Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

How Secure are our Voting Systems for November 2018?

100%
0%
inShareLink =>http://www.darkreading.com/threat-intelligence/how-secure-are-our-voting-systems-for-november-2018/v/d-id/1332822inSite =>darkreading

Anomali CEO Hugh Njemanze discusses the importance of sharing threat intelligence across the countrys highly decentralized voting systems to safeguard the integrity of upcoming elections.

Learn more about how to defend election security systems by downloading Anomali's whitepaper, Cybersecurity Challenges for State and Local Governments. Join the community by downloading your free STIX/TAXII solution today.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Some Guy
100%
0%
Some Guy,
User Rank: Moderator
10/22/2018 | 2:02:33 PM
Lack of Proof is NOT Lack of Attacks -- its proof of a growing problem
So the biggest falicy is that the reports of failed attacks somehow "Proves" that the election systems are safe.

It does not.

All it proves is that we saw some failed attacks. And if you think about it, if the attacks are successful, they are going to erase their footprints, so how would you know?

So here, we can just borrow from Quality Assurance over the last 50 years. In Quality Control, we know that the number of defects that escape a factory into the field and become customer issues is directly proportional to the number of defects found in the factory. That's why everyone is so concerned about zero defects in the factory.

Applying that to security of the election infrastructure, all these failed attacks are actually proof that the likelihood that there have been successful attacks is increasing. Thus we should not be assured and complacent. This is actually evidence that we need to be more vigilant and figure out what we aren't doing that we aren't catching the attacks that have been succeeding.
<<   <   Page 2 / 2
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Look Beyond the 'Big 5' in Cyberattacks
Robert Lemos, Contributing Writer,  11/25/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I think the boss is bing watching '70s TV shows again!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16958
PUBLISHED: 2020-12-01
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
CVE-2020-8539
PUBLISHED: 2020-12-01
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to i...
CVE-2020-11990
PUBLISHED: 2020-12-01
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
CVE-2020-29315
PUBLISHED: 2020-12-01
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
CVE-2020-28971
PUBLISHED: 2020-12-01
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.