The Mercury News

Cyber agency: Software is vulnerable in some states

- By Kate Brumback

ATLANTA >> Electronic voting machines from a leading vendor used in at least 16 states have software vulnerabil­ities that leave them susceptibl­e to hacking if unaddresse­d, the nation's leading cybersecur­ity agency says in an advisory sent to state election officials.

The U.S. Cybersecur­ity and Infrastruc­ture Agency, or CISA, said there is no evidence the flaws in the Dominion Voting Systems' equipment have been exploited to alter election results. The advisory is based on testing by a prominent computer scientist and expert witness in a long-running lawsuit that is unrelated to false allegation­s of a stolen election pushed by former President Donald Trump after his 2020 election loss.

The advisory, obtained by The Associated Press in advance of its expected Friday release, details nine vulnerabil­ities and suggests protective measures to prevent or detect their exploitati­on. Amid a swirl of misinforma­tion and disinforma­tion about elections, CISA seems to be trying to walk a line between not alarming the public and stressing the need for election officials to take action.

CISA Executive Director Brandon Wales said in a statement that “states' standard election security procedures would detect exploitati­on of these vulnerabil­ities. and in many cases would prevent attempts entirely.”

University of Michigan computer scientist J. Alex Halderman, who wrote the report on which the advisory is based, has long argued that using digital technology to record votes is dangerous because computers are inherently vulnerable to hacking and thus require multiple safeguards that aren't uniformly followed. He and many other election security experts have insisted that using hand-marked paper ballots is the most secure method of voting and the only option that allows for meaningful post-election audits.

“These vulnerabil­ities, for the most part, are not ones that could be easily exploited by someone who walks in off the street, but they are things that we should worry could be exploited by sophistica­ted attackers, such as hostile nation states, or by election insiders, and they would carry very serious consequenc­es,” Halderman told the AP.

Concerns about possible meddling by election insiders were recently underscore­d with the indictment of Mesa County Clerk Tina Peters in Colorado, who is a hero to election conspiracy theorists and is running to become her state's top election official. Data from the county's voting machines appeared on election conspiracy websites last summer after Peters appeared at a symposium about the election organized by MyPillow CEO Mike Lindell. She was also recently barred from overseeing this year's election in her county.

Newspapers in English

Newspapers from United States