Iowa Election App Vulnerable To Hackers

The US media only recently  learned that the Iowa Democratic Party planned to use a mobile app to report the Democrat Presidential Candidate caucus  results in their state, but the party refused to reveal details about the app. 

Now a fault in the smartphone app used to count and report votes from individual precincts has caused a severe delay to the results from Iowa  being made known. 

A  closer look shows that the App had potentially very serious problems that, so far as is presently known, did not come into play. These problems mean the App was  vulnerable to hacking.

The Democrats didn’t publish the app’s source code for independent security researchers to inspect. Nor did they give any information about how thoroughly the app had been tested which apparently it had not been very thoroughly tested. At the time the party wouldn’t even name the vendor that it hired to develop the app, a litlle-known firm named Shadow Inc. saying that doing so could inadvertently help potential cyber attackers.

Elected officials couldn’t get answers, either. The office of Democrta Senator for Oregon. Ron Wyden asked the Democratic National Committee for details about the app three times in lead-up to the Iowa caucuses, but the requests were ignored, 

The App was so insecure that vote totals, passwords and other sensitive information could have been intercepted or even changed, according to officials at Massachusetts-based Veracode, a security firm that reviewed the software.

A lack of adequate safeguards, including transmissions to and from the phone means that data was left largely unprotected. An attack would require some degree of sophistication, but it would have been much easier to pull off had a precinct worker used an open Wi-Fi hotspot to report votes instead of a mobile phone data plan.

To date there is no evidence that hackers intercepted or tampered with caucus results.

The turmoil over counting the votes in Iowa has raised fresh doubts about the election’s integrity. The question that has been asked is was the Iowa caucus chaos is a hit job by election-meddling Russians. The morning after caucus-goers filed into high-school gyms across Iowa, the state’s Democratic Party is still unable to produce results. The app it developed for precisely this purpose seems to have crashed.

The party was questioned by experts about the wisdom of using a secretive app that would be deployed at a crucial juncture, but the concerns were brushed away. Worried about Russian hacking, the party addressed security in all the wrong ways: It did not open up the app to outside testing or challenge by independent security experts.

If the App developer, Shadow Inc. had opened up the app to experts, they likely would have found many bugs, and the app would have been much stronger as a result. An app that is downloaded onto the phones of thousands of precinct officials across Iowa, with varying degrees of phone security and different operating systems, could not be fully protected against Russian or any other hackers. 

Underground “hacks for sale" allow remote attackers to infiltrate phones, especially ones without the latest system updates, as is the case for many Android phones. 

Creating a more hardened phone network is possible, but that would require issuing secure phones to every official, and providing training and technical support. There is no indication that any of that was done.Even without a more substantial reform of the complex and demanding caucus process, a simple adversarial confirmation system, which is a process used by many countries, would have worked well.

The US has experienced previous difficulties with obsolete election technology. The National Academy of Sciences released a lengthy report about it last year, complete with evidence-based recommendations for every step of the electoral process. 

The US Department of Homeland Security offered to test the app for the Iowa Democratic Party, but the party never took the government up on it, according to a US official familiar with the matter who was not authorised to speak publicly. The official said the party did participate in a dry run, known as a tabletop exercise.  
 

DefenseOne:       ProPublica:        The Intercept:

You Might Also Read:

Foreign Cyber Intrusions On The USA:

 

« Preparing Your Employees & Business Systems For A Cyber Attack
Leaked Report: The United Nations Was Hacked »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

ITpreneurs

ITpreneurs

ITpreneurs provides IT training content, Instructors, Learning Infrastructure and services to IT Training providers.

DataGuidance

DataGuidance

DataGuidance is a platform used by privacy professionals to monitor regulatory developments, mitigate risk and achieve global compliance.

Metasploit

Metasploit

Metasploit penetration testing software helps find security issues, verify vulnerabilities and manage security assessments.

Brit

Brit

Brit PLC is a market-leading global specialty insurer and reinsurer, focused on underwriting complex risks including cyber, privacy and technology.

Ntrepid

Ntrepid

Ntrepid products provide protection from web threats and enable organizations to safely conduct their online activities.

Network Integrated Business Solutions (NIBS)

Network Integrated Business Solutions (NIBS)

NIBS is an IT services provider offering a range of services with the aim of simplifying and securing technology.

Marcus Donald People

Marcus Donald People

Marcus Donald People is a UK IT recruitment specialist covering the following sectors: Infrastructure & Cloud, Information Security, Development, Business transformation.

Crosser

Crosser

The Crosser Platform enables real-time processing of streaming or batch data for Industrial IoT, Data Transformation, Analytics, Automation and Integration.

Proton Data Security

Proton Data Security

Proton Data Security is a certified small business specializing in the design, manufacturing and sales of data security products for permanent erasure of hard drives, tapes and optical media.

Absio

Absio

Absio provides the technology you need to build data security directly into your software by default, and the design and development services you need to make it happen.

Two Six Technologies

Two Six Technologies

Two Six Technologies delivers R&D, innovation, productization and implementation expertise in cyber, data science, mobile, microelectronics and information operations.

Tego Cyber

Tego Cyber

Tego Cyber delivers a state-of-the-art threat intelligence platform that helps enterprises deploy the proper resolution to an identified threat before the enterprise is compromised.

Digital.ai

Digital.ai

Digital.ai empowers organizations to scale software development teams, continuously deliver software with greater quality and security.

Sansec Technology

Sansec Technology

Sansec Technology is dedicated to the research and development of cryptographic products and solutions for cyber security.

Dialog Enterprise

Dialog Enterprise

Dialog Enterprise is the corporate ICT solutions arm of Dialog Axiata, Sri Lanka’s leading connectivity provider.

CIS Secure

CIS Secure

CIS Secure is an innovator, integrator and expert advisor supporting the broadest portfolio of powerful, mission-specific C5ISR communications and cybersecurity solutions.