National: Thousands of US voters’ data exposed by robocall firm | ZDNet

Another cache of US voter data has leaked. A Virginia-based political campaign and robocalling company, which claims it can “reach thousands of voters instantly,” left a huge batch of files containing hundreds of thousands of voter records on a public and exposed Amazon S3 bucket that anyone could access without a password. The bucket contained close to 2,600 files, including spreadsheets and audio recordings, for several US political campaigns. Kromtech Security’s Bob Diachenko, who discovered the exposed data and blogged his findings, shared prior to publication several screenshots of data, packed with voters’ full names, home addresses, and political affiliations.

National: Trump’s intel chiefs fight Russia’s election interference — with or without him | The Washington Post

President Trump’s top intelligence and national security officials are forging ahead with plans to disrupt any Russian interference ahead of the 2018 midterms. But they may be going it alone following Trump’s performance this week at the summit with Russian President Vladimir Putin in Helsinki. Just hours after Trump cast doubt on his own country’s conclusions about Moscow’s 2016 election interference at Monday’s presser, Director of National Intelligence Daniel Coats said the intelligence community “will continue to provide unvarnished and objective intelligence in support of our national security.”  And on Tuesday, the day after Trump suggested he believed Putin’s denials, my colleague Ellen Nakashima reported that the National Security Agency is partnering with the military’s cyberwarfare arm to counter threats from Moscow going into November. “Trump will keep waffling on Russia’s role in the 2016 election. If Russia interferes again, the national security agencies will have no problem running their past playbook: Name and shame, indict, and sanction,” said Stewart Baker, a former Department of Homeland Security assistant secretary and former general counsel for the NSA. But, he added, “the agencies are going to have to get White House approval for anything more, and I’m guessing the president won’t grant it.”

National: ES&S Admits It Installed Remote-Access Software on Systems Sold to States | Motherboard

The nation’s top voting machine maker has admitted in a letter to a federal lawmaker that the company installed remote-access software on election-management systems it sold over a period of six years, raising questions about the security of those systems and the integrity of elections that were conducted with them. In a letter sent to Sen. Ron Wyden (D-OR) in April and obtained recently by Motherboard, Election Systems and Software acknowledged that it had “provided pcAnywhere remote connection software … to a small number of customers between 2000 and 2006,” which was installed on the election-management system ES&S sold them. The statement contradicts what the company told me and fact checkers for a story I wrote for the New York Times in February. At that time, a spokesperson said ES&S had never installed pcAnywhere on any election system it sold. “None of the employees, … including long-tenured employees, has any knowledge that our voting systems have ever been sold with remote-access software,” the spokesperson said.

National: ES&S Admits Installing Remote-Access Software on State Voting Systems | ExtremeTech

In February 2018, Election Systems and Software told the press that it had never installed remote-access software in any of the e-voting systems it has sold in the various US states or to local governments. In April, the company told Senator Ron Wyden’s office (D-OR), that it had sold pcAnywhere remote connection software “to a small number of customers between 2000 and 2006.” The good news about this disclosure is that the systems in question have all been retired and are no longer in use across the United States. But the fact that this happened in the first place, combined with ongoing warnings about the generally poor state of e-voting security, speaks to the depth and breadth of the issues facing the United States’ e-voting system as the 2018 midterm election approaches. The fact that ES&S lied about its own previous behavior to the public until pressured by Senator Wyden’s office says little good about the civic responsibility these companies feel towards ensuring that voting is handled safely. It’s important — just not as important as minimizing any hint of corporate liability.

National: The Biggest Spender of Political Ads on Facebook? President Trump | The New York Times

It’s official: President Trump is the single biggest political advertiser on Facebook. Mr. Trump and his political action committee spent $274,000 on ads on the social network since early May, outpacing the second-biggest spender, Planned Parenthood Federation of America, a nonprofit organization that provides reproductive health care. Planned Parenthood spent just over $188,000 on Facebook ads over the same period. The ads bought by Mr. Trump and his PAC were also seen the most by Facebook’s users, having been viewed by at least 37 million people since May. That compared with 24 million people who saw the second-most viewed group of political ads, which were also from Planned Parenthood.

