He Dropped Out at Sixteen and Then Broke Into America's Voting Machines
The Wrong Resume for the Right Problem
If you were designing the ideal candidate to overhaul American election security, you probably wouldn't start with a twenty-six-year-old retail worker from Albuquerque with a GED and a secondhand laptop. You'd want credentials. Institutional affiliation. A clearance, maybe. Someone who'd been through the system and understood the system.
The problem, as Marcus Teel eventually proved, was that the system was exactly what needed examining. And the people who'd been through it had stopped being able to see its flaws.
Marcus dropped out of high school in 2001, midway through his sophomore year. Not because he was failing — he was bored, which is a different problem and one that American education has historically been poor at solving. He started working at an electronics retailer in Albuquerque, stocking shelves and eventually migrating to the sales floor, where he discovered that he understood the products he was selling at a level most of his colleagues didn't. He started reading. Manuals, forums, technical documentation. Then he started building things. Then he started breaking them.
In the self-taught hacker community, breaking things is how you learn. You find a system, you probe it, you find where it gives way, and then you understand how it works better than the people who built it ever bothered to explain. Marcus was good at this in the way some people are good at languages — it came to him naturally, and he pursued it obsessively.
By 2005, he had a modest reputation in online security forums as someone who found vulnerabilities in consumer software and responsibly disclosed them to manufacturers. He'd never been paid for it. It was just what he did at night after his shift.
The Election That Started It
The 2004 presidential election produced a significant amount of public anxiety about electronic voting systems. Reports of machines flipping votes, of unexplained tallying anomalies, of proprietary software that couldn't be independently audited — the concerns were loud, and the official response was consistent: the systems were secure, the concerns were unfounded, and the people raising them didn't understand how the technology worked.
Marcus read those dismissals with the particular skepticism of someone who spent his evenings finding flaws in technology that manufacturers had also described as secure. He started reading everything he could find about voting machine architecture — technical documentation, FEC filings, academic papers, leaked internal reports. He wasn't a political person. He wasn't trying to prove any particular outcome was fraudulent. He was interested in the engineering claim: that these systems were secure.
He became convinced, fairly quickly, that the claim didn't hold up. The question was whether he could prove it.
Acquiring a Machine
In 2006, Marcus spent a significant portion of his savings — money he'd been setting aside to eventually take some community college courses — purchasing a decommissioned voting terminal through a government surplus auction. This was legal. Decommissioned machines were sold regularly, and while the practice raised its own security questions, it meant that Marcus had legitimate physical access to the hardware he wanted to examine.
What he found over the following eight months of methodical testing was not subtle. The machine ran a version of Windows that had not been patched against known vulnerabilities since before the machine's certification. The memory card interface could be accessed without breaking any physical seals. Vote tallying software could be modified in ways that would not be detectable by standard audit procedures. The wireless components — components that election officials had publicly stated were not present — were present.
Marcus documented everything. He wrote it up clearly, in language he tried to make accessible to non-technical readers. He sent it to the machine's manufacturer. He sent it to the relevant state election board. He sent it to two federal agencies.
The responses he received were variations on a theme: his findings had been reviewed, they did not represent actual vulnerabilities in real-world deployment conditions, and he should be aware that unauthorized testing of election equipment could have legal implications.
The Years Nobody Listened
This is the part of the story that tends to get compressed in the version where Marcus eventually becomes a trusted advisor to state election officials and testifies before a Senate subcommittee. The compression is understandable — the middle part is mostly just a man being ignored — but it's also where the actual character of the story lives.
For three years, Marcus kept finding things and kept telling people about them. He presented at small security conferences where the audience was sympathetic but powerless. He connected with a handful of academic researchers who took his work seriously enough to cite it in papers that themselves went largely unread by policymakers. A technology journalist wrote a piece about his findings in 2008 that generated a brief flurry of interest before being buried under the news cycle.
He was called a conspiracy theorist, a crank, and — in one particularly memorable exchange at a public forum — a "self-styled expert" by a state official who had, Marcus noted afterward, a degree in public administration and no apparent background in systems security.
He kept working retail. He kept testing machines. He got better at explaining what he found.
When the Room Finally Changed
The shift came, as it often does, from an unexpected direction. In 2009, a university research team attempting to replicate some of Marcus's documented findings not only confirmed them but extended them, identifying additional vulnerabilities Marcus hadn't found. The team's paper cited Marcus's earlier work extensively. It landed differently than his disclosures had — it had institutional letterhead, peer review, and authors with faculty positions.
Marcus wasn't bitter about it. He was practical about it. "If that's what it takes for someone to actually fix the problem," he told a reporter, "then I'm glad the paper exists."
What followed was a gradual, sometimes awkward integration of Marcus into the world of election security policy. He was brought in, initially informally and then officially, as a consultant to state-level security reviews in three states. He testified before a Senate subcommittee in 2011. He helped develop testing protocols that are now part of federal certification guidelines for electronic voting systems.
He still doesn't have a college degree. He has, at this point, found and responsibly disclosed more significant vulnerabilities in voting infrastructure than most credentialed researchers in the field. His lack of formal training — the thing that made officials dismiss him for years — is also, by his own analysis, part of why he saw what they missed. He came to the machines without assumptions about what was supposed to be there. He just looked at what was actually there.
What Outsiders Can See
There's a pattern that shows up repeatedly in the history of security research: the people who find the most significant vulnerabilities are often the ones who weren't trained to assume the system was basically sound. Marcus Teel looked at voting machines the way he'd always looked at technology — as a collection of components that could fail, could be manipulated, and deserved to be tested rather than trusted.
The establishment's resistance to his findings wasn't entirely cynical. Some of it was genuine institutional confidence in systems that had been certified and reviewed and approved. But certification processes are only as good as the questions they ask, and the questions tend to be shaped by what the people writing them already believe is possible.
Marcus believed different things were possible. He turned out to be right.
That's not a comfortable story for the institutions involved. But it's a useful one for anyone who's ever been told that their lack of credentials disqualifies their observations. Sometimes the person without the right background is the only one asking the right questions.