Get Even More Visitors To Your Blog, Upgrade To A Business Listing >>

Was GA’s Election System Hacked in 2016?


When the Department of Homeland Security (DHS) notified 21 States in 2017 that they had been targeted by Russian Hackers intent on Interfering with the 2016 U.S. Presidential Election, Georgia, despite having one of the most Vulnerable Voting Systems in the Country, was not among them. Trump Won the State by nearly 6 percentage points over Democrat Hillary Clinton.

This was odd because around the same time the Russians were targeting other States, a Security Researcher in Georgia named Logan Lamb discovered a serious Security Vulnerability in an Election Server in his State. The Vulnerability allowed him to Download the State’s Entire Database of 6.7 Million Registered Voters and would have allowed him or any other Intruder to Alter Versions of the Database Distributed to Counties prior to the Election. Lamb also found PDFs with Instructions and Passwords for Election Workers to Sign-In to a Central Server on Election Day as well as Software Files for the State’s ExpressPoll Pollbooks, the Electronic Devices used by Poll Workers to Verify Voters’ Eligibility to Vote before allowing them to Cast a Ballot.

The Unpatched and Misconfigured Server had been Vulnerable since 2014 and was Managed by the Center for Election Systems, a small Training and Testing Center that until recently occupied a former two-story House on the Kennesaw State University Campus. Until last year, the Center was responsible for Programming every Voting Machine across the State, raising concerns that if the Russians or other Adversaries had been able to penetrate the Center’s Servers as Lamb had done, they might have been able to find a way to Subvert Software Distributed by the Center to Voting Machines across the State.

But Georgia Secretary of State Brian Kemp, who was the only State Election Official to Refuse Security Assistance from the DHS prior to the Election, has insisted for more than a year that his State’s Voting Systems were never at risk in the 2016 Election, because DHS told him the Russians had not targeted Georgia. This changed on Friday, however, when the Justice Department Unsealed the Indictment against 12 Russian Intelligence Officers who oversaw an Operation that, the Department says, included Targeting County Websites in Georgia.

On or around Oct. 28th, 2016, Anatoliy Sergeyevich Kovalev and Aleksandr Vladimirovich Osadchuk, both Officers in the Russian Military assigned to Unit 74455, allegedly Conspired with others to Hack into Computers involved in U.S. Election Administration, according to the Complaint. This included Scoping out the Websites of Unidentified Counties in Iowa, Florida, and Georgia, to Identify Vulnerabilities they could use to access Back-End Servers. The Indictment doesn’t state directly, but implies, that the Servers were part of Infrastructure for County Election Offices.

Asked about this New Revelation, a Spokeswoman for the Georgia Secretary of State’s Office declined to address it directly, saying only that the Secretary of State’s own Office had never been Breached. “We have never been hacked, and according to President Trump and the Department Of Homeland Security, we have never been targeted,” Candice Broce wrote in an email. “Georgia has secure, accessible, and fair elections because [Secretary of State Brian] Kemp has leveraged private sector solutions for robust cybersecurity, well before any of those options were offered by the federal government.”

In truth, Kemp’s Office would not have been the most likely Target for Russian Hackers, since his Office has had little to do with the Administration of Elections in Georgia since at least 2002, when it Contracted that responsibility to the Center for Election Systems. For 15 years, it was well known that the Center was responsible for Training Election Workers, Programming the State’s Electronic Voting Machines before each Election and distributing the Voter Registration Database to Counties. The Center’s Servers would have been the ideal Target for Russian Hackers, says Marilyn Marks, Executive Director of the Coalition for Good Governance, the Group behind the Lawsuit against the Secretary of State. “These sophisticated agents certainly [would have known] that Georgia’s entire election programming and management system, including private voter data, was on a single central computer managed by Secretary of State Kemp’s contract agent at Kennesaw State University,” she said.

The Unpatched and Insecure Server that Lamb Breached weren’t the Center’s only problem. A Report produced by the University’s IT Department after the Lamb Breach found numerous other Security Problems as well. These Security Problems are all the more alarming, Marks and others say, because Georgia uses a Single Model of Touchscreen Voting Machine Statewide that Security Researchers have shown to be Vulnerable to Hacking. The Machines do not have a Paper Trail and therefore provide No Means of Conducting an Audit of their Election Results, an ideal scenario for anyone who wants to Subvert an Election. Marks and her fellow Plaintiffs in the Lawsuit want the State to Replace these Machines with ones that use Paper Ballots.

As part of their Discovery demands, they want to examine the Center’s Servers to see if anyone other than Lamb had Breached them prior to the 2016 Presidential Election or a Special Congressional Runoff Election that was held on June 20th the following year between Karen Handel, Kemp’s Predecessor as Secretary of State, and Jon Ossoff. With the revelations in Friday’s Indictment, Marks says an Examination of the Center’s Servers is more important than ever. “The indictment’s reference to Russians searching for Georgia vulnerabilities makes it all the more imperative that plaintiffs in the federal lawsuit be promptly granted the right to conduct forensic discovery on the remaining electronic records related to the server,” Marks said.

This might be difficult to do, however. Shortly after the Plaintiffs Filed their Lawsuit in July 2017, Technicians at Kennesaw State University Wiped the Center’s Servers Clean, Destroying any Evidence that might have been on them. Two Backup Servers also were Wiped a Month later, News the Plaintiffs learned only Months later after obtaining Emails that disclosed the Data Destruction. Kemp’s Office initially Distanced itself from the Destruction, accusing the Technicians of “ineptitude” for Wiping Servers that were part of Litigation. Kemp later said, however, that the Wiping had simply been Standard Operating Procedure performed any time Servers were taken out of Service.

The good news is that FBI Agents in Atlanta made a Mirror Image of the Server that Lamb Breached when they were Investigating his Intrusion, and the Plaintiffs are hoping the Judge overseeing their Case will Rule that they can Examine this Image. It’s unclear, however, whether the Image preserved everything that was on the Server and whether the Image still exists.

Marks says it’s astonishing how little Curiosity or Concern Kemp and Georgia’s Election Board have shown toward the Center’s Server. “The Russians would not have had to ‘hack’ or force their way in. The electronic door was wide open ... and KSU’s wiping of the server logs would have likely concealed their tracks. [It] appears that Kemp and the State Board prefer not to know [what may have happened on that server]. Nor do they want plaintiffs to find out, as they are continuing to block all attempts at litigation discovery.”










NYC Wins When Everyone Can Vote! Michael H. Drucker


     
 
 


This post first appeared on The Independent View, please read the originial post: here

Share the post

Was GA’s Election System Hacked in 2016?

×

Subscribe to The Independent View

Get updates delivered right to your inbox!

Thank you for your subscription

×