sb-eu logo
Story image

State-sponsored election hacks are acts of cyber warfare - survey

11 Sep 2017

Most IT security professionals see state-sponsored attacks on elections as acts of cyber war and have huge impacts on confidence in the democratic process, according to a new survey.

At the US Black Hat conference in July, Venafi conducted a study which found that 78% of respondents said they would deem an act as cyber war if a nation-state was behind a successful or attempted hack of another country’s election.

Nation states have already been behind some major election targeting. The United States NSA found that Russia had attacked an election systems provider VR systems before last year’s election.

60% of respondents believe that hackers could alter election results and 27% believe attackers have already done so.

“The definition of an act of war is an action by one country against another which is an immediate threat to peace,” comments Venafi CEO Jeff Hudson.

“An attempt at election hacking could easily be considered an act of cyber war. The intent is to undermine the foundation of government, which is responsible for protecting the country. Elections are being targeted by cyber attacks, and the potential repercussions of election hacking cannot be understated. Malicious actors have the ability to alter voting databases, delay vote counts and subvert trust in the election process,” Hudson continues.

Attendees at security conference DEF CON 2017 were also discover and exploit vulnerabilities in five different voting machine types within 24 hours.

The conference featured a ‘voting machine village’ which comprised 30 different voting machines used in US elections. Machines included Sequoia AVC Edge, AccuVote TXS, Diebold Expresspoll 4000 and E-poll book.

Attendees were encouraged to hack the devices. The E-poll book machine was compromised in one hour. Another attendee discovered the OpenSSL CVE-2011-4019 vulnerability within the Diebold Expresspoll 4000 device, which compromised the entire machine.

“One user specifically calls out the use of ‘self-signed’ certificates still being used in machines. We see similar issues in IoT devices, where the manufacturer should be putting trusted CA issued certificates and rotating them. However, many organizations ignore this because they don’t have an easy way to do this. Instead, they simply embed a self-signed certificate,” comments Nick Hunter, Venafi senior digital trust manager.

Those systems that use self-signed certificates are targeted more because they are less trustworthy. If they are compromised, their identities can’t be validated.

“The machines it connects to will blindly trust the compromised system. And once a trusted session is established, all communication between machines is compromised,” Venafi concludes in a blog.

Story image
Check Point exposes Android malware vendor using dark net to rebrand products
Check Point security researchers have exposed an Android malware vendor using a marketer on the dark net to rebrand its products, with the intention of supercharging business and throwing off security vendors. More
Story image
SMEs treading water against 'endless volley' of cyber-attacks — report
According to a new report from Cynet, these SMEs are resorting to outsourcing some aspects of their threat mitigation in order to safeguard IT assets, as a result of the heightened risk of serious breaches.More
Story image
APAC secure content management market to hit $2.2 billion by 2024
The proliferation of cloud-based deployments will largely drive this, the report says, as the COVID-19 pandemic motivates more enterprises to move their workloads to the cloud and rely more on the internet. More
Story image
Trend Micro adds cloud-native container security to Cloud One Services Platform
Designed to ease the security of container builds, deployments and runtime workflows, the new service helps developers accelerate innovation and minimise application downtime across Kubernetes environments.More
Story image
Alibaba Cloud and LGMS tackle hybrid and multi-cloud security
Alibaba Cloud and LGMS, a cybersecurity consulting company, are teaming up to tackle the challenge of security around digital transformation and hybrid cloud.More
Story image
DDoS ransom attacks flare up again after brief hiatus
The second wave of attacks in December and January targeted organisations that were hit the first time and did not respond or pay the ransom. More