theDocumentId => 1332822 How Secure are our Voting Systems for November 2018?

Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

How Secure are our Voting Systems for November 2018?

100%
0%

Anomali CEO Hugh Njemanze discusses the importance of sharing threat intelligence across the countrys highly decentralized voting systems to safeguard the integrity of upcoming elections.

Learn more about how to defend election security systems by downloading Anomali's whitepaper, Cybersecurity Challenges for State and Local Governments. Join the community by downloading your free STIX/TAXII solution today.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Some Guy
100%
0%
Some Guy,
User Rank: Moderator
10/22/2018 | 2:02:33 PM
Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
So the biggest falicy is that the reports of failed attacks somehow "Proves" that the election systems are safe.

It does not.

All it proves is that we saw some failed attacks. And if you think about it, if the attacks are successful, they are going to erase their footprints, so how would you know?

So here, we can just borrow from Quality Assurance over the last 50 years. In Quality Control, we know that the number of defects that escape a factory into the field and become customer issues is directly proportional to the number of defects found in the factory. That's why everyone is so concerned about zero defects in the factory.

Applying that to security of the election infrastructure, all these failed attacks are actually proof that the likelihood that there have been successful attacks is increasing. Thus we should not be assured and complacent. This is actually evidence that we need to be more vigilant and figure out what we aren't doing that we aren't catching the attacks that have been succeeding.
<<   <   Page 2 / 2
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-37443
PUBLISHED: 2021-07-25
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
CVE-2021-37444
PUBLISHED: 2021-07-25
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Au...
CVE-2021-37445
PUBLISHED: 2021-07-25
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
CVE-2021-37446
PUBLISHED: 2021-07-25
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
CVE-2021-37447
PUBLISHED: 2021-07-25
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.