National: CIA: Intelligence assessment has not changed on Russia election interference | The Hill

The CIA said on Thursday that the U.S. intelligence community has not reached new conclusions on Russian efforts to interfere in the 2016 election, hours after the agency’s director, Mike Pompeo, said that intelligence agencies had determined that the meddling had no effect on the results. “The intelligence assessment with regard to Russian election meddling has not changed,” Ryan Trapani, a CIA spokesman, told The Washington Post, “and the director did not intend to suggest that it had.” Pompeo reportedly said during a security conference in Washington on Thursday that “the intelligence community’s assessment is that the Russian meddling that took place did not affect the outcome of the election.”

National: Warner, Klobuchar, McCain Introduce Bipartisan Legislation To Prevent Foreign Interference In Elections | Alexandria News

U.S. Senator Amy Klobuchar (D-MN), Ranking Member of the Senate Rules Committee, U.S. Senator Mark Warner (D-VA), Vice Chairman of the Select Committee on Intelligence, and U.S. Senator John McCain (R-AZ), Chairman of the Senate Committee on Armed Services today introduced the Honest Ads Act to help prevent foreign interference in future elections and improve the transparency of online political advertisements. “Online political advertising represents an enormous marketplace, and today there is almost no transparency. The Russians realized this, and took advantage in 2016 to spread disinformation and misinformation in an organized effort to divide and distract us,” Senator Warner said. “Our bipartisan Honest Ads Act extends transparency and disclosure to political ads in the digital space. At the end of the day, it is not too much to ask that our most innovative digital companies work with us by exercising additional judgment and providing some transparency.” 

National: Nikki Haley on Russia meddling: Election interference is ‘warfare’ | Politico

U.S. Ambassador to the United Nations Nikki Haley said Thursday that interference in U.S. elections by another nation “is warfare,” telling an audience in New York that such meddling has become Russia’s go-to tactic. “I will tell you that when a country can come interfere in another country’s elections, that is warfare. It really is, because you’re making sure that the democracy shifts from what the people want to giving out that misinformation,” Haley said Thursday at a forum hosted in New York by the George W. Bush institute. ”And we didn’t just see it here. You can look at France and you can look at other countries. They are doing this everywhere. This is their new weapon of choice. And we have to make sure we get in front of it.”

National: Russia Probes Spur Lawmakers on Election Security, Social Media | Bloomberg

After months of congressional investigations into Russian interference with U.S. elections, legislation is gaining traction in the Senate that would impose new disclosure requirements for political advertising on Facebook, Twitter, Google and other social media. Senator John McCain gave a big boost to a proposal by Democratic Senators Amy Klobuchar and Mark Warner to require disclosure of who’s paying for online political ads, announcing he’ll co-sponsor the bill. In two weeks, executives for the social media giants are due to testify at public hearings about Russia’s use of their networks to interfere in the 2016 election. “I’ve been fighting for free and open and full disclosure for the past 25 years. This is part of that effort,” McCain told reporters Wednesday.

National: Sessions: U.S. not doing enough to prevent interference in elections | Yahoo

Attorney General Jeff Sessions conceded Wednesday that the U.S. government is not doing enough to prevent future interference in elections by Russia and other foreign adversaries. “We’re not,” Sessions said, when asked by Sen. Ben Sasse, R-Neb., if the government is taking adequate action to prevent meddling in its elections. “The matter is so complex that for most of us we’re not able to fully grasp the technical dangers that are out there.” Sessions said he accepts the U.S. intelligence community’s findings that Russia interfered with the 2016 election and may attempt to do so again. He said the Justice Department has been aggressively looking into the stealing of trade secrets in the private sector and noted that the FBI’s computer experts are also highly trained.

National: Democratic Senators want probe of Trump’s fraud commission | The Hill

A group of Senate Democrats is asking a government watchdog to investigate President Trump’s voter fraud commission. Democratic Sens. Michael Bennet (Colo.), Amy Klobuchar (Minn.) and Cory Booker (N.J.) sent a letter to the Government Accountability Office (GAO) saying the panel, known as the Presidential Advisory Commission on Election Integrity, is a “cause for serious concern.” “Investigative reports raise questions about the partisan motives and actions of the Commission,” the senators wrote. They added that the panel has “ignored numerous requests” from lawmakers seeking to clarify its activities.

National: Despite backlash over political ads, Facebook’s role in elections will only grow | Los Angeles Times

Negative headlines. Congressional inquiries. Corporate apologies. The heightening scrutiny surrounding Facebook after it allowed Russian trolls and inflammatory political ads to spread on its network is the kind of thing companies would do anything to avoid. But don’t expect it to harm the tech giant’s bottom line. As the political world looks to apply the lessons of Donald Trump’s victory to future campaigns, one of the few clear conclusions is that Facebook played an outsized role in propelling the candidate to his improbable win. The company’s ability to affordably target hyper-specific audiences with little to no transparency gives it a distinct advantage over other forms of media, researchers and political operatives believe.