National: NSA and Cyber Command to coordinate actions to counter Russian election interference in 2018 amid absence of White House guidance | The Washington Post

The head of the nation’s largest electronic spy agency and the military’s cyberwarfare arm has directed the two organizations to coordinate actions to counter potential Russian interference in the 2018 midterm elections. The move, announced to staff at the National Security Agency last week by NSA Director Paul Nakasone, is an attempt to maximize the efforts of the two groups and comes as President Trump in Helsinki on Monday said Russian President Vladi­mir Putin was “extremely strong and powerful” in denying Russian involvement in the presidential election two years ago. It is the latest initiative by national security agencies to push back against Russian aggression in the absence of direct guidance from the White House on the issue.

National: Trump says he accepts Russia meddled in election, but still muddies waters | The Guardian

Donald Trump sought to reverse course on Tuesday, after top Republicans scrambled to distance themselves from his behavior in his meeting with Vladimir Putin in Helsinki. Even then, Trump could not resist muddying the waters further. Speaking to reporters in the Roosevelt Room of the White House, the president stated that he accepted the assessment of US intelligence agencies that Russiainterfered in the 2016 US election – and then, moments later, cast doubt on who was responsible. “Let me be totally clear in saying that … I accept our intelligence community’s conclusion that Russia’s meddling in the 2016 election took place,” Trump said, reading from a prepared script. He then added: “It could be other people also. There’s a lot of people out there.” On Monday, Trump met Putin with only interpreters in attendance for two hours then held a press briefing in which he sided with the Kremlin and against US intelligence services.

National: Indicted Russian firm says it was backing free political speech, not disrupting 2016 election | The Washington Post

A Russian company accused of bankrolling a massive online operation to disrupt the 2016 presidential election argued Monday that it had broken no federal laws, that it was merely supporting free political speech and that the fraud charge against it should be thrown out. Concord Management and Consulting was one of 16 Russian individuals or companies indicted by a federal grand jury in February at the behest of special counsel Robert S. Mueller III. The company is accused of defrauding the government by failing to register as foreign agents and failing to report its election-related expenditures to the U.S. government.

National: Tribal leaders tell Senate voting barriers are persistent, systemic | Cronkite News

Native Americans have been “systematically denied access to fair representation” as a result of persistent barriers to voting, advocates and tribal leaders told a Senate roundtable Tuesday. Witnesses told the informal meeting of senators from the Indian Affairs and Rules committees that tribal voters face a range of challenges, from language barriers, to restrictions with mail-in ballots and lack of access to voting locations. Many of those issues are rooted in “blatant discrimination,” one speaker said. “We should not have to talk about blatant discrimination,” said Jackson Brossy, the executive director of the Navajo Nation Washington Office. “Here we are in 2018. We still face many, many unacceptable barriers to voting for Navajo people.”

National: Russian bots, trolls test waters ahead of US midterms | Associated Press

The sponsors of the Russian “troll factory” that meddled in the 2016 U.S. presidential campaign have launched a new American website ahead of the U.S. midterm election in November. A Russian oligarch has links to Maryland’s election services. Russian bots and trolls are deploying increasingly sophisticated, targeted tools. And a new indictment suggests the Kremlin itself was behind previous hacking efforts in support of Donald Trump. As the U.S. leader prepares to meet Russian President Vladimir Putin in Helsinki on Monday, many Americans are wondering: Is the Kremlin trying yet again to derail a U.S. election? While U.S. intelligence officials call it a top concern, they haven’t uncovered a clear, coordinated Russian plot to mess with the campaign. At least so far. It could be that Russian disruptors are waiting until the primaries are over in September and the races become more straightforward – or it could be they are waiting until the U.S. presidential vote in 2020, which matters more for U.S. foreign policy. In the meantime, an array of bots, trolls and sites like USAReally appear to be testing the waters.

