Hackers may 'discredit' US electoral process

Experts warn that disruption to electoral process is more likely than widespread hack

Concerns that a mass cyberattack will hit the US during today's Presidential Election may be ill-founded, but a risk of disruption is still high according to security experts. 

The likelihood that a cyber attack would affect overall results is extremely low, but authorities should still be cautious of attacks attempting to "discredit the electoral process in critical states", according to security experts at the University of Michigan.

"Unless the election is extraordinarily close, it is unlikely that an attack will result in the wrong candidate getting elected," said Matt Bernhard and professor J Alex Halderman.

However, they warn the risk that the election could still be disrupted should still be taken very seriously.

Advertisement
Advertisement - Article continues below

The majority of voting in the US is done by electronic booths, which are disconnected from the internet and present a significant hurdle for any hackers. A coordinated attack on the voting system is near-impossible and therefore it is much more likely group would target specific close-run states.

The US Government has already started a 'cyber hygiene' campaign on voting systems in every state, with security officials ready to intervene if an area becomes compromised.

One cause for concern is the discrepancy of technology available between voting areas, with many states opting for touch screen booths, or direct-recording electronic voting machines (DREs).

"Vulnerabilities in DREs have been thoroughly documented over the past decade, and it is will established that they carry an elevated risk of hacking," said Bernhard. "Most DREs do not produce a physical record of each vote, so they provide little opportunity to detect or correct computer-based fraud."

Bernhard and Halderman have identified some key 'hack states' where there is a mix of poor security and a tight presidential race (highlighted in yellow).

"Nevada, Pennsylvania, Ohio, and Colorado top the list of states to watch out for tomorrow. Together they account for just under 10% of electoral votes," said Bernhard and Halderman.

States such as Texas, Kentucky and New Jersey are considered similarly at risk of hacking, but are firmly declared for one side.

"If a state uses insecure electronic voting machines in more than half of its districts... or sees a majority of precincts that indicate extreme difficulty finding poll works, we consider it at-risk."

Other attempts to disrupt the process, such as power surges, DDoS attacks or hacks on voter registration databases are all possibilities, according to the researchers.

"Fortunately, most precincts have fallback plans in the case of a complete failure of infrastructure, and in all likelihood an election result would still be generated in the case of a large-scale cyberattack," said Bernhard.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/policy-legislation/34603/california-bans-police-use-of-facial-recognition-for-three-years
Policy & legislation

California bans police use of facial recognition until 2030

10 Oct 2019
Visit/policy-legislation/34586/us-blacklists-chinese-surveillance-firms-over-uyghur-muslim-abuse
Policy & legislation

US blacklists Chinese surveillance firms over Uyghur abuse

8 Oct 2019
Visit/security/34572/uk-and-us-plead-with-mark-zuckerberg-to-bin-encryption-plans
Security

UK and US plead with Mark Zuckerberg to bin encryption plans

4 Oct 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019