Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

How Secure are our Voting Systems for November 2018?

100%
0%
inShareLink => http://www.darkreading.com/threat-intelligence/how-secure-are-our-voting-systems-for-november-2018/v/d-id/1332822inSite => darkreading

Anomali CEO Hugh Njemanze discusses the importance of sharing threat intelligence across the countrys highly decentralized voting systems to safeguard the integrity of upcoming elections.

Learn more about how to defend election security systems by downloading Anomali's whitepaper, Cybersecurity Challenges for State and Local Governments. Join the community by downloading your free STIX/TAXII solution today.

Comment  | 
Print  | 
Comments
Threaded  |  Newest First  |  Oldest First
Some Guy
100%
0%
Some Guy,
User Rank: Moderator
10/22/2018 | 2:02:33 PM
Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
So the biggest falicy is that the reports of failed attacks somehow "Proves" that the election systems are safe.

It does not.

All it proves is that we saw some failed attacks. And if you think about it, if the attacks are successful, they are going to erase their footprints, so how would you know?

So here, we can just borrow from Quality Assurance over the last 50 years. In Quality Control, we know that the number of defects that escape a factory into the field and become customer issues is directly proportional to the number of defects found in the factory. That's why everyone is so concerned about zero defects in the factory.

Applying that to security of the election infrastructure, all these failed attacks are actually proof that the likelihood that there have been successful attacks is increasing. Thus we should not be assured and complacent. This is actually evidence that we need to be more vigilant and figure out what we aren't doing that we aren't catching the attacks that have been succeeding.
briannajones
50%
50%
briannajones,
User Rank: Apprentice
10/30/2018 | 12:51:48 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
i agree
dieumoa199608
50%
50%
dieumoa199608,
User Rank: Apprentice
1/2/2019 | 5:36:10 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
i agree
doctor91
50%
50%
doctor91,
User Rank: Apprentice
11/9/2018 | 8:00:11 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
De mon coté c'est bien sécurisé
jeffreyredfieldd
50%
50%
jeffreyredfieldd,
User Rank: Apprentice
11/22/2018 | 4:25:49 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
thanks
leslielorenzz
50%
50%
leslielorenzz,
User Rank: Apprentice
1/5/2019 | 8:27:48 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
great
instantassignmenthelp
50%
50%
instantassignmenthelp,
User Rank: Apprentice
1/17/2019 | 4:12:43 AM
Re: Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
yep
Pm4zv
100%
0%
Pm4zv,
User Rank: Apprentice
1/6/2019 | 8:43:37 PM
Does not inspire confidence.
The guest's mouth was saying "Yes, we're safer," while his visible body language was "Ummm...NOOOOO!!"

I agree.  I think that not only are the electornic voting systems no more secure than they've been for the past decade or two (at the least), but municipalities are woefully under-concerned and, thusly, woefully under-informed about the issues.

Paper ballots are, in my opinion, the answer.
w88betwin
0%
100%
w88betwin,
User Rank: Apprentice
1/23/2019 | 3:51:13 AM
Re: Does not inspire confidence.
Great!

#W88betwin
#W88
#link_w88
#link_vao_w88betwin

EmmaWilliam
50%
50%
EmmaWilliam,
User Rank: Apprentice
1/29/2019 | 12:13:23 PM
Re: Does not inspire confidence.
The overall communication is excellent...
Jill P
50%
50%
Jill P,
User Rank: Apprentice
1/19/2020 | 12:32:53 PM
Re: FredLuis
I absolutely agree and this particular article is spot on. I will also be visiting this site regularly for updates and new articles. 
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...
CVE-2021-21246
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/` endpoint there are no security checks enforced so it is possible to retrieve ar...