2 years, 10 months ago

Cyber agency: Voting software vulnerable in some states

ATLANTA — Electronic voting machines from a leading vendor used in at least 16 states have software vulnerabilities that leave them susceptible to hacking if unaddressed, the nation’s leading cybersecurity agency says in an advisory sent to state election officials. CISA Executive Director Brandon Wales said in a statement that “states’ standard election security procedures would detect exploitation of these vulnerabilities and in many cases would prevent attempts entirely.” Yet the advisory seems to suggest states aren’t doing enough. Halderman said it’s an “unfortunate coincidence” that the first vulnerabilities in polling place equipment reported to CISA affect Dominion machines. He called Halderman’s claims “exaggerated.” Dominion has told CISA that the vulnerabilities have been addressed in subsequent software versions, and the advisory says election officials should contact the company to determine which updates are needed. Halderman said that as far as he knows, “no one but Dominion has had the opportunity to test their asserted fixes.” To prevent or detect the exploitation of these vulnerabilities, the advisory’s recommendations include ensuring voting machines are secure and protected at all times; conducting rigorous pre- and post-election testing on the machines as well as post-election audits; and encouraging voters to verify the human-readable portion on printed ballots.

Associated Press

Discover Related