National: Trump’s meeting with Putin a pivotal moment for effort to deter Russian cyberattacks | The Washington Post

President Trump’s meeting today with Russian President Vladimir Putin is a pivotal moment for his administration’s efforts to deter future election interference efforts by Moscow and other sophisticated actors. Trump entered his meeting with Putin in Helsinki armed with the sweeping indictment of 12 Russian intelligence officers in connection with the hack on the Democratic Party in 2016, which drew the clearest connection to date between the election cyberattacks and the Kremlin. The intelligence community’s attribution of the attack to Russia — and now, the indictments of specific individuals involved — can be powerful parts of a country’s deterrence strategy. But experts say they could be far less effective if the president doesn’t back up their conclusions. “Trump’s reluctance to admit that the Russians did wrong tends to put a top limit on the kind of retaliation that Russia can expect from a repeat of 2016,” said Martin Libicki, chair of cybersecurity studies at the U.S. Naval Academy. Anything less than a strong demand that Putin back off will likely dull the effects of not just the “naming and shaming” approach the intelligence community has taken but also sanctions, indictments and other punitive measures the administration and Congress have levied.

National: Dominion Voting Systems Acquired by its Management Team and Staple Street Capital

Dominion Voting Systems (“Dominion Voting”) announces that it has been acquired by its management team and Staple Street Capital, a leading New York-based, middle-market private equity firm. Dominion Voting is a top provider of election tabulation solutions to government customers. The company’s scalable and customizable platform holds industry-leading certifications and provides accessibility and efficiency at the state and local levels. Dominion Voting CEO and President John Poulos said, “Our senior management team is extremely pleased to partner with Staple Street Capital, which has a proven track record of successfully investing in growing mid-size businesses. Given the opportunities on our horizon, this is the ideal time for us to add financial resources and an experienced strategic partner to help us meet market demand, better serve customers and invest in evolving security initiatives.”

National: Mueller reveals depth of states’ election vulnerabilities | Poitico

Special counsel Robert Mueller’s latest indictment offers new details of just how deeply Russian operatives have infiltrated state and local election agencies across the U.S. — adding to years of warnings about the technologies that underpin American democracy. Deputy Attorney General Rod Rosenstein said Friday that hackers within Russia’s GRU military intelligence service targeted state and local election boards, infiltrated a Florida-based company that supplies software for voting machines across the country, and broke into a state election website to steal sensitive information on about 500,000 American voters. While the FBI had issued warnings in 2016 about hackers breaching state election websites in Illinois and Arizona, the latest indictments in Mueller’s ongoing Russia probe surfaced the most granular account yet on foreign operatives’ efforts to tamper with U.S. election systems. Sen. James Lankford (R-Okla.) said the charges outline a Russian “attack on our democracy.”

National: Mueller Indictment Adds Urgency to Securing 2018 Midterm Elections | Wall Street Journal

Special counsel Robert Mueller’s latest move briefly hijacked a closed-door meeting of state election officials and federal cybersecurity personnel here last Friday, as phones buzzed with news alerts about his indictment against Russians allegedly behind a spree of hacks before the 2016 election. The interruption, described by several people in attendance, caught the room off guard. Some of the details in the indictment, describing the persistent efforts to compromise both Democratic Party and state election networks, were new to the officials present. That added urgency to the gathering’s mission—protecting the nation’s election machinery in November. It also reflected how tightly the secrets unearthed by Mueller’s investigators are held, even from the officials responsible for preventing a repeat in 2018.

National: States with ‘most vulnerable’ voting systems named in congressional report | StateScoop

Eighteen states made a list of the “most vulnerable” election systems in the country in a report published Thursday by the U.S. House Administration Committee. The states included in the report were faulted for lacking several of the things voting-security advocates frequently call for, including paper records of ballots and post-election audits. The report also states that the $380 million in funds currently being distributed to states by the federal Election Assistance Commission isn’t nearly enough, and that it could cost another $1.4 billion over the next decade for every state to properly secure its election systems. All 50 states plus the District of Columbia have now requested their share of the EAC’s grant money, but the report claims that much more will be needed to upgrade election officials’ information technology, implement cybersecurity training and swap out paper-free Direct Recording Electronic ballot machines, known as DREs.