National: The fix is in for hackable voting machines: use paper | Naked Security

Want better security of election voting results? Use paper. With the US almost halfway between the last national election and the 2018 mid-terms, not nearly enough has been done yet to improve the demonstrated insecurity of current electronic voting systems. Multiple experts say one obvious, fundamental move should be to ensure there is a paper trail for every vote. That was a major recommendation at a panel discussion this past week that included representatives of the hacker conference DefCon and the Atlantic Council think tank, which concluded that while there is progress, it is slow.

National: Russian troll factory paid US activists to help fund protests during election | The Guardian

Russian trolls posing as Americans made payments to genuine activists in the US to help fund protest movements on socially divisive issues, according to a new investigation by a respected Russian media outlet. On Tuesday, the newspaper RBC published a major investigation into the work of a so-called Russian “troll factory” since 2015, including during the period of the US election campaign, disclosures that are likely to put further spotlight on alleged Russian meddling in the election. The existence of the troll factory, which has a history of spamming Russian and English blogs and comment forums, has been reported on by many outlets including the Guardian, but the RBC investigation is the first in-detail look at the organisation’s activity during the election period.

National: Conflict Mounts Inside Fraud Commission in the Wake of Child Porn Arrest | ProPublica

The arrest, on child pornography charges, of a researcher for the controversial Presidential Advisory Commission on Election Integrity is intensifying conflict inside the group, with two Democratic members asserting again that a small band of conservatives holds disproportionate power. The researcher, Ronald Williams II, who was arrested late last week, previously worked as an intern at the Department of Justice on a case with J. Christian Adams, who is now a Republican member of the commission. Democratic commissioner Matt Dunlap contends Williams’ involvement with the commission is the latest in a series of discoveries suggesting a few conservative members wield outsize clout; Dunlap claims that Democratic members have been largely excluded from planning. Today he wrote a letter to the commission demanding information. “I am seeking information because I lack it,” stated the letter, a copy of which was given to ProPublica. “I am in a position where I feel compelled to inquire after the work of the Commission upon which I am sworn to serve, and am yet completely uninformed as to its activities.” The letter demanded copies of “any and all communication between members of the commission” beginning in May.

National: State officials to be given access to 2016 election cyberattack data | CBS

CBS News has learned that in an unprecedented effort to enhance election security ahead of the 2018 midterms, select state officials will be given access to some of the most sensitive information about the extent of the 2016 cyberattacks, but that access will require them to submit to the time-consuming and lengthy process of filling out federal security clearance applications. The process online can take up to 10 hours and, even after completing the application, some election officials say they have doubts about the extent of what they’ll be able to see.During the 2016 election, suspected Russian hackers scanned and probed voter databases and other election related computer networks in at least 21 states.

National: DHS and top election officials finally meet to begin hashing out ‘critical infrastructure’ designation | Washington Examiner

Top election officials from around the country met this weekend to create the formal organization to hash out what powers and lines of communications the Department of Homeland Security should have after the department designated voting systems in the states and territories as “critical infrastructure” earlier this year. By voting to adopt a charter for a “Government Coordinating Council,” the secretaries of state now have a group that has an official channel and a single “voice” to communicate with DHS. The move marks the first major step in the coming together between the nonpartisan National Association of Secretaries of State, or NASS, and DHS, amidst a contentious and sometimes mistrusting year.

National: Senator Klochubar wants Kaspersky out of U.S. voting systems | FCW

A U.S. senator has linked two of the hottest tech policy stories around – efforts by U.S. agencies to blacklist cybersecurity vendor Kaspersky Lab and concerns about the vulnerability of voting systems used by cities and states. Sen. Amy Klochubar (D-Minn.) who sits on a committee with authority over federal elections, is concerned that Kaspersky could be in a position to provide Russian intelligence agencies access to state and local election data, by virtue of connections to computers involved in managing election activities. “Given recent revelations regarding how Russia used Kaspersky software to breach our systems, it is important to prioritize state critical infrastructure systems in conjunction with efforts currently underway at the federal level,” Klochubar wrote in an Oct. 12 letter to Acting Homeland Security Secretary Elaine Duke.

National: Google, Facebook putting an early mark on political advertising bills | Politico

Google and Facebook are looking to make an early imprint on legislation being drafted in the House and Senate that would force them and other online networks to disclose information about the buyers of political ads. Lobbyists from the Silicon Valley behemoths have met with the staffs of Sens. Mark Warner and Amy Klobuchar and Rep. Derek Kilmer, all of whom are drawing up bills that would impose new regulations on the industry, according to Democratic aides and company representatives. The Senate bill is expected to be formally introduced next week. It is not clear when the House legislation, which has not been previously reported, will be introduced. Facebook has talked with those working on the bill, a company source confirmed, characterizing Facebook as willing to continue discussing it as the process moves along. A spokesperson for Google declined to comment.

