> I am not seeing how the request system is vulnerable.
Here's the scenario: I obtain your SSN, Name and Address to request your ballot to my address (either in the bussing example through your explicit permission or through the nefarious example like using Equifax 2017-2018 Data), then I fill it in at my address, and then mailed it in.
(Edit: to be clear, you have only provided the information to start the ballot process, or I obtained it nefariously, and submitted a ballot without your presence and pen to paper)
That's not a vulnerability? I guess I have a weird definition... I'm saying that's not what I expect when I hear someone 'voted.'