National: State election officials in US meet amid security concerns | Associated Press

The top state election officials from throughout the U.S. are gathering this weekend in Philadelphia amid fresh revelations of Russia’s interference in the 2016 presidential election and just before President Donald Trump holds one-on-one talks with Russian President Vladimir Putin. The annual gathering has typically been a low-key affair highlighting such things as voter registration and balloting devices. This year’s meetings of the National Association of Secretaries of State and the National Association of State Election Directors are generating far greater interest. The conference is sandwiched between Friday’s indictments of 12 Russian military intelligence officers alleged to have hacked into Democratic party and campaign accounts, and Trump’s long-awaited meeting with Putin.

National: Secretaries of State gavel in at annual conference | Politico

Democratic secretaries of state consider election security a priority and will raise it repeatedly at a gathering of secretaries that begins today — in contrast, they say, to what they call President Donald Trump’s dithering on the subject. “While Trump continues to deny Russia’s interference in the 2016 elections, and his administration neglects the urgent need to better safeguard our elections, it has never been more important for Secretaries of State to lead,” the Democratic Association of Secretaries of State said in a statement. “It is critical that state election officials do everything we can to defend our elections from foreign interference and cyber threats.” The National Association of Secretaries of State’s summer conference, which runs from today through Monday in Philadelphia, includes several sessions focused on cyber threats to elections, including a meeting of the recently created group that coordinates state and federal security efforts.

National: Would Asking People To Hack America’s Election Systems Make Them More Safe? | FiveThirtyEight

There are four months until the midterm elections, and the security of state election systems remains a concern. The clock is ticking to ferret out problems and fix them before Nov. 6. Websites associated with voting continue to have poor cybersecurity hygiene, even after the revelation that hackers probed the systems of 21 states in the lead-up to the 2016 election. And while Congress has increased the funds available to states to improve their election systems, many are still jumping through bureaucratic hoops to actually access the money. One way to supplement much-needed security checks of election systems would be to replicate the security practices of tech-savvy companies. Many private tech companies treat cybersecurity differently than the government does, adapting security practices to deal with inevitable mistakes quickly and through the wisdom of the crowd. They rely partly on outside feedback to suss out vulnerabilities, something that many in the elections community seem allergic to. This could mean that fixable security flaws are left on the table for bad actors to exploit.

National: Election security legislation may be gaining steam in Congress | The Washington Post

Momentum may finally be building in Congress to take new action to secure the elections from cyberthreats as the midterms approach. Lawmakers have struggled to advance election security legislation in the months since they approved a $380 million funding package for states to upgrade their election systems. But a flurry of election-related hearings on Capitol Hill in recent weeks — including a pair of hearings Wednesday that featured testimony from some of the government’s top cybersecurity and election officials — shows they’re sharpening their focus on the issue. And the latest attention could help move bipartisan legislation to combat election cyberthreats closer to the goal line as November nears and intelligence officials warn of ongoing attempts by the Russian government to disrupt the U.S. political system. “The tone has changed so it’s much more forward-looking in terms of, ‘Let’s figure out what we can get done,’ ” said Sen. Amy Klobuchar (D-Minn.), co-sponsor of Secure Elections Act, which would streamline the way state and federal officials exchange threat information and has garnered broad support in the Senate. “Congress, I think, has realized our role has to focus on what’s in front of us, and that’s protecting the 2018 and 2020 elections from foreign interference.”

National: Elections Seen Safer From Hacking, but Meddling Threat Lingers | Bloomberg

U.S. elections are safer from hacking than they were two years ago, but the threat of foreign meddling hasn’t been stamped out, lawmakers said. “People are much more aware of the problem and taking steps to protect themselves” from hacking before the November elections, Sen. Amy Klobuchar(D-Minn.) said in a phone interview. “We’ve reached a new era” with lawmakers of both parties concerned about Russia’s interference in 2016 and are “trying to solve the problem going forward,” she said. Klobuchar spoke after the Senate Rules and Administration Committee took testimony from experts on how to safeguard U.S. elections. Congress provided $380 million for grants in response to Department of Homeland Security revelations that Russia targeted election systems in at least 21 states for possible interference in 2016. The DHS found no evidence of actual ballot tampering, but said steps are needed to secure future elections.

