51精品视频

Tags
  • Institute for Cyber Law, Policy, and Security
  • Innovation and Research
Features & Articles

51精品视频 Cyber Expert Discusses Security, Integrity Concerns Ahead of Upcoming Elections

woman walking into a brick polling place building with a VOTE HERE sandwich board outside
With midterm elections just over a week away, hundreds of thousands of new and newly invigorated voters are expected to show up at the polls across the nation while many election security issues remain unresolved.

In Pennsylvania, for example, 201,331 new voter applications were approved the week of Oct. 15 alone, according to the Pennsylvania Department of State. And many of those voters 鈥 approximately eight out of 10 鈥 will cast ballots on machines that offer no auditable paper record that聽could prevent the detection of a successful hacking or even benign error. This issue is emblematic of the potential threat to election security in systems across the U.S.

鈥淭he sophistication of nation-state hackers and cyber criminals is only increasing," said , founding director of the 51精品视频 Institute for Cyber Law, Security, and Policy. "We must act with the urgency that this threat to our democracy requires and improve the security of our election architecture.鈥

Hickton, along with聽Grove City College President Paul McNulty, convened the independent, bipartisan this year with support from The Heinz Endowments and the Charles H. Spang Fund of The 51精品视频sburgh Foundation. The commission鈥檚 goal is to assess the cybersecurity of Pennsylvania鈥檚 election architecture, including voting machines and back-end election management systems, the voter registration system and resilience and recovery in the instance of a cyberattack.

The commission recently released a set of urging immediate actions prior to this year鈥檚 midterm elections and is set to release a full report early next year.

Warnings to legislators

In September, Hickton and McNulty offered testimony to the Senate State Government Committee on voting systems. In October, they presented testimony to the Pennsylvania House State Government Committee to outline specific cybersecurity risks associated with voter registration systems.

The testimony noted聽that Pennsylvania鈥檚 Statewide Uniform Registry of Electors (SURE) system is more than a decade old and was not initially designed to withstand today鈥檚 cybersecurity threats. SURE uses personal data such as Social Security and drivers鈥 license numbers to authenticate registered voters. Actors seeking to create fake voter registrations can find that information through illegal websites and use it in conjunction with the publicly available state voter file and SURE鈥檚 own polling place location tool.

Hickton at a podium in a gray suit
Another concern noted was the potential for Distributed Denial of Service (DDoS) attacks on voter registration and election聽reporting sites that could disrupt voting or interfere with how preliminary vote totals are reported.

鈥淪uccessful attacks to the system could create substantial administrative challenges for election officials and frustrate voters in a way that could depress turnout. And such an attack could undermine faith in the Commonwealth鈥檚 elections and erode public trust in democracy 鈥 outcomes that must be guarded against,鈥 read聽the testimony from Hickton and McNulty.

The testimony recommended replacing the SURE system as soon as possible and adding another layer of authentication, such as having voters identify information they provided during the application process, into the voter registration system to prevent fraud. It also suggested stronger encryption of voter data and sending paper notifications to voters to verify changes of address made online.

The call to replace the dated SURE system echoes interim recommendations the commission made in September to replace Direct Recording Electronic聽voting machines that lack voter-verifiable paper audit trails with machines using voter-marked paper ballots. It also suggested the state and federal government should fund聽counties鈥 efforts to replace the machines and highlighted following vendor selection and management best practices to avoid vulnerabilities through the supply chain.

The testimony noted聽that Pennsylvania鈥檚 Statewide Uniform Registry of Electors (SURE) system is more than a decade old and was not initially designed to withstand today鈥檚 cybersecurity threats.

The report and testimony applaud the state鈥檚 directive by Acting Secretary of State Robert Torres聽that all counties must have voter-verifiable paper record voting systems selected by Dec. 31, 2019, and preferably in place earlier, in time for the November 2019 off-year election. The report and testimony also highlight the sense of urgency that comes with replacing the systems, as well as聽the importance聽of state and federal funding for the effort.

The state directive was issued in April. Since that time, Susquehanna County, which was already using machines with paper ballots, has been the only county in the state to purchase a voting management聽system.

鈥淲e recognize that the General Assembly and counties have many funding priorities. The County Commission Association of Pennsylvania estimates the cost for replacing voting machines to be $125 million statewide. The majority of Pennsylvania鈥檚 current voting machines leave the integrity of our Commonwealth鈥檚 vote at risk. This is unacceptable. Compared to the magnitude of this risk, $125 million is a relative bargain,鈥 reads the election security commission鈥檚 interim report.