Iowa Election App Vulnerable To Hackers

The US media only recently  learned that the Iowa Democratic Party planned to use a mobile app to report the Democrat Presidential Candidate caucus  results in their state, but the party refused to reveal details about the app. 

Now a fault in the smartphone app used to count and report votes from individual precincts has caused a severe delay to the results from Iowa  being made known. 

A  closer look shows that the App had potentially very serious problems that, so far as is presently known, did not come into play. These problems mean the App was  vulnerable to hacking.

The Democrats didn’t publish the app’s source code for independent security researchers to inspect. Nor did they give any information about how thoroughly the app had been tested which apparently it had not been very thoroughly tested. At the time the party wouldn’t even name the vendor that it hired to develop the app, a litlle-known firm named Shadow Inc. saying that doing so could inadvertently help potential cyber attackers.

Elected officials couldn’t get answers, either. The office of Democrta Senator for Oregon. Ron Wyden asked the Democratic National Committee for details about the app three times in lead-up to the Iowa caucuses, but the requests were ignored, 

The App was so insecure that vote totals, passwords and other sensitive information could have been intercepted or even changed, according to officials at Massachusetts-based Veracode, a security firm that reviewed the software.

A lack of adequate safeguards, including transmissions to and from the phone means that data was left largely unprotected. An attack would require some degree of sophistication, but it would have been much easier to pull off had a precinct worker used an open Wi-Fi hotspot to report votes instead of a mobile phone data plan.

To date there is no evidence that hackers intercepted or tampered with caucus results.

The turmoil over counting the votes in Iowa has raised fresh doubts about the election’s integrity. The question that has been asked is was the Iowa caucus chaos is a hit job by election-meddling Russians. The morning after caucus-goers filed into high-school gyms across Iowa, the state’s Democratic Party is still unable to produce results. The app it developed for precisely this purpose seems to have crashed.

The party was questioned by experts about the wisdom of using a secretive app that would be deployed at a crucial juncture, but the concerns were brushed away. Worried about Russian hacking, the party addressed security in all the wrong ways: It did not open up the app to outside testing or challenge by independent security experts.

If the App developer, Shadow Inc. had opened up the app to experts, they likely would have found many bugs, and the app would have been much stronger as a result. An app that is downloaded onto the phones of thousands of precinct officials across Iowa, with varying degrees of phone security and different operating systems, could not be fully protected against Russian or any other hackers. 

Underground “hacks for sale" allow remote attackers to infiltrate phones, especially ones without the latest system updates, as is the case for many Android phones. 

Creating a more hardened phone network is possible, but that would require issuing secure phones to every official, and providing training and technical support. There is no indication that any of that was done.Even without a more substantial reform of the complex and demanding caucus process, a simple adversarial confirmation system, which is a process used by many countries, would have worked well.

The US has experienced previous difficulties with obsolete election technology. The National Academy of Sciences released a lengthy report about it last year, complete with evidence-based recommendations for every step of the electoral process. 

The US Department of Homeland Security offered to test the app for the Iowa Democratic Party, but the party never took the government up on it, according to a US official familiar with the matter who was not authorised to speak publicly. The official said the party did participate in a dry run, known as a tabletop exercise.  
 

DefenseOne:       ProPublica:        The Intercept:

You Might Also Read:

Foreign Cyber Intrusions On The USA:

 

« Preparing Your Employees & Business Systems For A Cyber Attack
Leaked Report: The United Nations Was Hacked »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

BH Consulting

BH Consulting

BH Consulting we are a vendor independent consulting firm providing market leading range of information security services focused on data protection and cybersecurity.

Qualys

Qualys

Qualys is a pioneer and leading provider of cloud security and compliance solutions.

Research Institute in Trustworthy Industrial Control Systems (RITICS)

Research Institute in Trustworthy Industrial Control Systems (RITICS)

RITICS is one of three Research Institutes formed as part of the UK National Cyber Security Strategy.

Westminster eForum

Westminster eForum

Wesrtminster eForum runs a series of conferences on matters relating to the UKs Digital Strategy. Topics include Smart Cities and Cyber Security.

Tempered Networks

Tempered Networks

Tempered Networks delivers the first purpose-built platform for IIoT cybersecurity that allows customers to connect and secure devices in minutes without the need for specialized skills.

Asseco Group

Asseco Group

Asseco Poland stands at the forefront of the multinational Asseco Group. We are a leading provider of state-of-the-art IT solutions in Central and Eastern Europe.

Penacity

Penacity

Penacity, LLC provides strategic consulting technology services and Information Security Services to commercial and government organizations.

Cervello

Cervello

Cervello is a leading provider of comprehensive and proven solutions to protect railways against cyber attacks.

Defensity

Defensity

Defensity offer bespoke & pre packaged IT Security Solutions for Small business to help companies reduce overall IT related risk.

Salt Cybersecurity

Salt Cybersecurity

Salt Cybersecurity offer a four-pronged approach to information security that includes Custom Security Policy, Vulnerability Assessment, Threat Detection, and Security Awareness Training.

MVP Tech

MVP Tech

MVP Tech designs and deploys next generation infrastructures where Security and Technology converge.

Corsica Technologies

Corsica Technologies

Corsica Technologies is recognized as one of the top managed IT and cybersecurity service providers. Our integrated IT and cybersecurity services protect companies and enable them to succeed.

SEIRIM

SEIRIM

SEIRIM delivers cybersecurity solutions in Shanghai China specializing in Web Application Security, Network Security for SME's, Vulnerability Management, and serving as Managed Security as a Service.

National Renewable Energy Laboratory (NREL) - USA

National Renewable Energy Laboratory (NREL) - USA

NREL is transforming energy through research, development, commercialization, and deployment of renewable energy and energy efficiency technologies.

System360

System360

System360 is one of Houston's top suppliers of network administration, design, security, and support services.

Atlantica Digital

Atlantica Digital

Atlantica design and create highly innovative software solutions and solid, scalable and secure IT infrastructures for a constantly evolving market.