National: Voting machine vendors under pressure | Politico

The top Democrat on the Senate Rules Committee wants more answers from voting machine vendors after two of the three largest companies skipped Wednesday’s election security hearing. Hart InterCivic sent a representative, but Election Systems & Software and Dominion did not. “I think we should try again, and I personally plan on sending them a number of written questions, since they wouldn’t come to the hearing,” Minnesota Sen. Amy Klobuchar told Eric. “They have a responsibility, when there’s only three of them, to answer our questions.” Klobuchar is the lead Democratic sponsor of the bipartisan Secure Elections Act (S. 2593), Congress’ most significant attempt yet to protect U.S. election infrastructure from hackers. Klobuchar may get her wish to bring in Dominion and ES&S — a spokeswoman for Rules Chairman Roy Blunt told MC that the panel was planning additional hearings.

National: Nation’s top voting equipment vendors grilled by Senate on election security | Washington Times

The Senate’s leading election security advocates blasted the country’s top voting equipment vendors on Wednesday for potentially failing to shore up ballot boxes despite November’s midterm elections already being underway with primaries. Mark Warner, also the top Democrat in the Senate’s probe into Russian interference in the 2016 election, scolded Texas-based Hart InterCivic for failing to cooperate with a security review in his home state of Virginia after that contest. “I am very concerned that there is a lot of chest thumping about how well we did in 2016,” Mr. Warner said during a Senate Rules and Administration Committee’s hearing on election safety — the second on the subject in less than a month. Peter Lichtenheld, vice president of operations for Hart InterCivic, had earlier told lawmakers of the firm’s “strong working relationships” with federal, state and local election officials.

National: Elections officials have a lot of security work to do before November, state and federal officials tell Congress | StateScoop

Russian hackers might not be as active in interfering with U.S. voting systems this year as they were in 2016, but that doesn’t mean states don’t have plenty of work to do to secure future elections, state and federal officials told members of the House of Representatives Wednesday. “Many elections across our country are being run on equipment that is either obsolete or near the end of its useful life,” Rhode Island Secretary of State Nellie Gorbea told the House Homeland Security Committee. But Gorbea, who said her state started buying new paper-ballot optical scanning machines to count votes in 2015, said replacing hardware is only one part of making the elections she oversees less vulnerable. In her experience, she said, the state-, county- and city-level officials who actually manage elections are “ill-prepared” to deal with cyberthreats.

National: Senators push for increased elections security | GCN

To help protect the nation’s voting infrastructure, the Elections Assistance Commission is distributing $380 million in funding to states, while the Department of Homeland Security is conducting  vulnerability scans on election equipment in at least 17 states. But some senators believe there’s much more that could be done to help secure elections. “We want to put some processes in place to make sure that we’ve not forgotten the lessons from 2016,” Sen. James Lankford (R-Okla.) said in his testimony at a July 11 Senate rules committee hearing. “There are some basic things that could be done while still allowing the states to control their election structures and have flexibility on the type of election machines that they want to have.”

National: The 5 States Most Vulnerable to a 2018 Election Hack | U.S. News & World Report

Around one year ago, Liz Howard, the deputy commissioner of elections in Virginia had felt good about being prepared for the fall’s approaching voting. Localities looked ready and the state legislature had just passed mandatory post-election audits. “And then,” she recalled. “DEFCON happened.” At an annual worldwide hacking convention in Las Vegas – scheduled this year during the second week in August – intruders in a simulation made their way into the commonwealth’s electronic touch-screen voting machines used in roughly two dozen jurisdictions.  … Some swing states, like Pennsylvania, are racing to upgrade all of their equipment in time for 2020. But that leaves the commonwealth – host of a U.S. Senate and gubernatorial contest – vulnerable in 2018. In Georgia, a commission is still studying a replacement for its touch-screen voting machines and hasn’t yet decided how to precisely spend its $10 million federal grant, according to McClatchy.

