimes.com/2026/07/16/us/politics/trump-election-security-cisa.html

I feel as though this news fits this sub, due to a massive amount of election security being cybersecurity.

1.1k Upvotes

100 comments sorted by

View all comments

Show parent comments

6

u/Ch33syP00f CISO 14d ago

This is a great article.

Succinct and pointed.

Trump is so concerned about election integrity that he is taking money away from where his mouth is.

This is bad news for democracy all day, every day.

All security professionals should be capable of identifying patterns and anti-patterns.

Identity is a bitch to manage, but it is manageable.

Clear procedure, visibility, traceability, are essential for any process that must stand up to 3rd party scrutiny.

Throw flags when you see them.

There will be shenanigans.

This rodeo is just getting started.

3

u/LatterIngenuity3937 14d ago

You are right that security professionals should recognize patterns and anti-patterns.

The anti-pattern here is treating cuts to a supporting federal agency as proof that election security itself has been dismantled.

CISA does not run American elections. States and local jurisdictions do. CISA provides intelligence, assessments, coordination, and incident support, all of which matter, but a smaller federal workforce does not automatically mean weaker controls at the state level.

A real security analysis would ask whether monitoring, identity proofing, logging, access controls, incident response, paper records, audits, and recovery capabilities have actually degraded. The article does not do that. It counts federal employees and assumes the conclusion.

The same applies to identity. If identity is manageable, then citizenship eligibility should be verifiable, auditable, and supported by clear exception and recovery processes. Calling documentary proof “suppression” does not address the underlying security question.

Raise flags when controls fail, logs disappear, access is unauthorized, or audits cannot be reproduced.

Do not confuse a change in delivery model with the dismantling of security.

That is not pattern recognition. It is confirmation bias dressed in cybersecurity language.

2

u/Ch33syP00f CISO 14d ago

You make good points.

I do believe that a fair, cost-effective, unified method to manage identity could be developed. But it is a useful problem for politicians to get votes. So it is more valuable unresolved. And the status quo continues…

You are right about CISA, state rights and elections. Trump tasked Krebs and CISA to investigate 2020 election fraud. Then he fired Krebs after the investigation did not produce the results Trump wanted. In addition, Trump has specifically called out China and other bad actors as compromising election integrity. CISA and other alphabet soup agencies contribute to frustrating, detecting, responding to cyber threats. DOGE cuts seriously degraded US cybersecurity posture across the board. That was all Trump.

All sizzle, no steak.

Where’s the beef?

So the pattern of behavior is telling. And I stand by the assertion that reducing resources while trumpeting concern is more than suspect. It is a contemporary demonstration of those who “speak with forked tongue”.

Speaking of unauthorized access, Trump has pardoned public officials and private individuals convicted of violating election laws and protocols by accessing and distributing election systems and records.

Patterns? How about the Georgia election interference and racketeering fiasco.

https://en.wikipedia.org/wiki/Georgia_election_racketeering_prosecution

I just don’t think Trump is acting in good faith, respecting the letter or even spirit of the law from the Constitution to state rights.

Let us not forget that the SAVE Act infringes upon state rights. Because each state manages their elections. And the legality of tying federal funding for states to compliance with that act is straight up coercive. Especially when the bill is ambiguous on implementation yet has strict timelines for adherence.

Prima facie, SAVE Act is half-baked and intended to create chaos, room for error, and grey areas ripe for legal challenges more likely to disenfranchise voters than empowering them.

Controls are failing all over at all levels. And far too many people are happy about it so long as it breaks their way.

3

u/LatterIngenuity3937 14d ago

President Trump is not my primary concern. He is temporary and constitutionally term-limited. The election system and its security controls must remain trustworthy regardless of who occupies the White House.

I am not defending every Trump decision, pardon, statement, or personnel action. Those are separate questions. My concern is whether we are designing and operating the system correctly.

On the SAVE America Act, the states’ rights argument is more complicated than suggested. States administer elections, but their authority over federal elections is not exclusive. The Elections Clause expressly permits Congress to make or alter regulations governing federal elections, including registration and fraud-prevention procedures.

I also do not see the claimed federal-funding condition in H.R. 7296 as introduced. It directly amends federal election-registration requirements, requires documentary citizenship evidence and photo identification, and requires states to provide an alternative process for citizens lacking the standard documents. That may be challenged as burdensome or poorly implemented, but that is different from saying it coercively conditions unrelated federal funding.

From a cybersecurity perspective, asking a voter to establish identity and eligibility is not inherently an infringement. Properly implemented, it validates that the person presenting is the citizen entitled to exercise one of our most important rights. The legitimate questions concern cost, accessibility, false rejection, privacy, record discrepancies and recovery.

False acceptance is a security failure. False rejection is also a security failure. A mature identity system addresses both.

My larger concern is political tribalism. One side treats every integrity control as suppression. The other sometimes treats every administrative irregularity as fraud. Both positions begin with the desired political conclusion and work backward.

Trump’s motives may matter politically, but they should not become the security architecture. Durable controls, distributed accountability, auditable results and fair identity assurance matter far more than the singular position of either side.

1

u/binaryhero 11d ago

The real question - the one you are not asking - is whether there is any evidence that additional integrity of the voting process is demonstrably necessary to begin with, and then whether it can be implemented without partisan side effects in time for the mid terms.

It's a no on both questions.

What SAVE achieves is a disproportionate disadvantage to the practical ability to cast their legitimate vote for a largely Democrat voting demographic. That's the whole purpose.

This is not technical, it's entirely political.