Good News About Voting Security

The hacking attempts haven’t slowed. The disinformation campaigns are ongoing. And the warning lights have been “blinking red” for a potential foreign operation aimed at disrupting the midterm elections, but the US survived.

But if there is anything positive to take away from Russia’s election interference in 2016, it’s this: America’s election infrastructure has never been more carefully monitored in the days, weeks, and months leading up to a nationwide vote, and voters themselves are more-wary than ever of foreign propaganda, masked as a political ad, or Twitter troll.

That heightened awareness is a key takeaway from a report published just one day before the election about hacking attempts on election infrastructure. 

The Boston Globe revealed on Monday 5th November that it had obtained leaked threat reports filed by state and local election officials across the country alerting federal agencies to cyber intrusions and other suspicious activity that appeared to be targeting voter registration databases, election officials, and election networks in the days before the midterms. 

One unnamed state, the threat reports don’t name states or detail specific incidents, successfully blocked more than 51,000 login attempts from foreign countries in a 24-hour period, the documents reportedly revealed. Some hackers even had “limited success.”

Yet voting and cybersecurity experts I spoke to seemed less alarmed than one might expect. “I’m heartened by this,” said David Becker, a former trial attorney in the Voting Section of the Department of Justice’s Civil Rights Division who now runs the Center for Election Innovation & Research. 

The coordination between the various levels of government in preparation for potential meddling in Tuesday 7th November’s election represents a major leap forward since 2016, when many states declined help from the Department of Homeland Security to secure their election systems and balked at declaring such systems “critical infrastructure.” 

Such a designation, which was finally made in January 2017, puts election infrastructure in the same category as the US power grid and financial sector, and gives states quicker access to classified threat information sharing. It also means that states can participate in joint-defense exercises. 

In addition, all 50 states have now opted in to the DHS-funded program that has allowed election officials to share information with each other and with the government. Many have enrolled in a DHS program that offers states computer- vulnerability scanning for their election systems.

But aging voting machines and outdated software are still a major problem, and Congress has not allocated nearly enough money, only $380 million has been appropriated for the whole country, to help states completely revamp their infrastructure, experts say. 

Only one state, Virginia, has completely replaced its electronic voting machines since 2016. And while Illinois has bolstered its cyber defenses since hackers infiltrated its voter database in 2016, its voting machines are still outdated and vulnerable to attack. 

According to NBC News, there are still counties in 14 states, including Georgia and Florida, whose voting districts have no paper backup for their electronic voting machines. That means it would be impossible to conduct a paper recount if necessary.

That’s particularly concerning because, two years on from Russia’s unprecedented interference, there is no sign that the threats are waning. 

In a joint statement released on Monday night, the DHS, Director of National Intelligence, FBI and DOJ warned that “Americans should be aware that foreign actors, and Russia in particular, continue to try to influence public sentiment and voter perceptions through actions intended to sow discord.” 

Senior Trump administration officials, including DHS Secretary Kirstjen Nielsen, FBI Director Chris Wray, and DNI Dan Coats, issued a similar warning during a rare joint press conference in August, “Russia attempted to interfere with the last election,” Wray said, “and continues to engage in malign influence operations to this day.” 

Days earlier, Missouri Democratic Senator Claire McCaskill, who is seeking re-election in a state that went for Trump in 2016, confirmed that Russians had tried to hack her senate computer network but were unsuccessful.

So far, however, the kind of massive hacking-and-leaking operation that took the law enforcement and intelligence communities by surprise in 2016 has not materialised. And, overall, the preparation and response to irregularities in the run up to the midterms has been reassuring, experts say.

The NSA has reportedly begun sending messages directly to Russian hackers, reminding them that they are being watched.

Those seeking to sow disinformation and wage information warfare, meanwhile, continue to prey upon social media users, despite their increased awareness of organised foreign-influence operations.

The Justice Department has already charged the first Russian with interfering in the midterms: Elena Khusyaynova, a 44-year-old Russian national who allegedly managed the finances of an election-interference campaign run out of the Internet Research Agency in St. Petersburg, code-named Project Lakhta. 

Facebook, which did not discover until late 2017 that the Russians had purchased hundreds of political ads that were seen by approximately 10 million users in 2016, revealed over the summer that it shut down Russian and Iranian accounts that were waging political influence campaigns to influence the midterms, and set up a “war room” where a team will monitor fake news and disinformation on Election Day. 

The Democratic Congressional Campaign Committee, meanwhile, successfully encouraged Twitter to delete more than 10,000 “bot” accounts that were posing as Democrats while discouraging people from voting in Tuesday’s midterms.

This is an increasingly common narrative among Russian bots and trolls, according to Brett Bruen, a former US Diplomat who served as Director of Global Engagement at the White House under President Obama. 

Defense One:

You Might Also Read:

Schoolboy Hacked Mock Florida Election Site In 10 Minutes

« Darktrace Describe The Alarming Future AI Attack Scenario
Don't Underestimate The Impact Of Phishing »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Frazer-Nash Consultancy

Frazer-Nash Consultancy

Frazer-Nash is a leading engineering, systems and technology company. Areas of expertise include information security and cyber security.

L3Harris United Kingdom

L3Harris United Kingdom

L3Harris UK (formerly L3 TRL Technology) designs and delivers advanced electronic warfare and cyber security solutions for the protection of people, infrastructure and assets.

Andrisoft

Andrisoft

Andrisoft develops WANGUARD, an anti-DDoS Software solution that monitors IP traffic using packet-based and flow-based Sensors, and protects networks

Marsh

Marsh

Marsh is a global leader in insurance broking and risk management and has been a leader in combatting cyber threats since their emergence.

Cryptus Cyber Security

Cryptus Cyber Security

Cryptus Cyber Security is an Information Security Training company providing advanced training and services to IT Professionals.

Picasso

Picasso

The Picasso project is focused on ICT Policy, Research and Innovation for a Smart Society: towards new avenues in EU-US ICT collaboration.

Data Shepherd

Data Shepherd

Data Shepherds primary focus is to protect your business. We achieve this by offering extensive and unique expertise in innovative IT and Cyber security solutions.

ATIS Systems

ATIS Systems

ATIS Systems offers first-class complete solutions for legal interception, mediation, data retention, and IT forensics.

Sikur

Sikur

Sikur have developed a communication platform that sets new boundaries for corporate privacy and security.

CybernetIQ

CybernetIQ

CLAW by CybernetIQ is the industry's most advanced SOAR platform helping unify all cybersecurity tools under one umbrella and providing organizations faster, better and more accurate cybersecurity.

Industrial Defender

Industrial Defender

Committed to ICS Cybersecurity. Industrial Defender provides a fully automated solution to discover, track and report on assets across your ICS footprint.

Progress Partners

Progress Partners

Progress Partners is a corporate advisory firm that works with buyers and sellers of emerging growth companies to complete M&A or private placement transactions. Our sectors include cybersecurity.

eCloudvalley Digital Technology

eCloudvalley Digital Technology

eCloudvalley Digital Technology is a born-in-the-cloud partner focused entirely on AWS services across APAC region.

Camelot Secure

Camelot Secure

Camelot Secure Secure360 platform is a holistic redefinition of what world-class cybersecurity strategies can be. Prepare. Protect. Deploy.

REAL Security

REAL Security

REAL Security is a market leader across the Adriatic region in value-added distribution in the field of IT Security & virtualisation.

NAM-CSIRT

NAM-CSIRT

NAM-CSIRT is a team established to contribute to the security and stability of critical infrastructure and critical information infrastructure of the Republic of Namibia.