National: Here’s an early look at how states are spending federal election security cash | The Washington Post

Nearly four months have passed since Congress set aside $380 million for states to upgrade their election systems, and we’re just now seeing concrete details about how states plan to spend that money. California will immediately make more than $3 million available to county officials to help them protect voter rolls from cyberthreats and improve accessibility at polling places, according to figures provided to The Cybersecurity 202. And Hawaii will spend more than $400,000 ahead of the November midterms to upgrade computers, hire staff and conduct cybersecurity training, the secretary of state’s office says.  California and Hawaii are among 13 states that, as of Monday, have submitted their detailed plans to the Election Assistance Commission about how they intend to spend their share of the federal cash ahead of the July 16 deadline. Their plans offer an early indication that states are taking recommendations from federal officials and election security experts seriously as the midterms approach and intelligence officials warn of a new wave of election interference from the Russian government. 

National: Expert: Putin can hack our midterms | Yahoo News

Russian President Vladimir Putin is poised once again to meddle in an American election, and there’s little the U.S can do to stop him, an expert says. “The midterm is vulnerable to attack. There’s nothing we can do about it. It’s too late — if Putin wants to attack our midterm, he will.” Barbara Simons, a former IBM researcher and the co-author of “Broken Ballots: Will Your Vote Count?” told Grant Burningham, host of the Yahoo News podcast “Bots & Ballots.” Having spent the last decade trying to warn politicians of the vulnerabilities of computerized voting systems, Simons, who received a PhD in computer science from the University of California, Berkeley, says that states like Georgia, New Jersey, Delaware, Louisiana and South Carolina that have switched to paperless elections are especially ripe targets.

National: DEF CON Voting Village grows this year | POLITICO

Black Hat and DEF CON are just around the corner, and one of the biggest headlines from last year’s conferences was the Voting Village where hackers broke into voting machines en masse. This year’s Voting Village at DEF CON will be three times the size of last year’s event to accommodate the massive demand from 2017, event organizer Harri Hursti told Tim. But it wasn’t easy to get to that point: Hursti said voting machine vendors unhappy with the publicity about hacked equipment threw up hurdles that forced them to get creative, like visiting government auctions to buy equipment to probe.

National: Why Was a Citizenship Question Put on the Census? ‘Bad Faith,’ a Judge Suggests | The New York Times

From the moment it was announced in March, the decision to add a question about citizenship to the 2020 census was described by critics as a ploy to discourage immigrants from filling out the form and improve Republican political fortunes. The Commerce Department, which made the decision, insisted that sound policy, not politics, was its sole motivation. Now a federal lawsuit seeking to block the question has cast doubt on the department’s explanation and the veracity of the man who offered it, Commerce Secretary Wilbur L. Ross Jr. And it has given the plaintiffs in the suit — attorneys general for 17 states, the District of Columbia and a host of cities and counties — broad leeway to search for evidence that the critics are correct. In a hearing last week in the United States District Court in Manhattan, Judge Jesse M. Furman gave the plaintiffs permission to search government files and take sworn testimony from up to 10 administration officials in an effort to discover how and why the citizenship decision was made.

National: States Aren’t Waiting for the Supreme Court to Solve Gerrymandering | Politico

For Americans who want to fight the mapmaker’s tyranny over politics, the U.S. Supreme Court has delivered the classic losers’ consolation: Wait ’til next year. Or the next. Or forever. The court passed up two chances at the end of its term to declare extreme partisan gerrymandering unconstitutional, sending cases from Wisconsin and Maryland back to lower courts. Then, the justices ducked again, remanding a North Carolina gerrymandering case—and making it less likely they’ll confront partisan district-drawing in their next term. Then Justice Anthony Kennedy retired, depriving gerrymandering’s opponents of a potential fifth vote, without resolving Kennedy’s long search for a legal standard on the practice. It’s a clear message to Americans who are sick of how gerrymandering lets politicians pick their voters, creates grotesquely-shaped one-party districts and encourages the partisan divide. With three years to go before the entire nation redistricts after the next census, if gerrymandering’s opponents want better, fairer maps, they’ll have to demand them, state by state. Ohio just showed how it can be done.