California & Florida Voter Websites Vulnerable To Hackers

Two cyber security firms sent the Department of Homeland Security (DHS) a troubling report in July this year that described a possible vulnerability in the online voter registration systems in dozens of counties in California and Florida. 

Many states, including Florida, make voters' information, including their names and party affiliations, easily accessible to members of the public who request it. Iranian intelligence was responsible for a recent campaign of emails sent to intimidate Florida voters, the FBI announced recently, adding that Russia was also working to influence the election

Now the Director of National Intelligence John Ratcliffe has announced that Russian and Iranian hackers had used some voter registration information in a bid to send misinformation to voters and sow discord ahead of the election. 

Both Iran and Russia had obtained some Americans' voter registration information, Ratcliffe said. Last year, a cybersecurity company found a software flaw in Riverside County in California voter registration lookup system, which it believes could have been the source of the breach.

The cyber security company, RiskIQ, said it was similar to the vulnerability that appears to have allowed hacks by Russian military hackers.The election threat report that flagged the vulnerability was written by cybersecurity experts  RiskIQ and  Northrop Grumman compared voter registration websites around the country with those that appeared to have been hacked in 2016. 

Administration officials have confirmed publicly that they believe that several counties in Florida, the State of Illinois Board of Elections, and possibly several counties in California had been victims of a hacking campaign four years ago.

The RiskIQ / Northrop Grumman report found that dozens of counties in Florida had voter registration websites that had lots of similarities to those in Riverside County in 2016. The report also raises the concern that these Florida counties could potentially be even more vulnerable than Riverside County was four years ago because they all share the same website management system. So if a hacker is inside one website he or she could have access to all the others too. 

In May, the FBI briefed Florida lawmakers on which of their 67 counties were successfully breached back in 2016. The officials were not allowed to divulge what they had learned, but they stressed that there was no evidence that cyber attacks changed any votes. "The actors got loud and essentially shut down the voter registration database, and that called attention to the problem," said Neil Jenkins, Chief Analytic Officer at the Cyber Threat Alliance

The report also looked at the websites' vulnerability to a particular kind of hack, something called a Padding Oracle Exploit (POE)  It was popular with hackers over a decade ago and is used to decrypt encrypted information. One of the concerns laid out in the report is that bad actors could use a POE to decrypt credentials to give themselves administrator access to the voter registration website.

Armed with this type of access hackers could potentially plant malware, change code, and even insert errors into the data.

The report also said, however, that the websites could have been compromised before the migration happened. The last voter website to migrate to a new operating system did so in 2019. The report says that the DHS do an audit of the Florida voter registration websites to make sure some vulnerability didn't accidentally slip in. However, DHS officials might hesitate to address details of the report or contact local officials about its findings because they haven't seen any indication that this hack is imminent.

As a general matter, local officials are unlikely to patch their systems against a possible vulnerability this close to the election. The last thing election officials would want to do just a week before their big day, he said, is to patch a website against a vulnerability that might not be severe and then find themselves watching helplessly when the patch makes their website crash. 

NPR:      NBC News:      Tallahassee Democrat:        NBC:   

You Might Also Read: 

Foreign Influence In The American Election Of 2020 Is Declining

 

« Cyber Spying Laws Are Changing
Securing AI In Military Systems »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Frazer-Nash Consultancy

Frazer-Nash Consultancy

Frazer-Nash is a leading engineering, systems and technology company. Areas of expertise include information security and cyber security.

Global Forum on Cyber Expertise (GFCE)

Global Forum on Cyber Expertise (GFCE)

GFCE is a global platform for countries, international organizations and private companies to exchange best practices and expertise on cyber capacity building.

GraVoc

GraVoc

GraVoc is a technology-consulting firm committed to solving business problems for customers through the development, implementation, & support of technology-based solutions.

Option3

Option3

Option3 (formerly Option3Ventures - O3V) primarily seek control investments in the growing cybersecurity mid-market, seeking to build champions with the scale to bring cutting-edge products to market.

e360

e360

e360 (formerly Entisys360) is an award-winning IT consultancy specializing in advanced IT infrastructure, virtualization, security, automation and cloud first solutions.

Cyber Risk Institute (CRI)

Cyber Risk Institute (CRI)

CRI is a not-for-profit coalition of financial institutions and trade associations working to protect the global economy by enhancing cybersecurity and resiliency through standardization.

Q6 Cyber

Q6 Cyber

Q6 Cyber is an innovative threat intelligence company collecting targeted and actionable threat intelligence related to cyber attacks, fraud activity, and existing data breaches.

SHe CISO Exec

SHe CISO Exec

SHe CISO Exec is a sustainable global training and mentoring platform in information security and leadership.

Firmus

Firmus

As the leading penetration testing services provider in Malaysia, Firmus evaluates the ability of your internal or external information assets to withstand attacks.

CommandK

CommandK

CommandK provides companies with infrastructure to protect their sensitive data. Built-in solutions to prevent data-leaks and simplify governance.

AArete

AArete

AArete is a global management and technology consulting firm specializing in strategic profitability improvement, digital transformation, and advisory services.

Papua New Guinea National Cyber Security Centre (PNG NCSC)

Papua New Guinea National Cyber Security Centre (PNG NCSC)

PNG NCSC is a jointly funded initiative enabling PNG to benefit with the most advanced cyber protection of its critical information and communications technology infrastructure.

KnoTra Global

KnoTra Global

KnoTra Global is a next-generation Managed Service provider with a portfolio of services including Cybersecurity Solutions, Network Management, IT Leadership, and Day-to-Day Helpdesk and IT services.

Secuvy

Secuvy

Secuvy leads in data security, privacy, compliance, and governance, offering a unified platform for proactive data discovery, management, protection, and enhanced data value.

Waterleaf International

Waterleaf International

Waterleaf provide advanced network and cybersecurity solutions - informed by data sciences. Transforming Connectivity, Security and Information for Municipalities, Government & Enterprise.

Swick Technologies (SWICKtech)

Swick Technologies (SWICKtech)

SWICKtech offer IT managed services to increase IT security, stability, and performance for your organization.