Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • IT Management

    Russian Voter System Tampering the Result of Typical Weak Security

    Written by

    Wayne Rash
    Published June 8, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The recent disclosure of a document leak from the National Security Agency that contains details about the Russian hacking attempt on a vendor of voter registration software has the making of a spy thriller, even including a perpetrator with a name that might be right out of a James Bond spy thriller.

      But as bad as that leak was, the ease with which the Russians penetrated the voter registration software company’s security was worse. Worse yet was the ease at which the Russians penetrated some of the state election officials’ defenses.

      The theft of the top secret report on Russian hacking by a former NSA contractor with the unlikely name of Reality Winner is something that the intelligence agency always tries to prevent. But there are some things that even the best security can’t stop and bad faith on the part of a trusted individual is one of them.

      The U.S. Justice Department announced on June 5 that it had charged Winner with mailing a classified document that contained details of the Russian hack on a voter-registration system known as EViD to “The Intercept,” news website.

      It’s easy to criticize the NSA for allowing Winner to have access to such files, but in reality employees and contractors need access to classified information to do their jobs. Every now and then, there’s a failure in the system, which is what happened here.

      Last fall, however, a series of other system failures put the integrity of the 2016 election at risk. While it’s not clear that the Russians were able to were actually able to tamper with election results, the fact that they got access so easily is deeply troubling.

      There were two types of failings that gave the Russian hackers access. The first was a phishing attack against a vendor of voter registration software, VR Systems of Tallahassee, Florida. Someone in the targeted company clicked on a link that provided the hackers with access to a database containing the contact information of election officials in several states.

      The second attack was another phishing attack, this time with a payload of purported Microsoft Word files. Those emails were crafted to appear to be from the vendor of the voter registration software. The apparent goal was to provide access to voter registration records in several states and then to alter them in a way to create chaos on election day.

      Had the software vendor or the states involved had adequate security, the cyber-attack launched by the Microsoft Word files would not have been successful, which is apparently the case in at least some of the states. This may have been partly because the bogus emails used to approach the states were so blatantly phony that state officials recognized them as such and complained to the software vendor.

      But suppose the fake emails had been more expertly crafted. Would the states still have caught on? That would require an additional level of security, and at this point it’s not known whether there was another level of security to thwart this attack.

      But the apparently unsuccessful hacking attempt is behind us, so the next step is to find lessons to learn from the attempt. The first lesson is how to deal with a phishing attack. After all, if your employees don’t act on a phishing email, then nothing will come of it.

      This is one area that requires constant training. There’s currently no effectively way to filter out phishing emails, so your employees need to recognize a potential phishing attempt, and at the very least not act. Preferably, those employees should then notify your head of IT or head of security of the apparent attempt. That person can then take further action to prevent or render useless any further phishing attempts.

      Second, your security software needs to recognize the payloads and actions of the malware that may be included in a phishing email. Because the malware providers are trying to find ways to evade such detection, you can’t just buy an anti-virus product and hope for the best. You also need anti-malware software that recognizes the threat hidden inside the payload.

      It’s worth noting that the voter registration software company was fairly small, which may it was targeted by the Russian hackers. It’s a fact of life that many smaller companies have only a minimal IT staff, if they have any at all. They are even less likely to have an IT security staff, which makes them a very soft target and exactly what attackers are looking for.

      That small under-protected company can then lead the attackers to their larger partners by providing an attack pathway and by providing a credible disguise for phishing emails. In addition, attackers depend on those smaller companies not believing that they’re a potential target, which in turn makes them more susceptible to attacks.

      Just as in the case of constant training to handle phishing attacks, your employees also need to recognize other vulnerabilities where they’re the first line of defense. That means they need to be suspicious about releasing email addresses and phone numbers for executives and other senior employees for example. And remember, that release of information can come from phone calls as easily as from emails.

      While it’s probably impossible to block every attempt to extract information from any company, the ultimate goal is to make it sufficiently inconvenient that the attacker targets someone else. If enough companies make it really hard to get info, then eventually the attackers will try another line of work.

      Wayne Rash
      Wayne Rash
      https://www.eweek.com/author/wayne-rash/
      Wayne Rash is a content writer and editor with a 35-year history covering technology. He’s a frequent speaker on business, technology issues and enterprise computing. He is the author of five books, including his most recent, "Politics on the Nets." Rash is a former Executive Editor of eWEEK and a former analyst in the eWEEK Test Center. He was also an analyst in the InfoWorld Test Center and editor of InternetWeek. He's a retired naval officer, a former principal at American Management Systems and a long-time columnist for Byte Magazine.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×