On Dec. 20, 2024, Denver District Attorney Beth McCann announced that criminal charges will not be filed in connection with the publication of voting machine passwords on the Colorado Department of State website earlier this year.
“After an extensive investigation by prosecutors and investigators in my office, we have concluded that there were no criminal violations of the law regarding the publication of the voting machine passwords,” McCann said via press release. “Based on everything we have learned, the passwords were published in error and not ‘knowingly,’ as required to prove a violation of C.R.S. 1-13-708(2), or ‘knowingly, arbitrarily or capriciously,’ as required to prove a violation of CRS 18-8-405(1). There is no indication that the passwords were published in an effort to influence the outcome of an election.”
The press release notes the investigation took seven weeks and focused on possible violations of the two Colorado statutes.
The full investigative report is available at https://bit.ly/4gtW1H8.
The investigation’s findings come in addition to the findings of Baird Quinn LLC, which determined that the BIOS — Basic Input Output System — passwords contained in the hidden worksheets posted on the Department website were posted “mistakenly, unknowingly and unintentionally.”
In November, Baird Quinn was engaged to conduct an independent investigation to determine how the posting happened, how it could be prevented in the future, and to present recommendations for improvement of department practices and procedures.
According to a press release, Baird Quinn was given full access to department personnel and documents to conduct its investigation. The investigation was supported by a company specializing in digital forensics for the purpose of providing expertise on metadata and other information associated with the specific files involved in the password posting.
The press release notes the investigation concluded that the BIOS passwords contained in the hidden worksheets posted on the Department website were posted “mistakenly, unknowingly and unintentionally.”
The report also finds that “a series of inadvertent and unforeseen events led to the public disclosure of the BIOS passwords.”
The report notes that, “The investigator finds that this unique set of circumstances would have been difficult to anticipate,” and, “on an organizational level, the Secretary of State/CDOS consistently took significant and appropriate measures to protect state information, including the BIOS passwords.”
The report determined there was a policy failure to adequately “review the posted document to ensure that non-public information would not be disclosed.”
The report furnished seven recommendations for the department to consider to minimize risk of any inadvertent disclosure in the future. They include:
• Instituting a policy prohibiting the use of “hide” functions for highly sensitive or confidential information within documents.
• Establishing a requirement that all passwords of any kind, whether they be individual user login credentials or password information such as the BIOS passwords, be kept only in a password safe unless an exception to that policy is granted in writing.
• Requiring better training on the data protection features of the computer software programs used on a daily basis, such as Microsoft Excel and Word.
• Updating the “Acceptable Use Computing Policy” (AUP) so the policy on the use of the password safe and the policy on creating and managing passwords are single, standalone policies rather than policies contained at various places within the User ID and Password section of the AUP.
• Requiring employees to review its AUP policy every year and sign that they have reviewed the document.
• Creating a substantive review process for the Elections Division (and possibly other divisions) for web requests involving posting documents to the department website.
• Reviewing the transition and exit processes for departing employees whose responsibilities involve handling sensitive or confidential information.
The full Baird Quinn report is available at https://bit.ly/4fyyZxv.
“The Department of State thanks Baird Quinn for their thorough review of this matter. We are committed to implementing their recommendations to ensure a situation like this never occurs again,” said Secretary of State Jena Griswold via press release.
The Colorado Secretary of State’s Office explains Colorado’s elections are protected by multiple layers of physical and network security measures. All of Colorado’s elections, including the recent General Election, are accurate and secure.
The fact sheet available at https://bit.ly/49X7hZZ explains the multiple layers of security, and how the Department of State verified the security and accuracy of the election.