Hackers may 'discredit' US electoral process

Experts warn that disruption to electoral process is more likely than widespread hack

Concerns that a mass cyberattack will hit the US during today's Presidential Election may be ill-founded, but a risk of disruption is still high according to security experts. 

The likelihood that a cyber attack would affect overall results is extremely low, but authorities should still be cautious of attacks attempting to "discredit the electoral process in critical states", according to security experts at the University of Michigan.

"Unless the election is extraordinarily close, it is unlikely that an attack will result in the wrong candidate getting elected," said Matt Bernhard and professor J Alex Halderman.

However, they warn the risk that the election could still be disrupted should still be taken very seriously.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The majority of voting in the US is done by electronic booths, which are disconnected from the internet and present a significant hurdle for any hackers. A coordinated attack on the voting system is near-impossible and therefore it is much more likely group would target specific close-run states.

The US Government has already started a 'cyber hygiene' campaign on voting systems in every state, with security officials ready to intervene if an area becomes compromised.

One cause for concern is the discrepancy of technology available between voting areas, with many states opting for touch screen booths, or direct-recording electronic voting machines (DREs).

"Vulnerabilities in DREs have been thoroughly documented over the past decade, and it is will established that they carry an elevated risk of hacking," said Bernhard. "Most DREs do not produce a physical record of each vote, so they provide little opportunity to detect or correct computer-based fraud."

Bernhard and Halderman have identified some key 'hack states' where there is a mix of poor security and a tight presidential race (highlighted in yellow).

"Nevada, Pennsylvania, Ohio, and Colorado top the list of states to watch out for tomorrow. Together they account for just under 10% of electoral votes," said Bernhard and Halderman.

Advertisement - Article continues below

States such as Texas, Kentucky and New Jersey are considered similarly at risk of hacking, but are firmly declared for one side.

"If a state uses insecure electronic voting machines in more than half of its districts... or sees a majority of precincts that indicate extreme difficulty finding poll works, we consider it at-risk."

Other attempts to disrupt the process, such as power surges, DDoS attacks or hacks on voter registration databases are all possibilities, according to the researchers.

"Fortunately, most precincts have fallback plans in the case of a complete failure of infrastructure, and in all likelihood an election result would still be generated in the case of a large-scale cyberattack," said Bernhard.

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/policy-legislation/data-protection/354454/box-ceo-most-internet-users-will-ditch-privacy-for-online
data protection

Box CEO: Most internet users will ditch privacy for online services

3 Jan 2020
Visit/business/business-strategy/354445/what-tech-does-it-take-to-make-a-business-succeed-in-the-us
Business strategy

What tech does it take to make a business succeed in the US?

3 Jan 2020
Visit/infrastructure/network-internet/354446/what-is-google-fiber
Network & Internet

What is Google Fiber?

2 Jan 2020
Visit/security/privacy/354444/what-is-the-california-consumer-privacy-act-ccpa
privacy

What is the California Consumer Privacy Act (CCPA)?

31 Dec 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/security/cyber-security/354468/if-not-passwords-then-what
cyber security

If not passwords then what?

8 Jan 2020
Visit/policy-legislation/31772/gdpr-and-brexit-how-will-one-affect-the-other
Policy & legislation

GDPR and Brexit: How will one affect the other?

9 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020