National: An intern Cambridge Analytica left sensitive voter targeting tools online for nearly a year | Business Insider | Business Insider

An intern at the data mining and analysis firm Cambridge Analytica left online for nearly a year what appears to be programming instructions for the voter targeting tools the company used around the time of the election, raising questions about who could have accessed the tools and to what end. Social media analyst and data scientist Jonathan Albright discovered the election data processing scripts — or programming instructions — on what he said was the intern’s personal GitHub account. GitHub, a “Facebook for programmers,” is an internet hosting service mostly used for code. The account was scrubbed less than an hour after Albright published his findings on Medium, but the scripts had already been archi

National: Are Americans Beginning to Care About Election Integrity? | WhoWhatWhy

Nearly a year after the 2016 presidential election, many Americans have been forced, some for the very first time, to look critically at their voting protections, and recognize that US balloting systems are not nearly as impregnable as they once thought. Clearly, the US intelligence reports about Russia hacks provided a long-overdue wake up call for this issue. The good news: some progress has been made in some jurisdictions in the last year. The bad news: that progress hasn’t been as widespread or comprehensive as the problem would seem to demand. “I think we’re moving in the right direction,” said Larry Norden, of NYU’s nonpartisan Brennan Center for Justice. “I’m heartened by the fact that, for instance, we’re seeing, in both House and Congress, bipartisan proposals to invest in increased election system security.” … Election consultant Pam Smith agreed that there has “definitely [been] a pattern towards more secure elections” across the country. Some states appear to be ahead of the game. Virginia, for example, recently earned praise for decertifying all its touchscreen, paperless Direct Record Electronic (DRE) voting machines ahead of the termination date required by its own legislation.

National: The Race to Secure Voting Tech Gets an Urgent Jumpstart | WIRED

Numerous electronic voting machines used in United States elections have critical exposures that could make them vulnerable to hacking. Security experts have known that for a decade. But it wasn’t until Russia meddled in the 2016 US presidential campaigns and began probing digital voting systems that the topic took on pressing urgency. Now hackers, researchers, diplomats, and national security experts are pushing to effect real change in Washington. The latest update? It’s working, but maybe not fast enough. On Tuesday, representatives from the hacking conference DefCon and partners at the Atlantic Council think tank shared findings from a report about DefCon’s Voting Village, where hundreds of hackers got to physically interact with—and compromise—actual US voting machines for the first time ever at the conference in July. Work over three days at the Village underscored the fundamental vulnerability of the devices, and raised questions about important issues, like the trustworthiness of hardware parts manufactured in other countries, including China. But most importantly, the report highlights the dire urgency of securing US voting systems before the 2018 midterm elections.

National: Wary of Hackers, States Move to Upgrade Voting Systems | The New York Times

State election officials, worried about the integrity of their voting systems, are pressing to make them more secure ahead of next year’s midterm elections. Reacting in large part to Russian efforts to hack the presidential election last year, a growing number of states are upgrading electoral databases and voting machines, and even adding cybersecurity experts to their election teams. The efforts — from both Democrats and Republicans — amount to the largest overhaul of the nation’s voting infrastructure since the contested presidential election in 2000 spelled an end to punch-card ballots and voting machines with mechanical levers. One aim is to prepare for the 2018 and 2020 elections by upgrading and securing electoral databases and voting machines that were cutting-edge before Facebook and Twitter even existed. Another is to spot and defuse attempts to depress turnout and sway election results by targeting voters with false news reports and social media posts.

National: Trump Fraud Commission Violates Federal Law, Lawsuit Claims | Newsweek

President Donald Trump’s controversial “election integrity” commission is facing yet another legal challenge with a privacy-rights group saying the panel is breaking federal law by gathering massive amounts of information on the nation’s registered voters. The Electronic Privacy Information Center, which has been doing court battle against the voter panel for months, filed a revised complaint in District of Columbia federal court Thursday. Privacy watchdogs concerned about the panel’s activities have questioned whether the information can and will be kept safe from hackers and whether it will only used for research and not other political purposes.  The Trump administration has defended the attempt to collect huge quantities of voter data by saying the panel is not technically a federal agency. Therefore, the argument goes, it does not have to do a so-called “impact assessment” to show that collecting the information doesn’t violate anyone’s privacy rights.

National: DEFCON hopes voting machine hacking can secure systems | TechTarget

A new report pushes recommendations based on the research done into voting machine hacking at DEFCON 25, including basic cybersecurity guidelines, collaboration with local officials and an offer of free voting machine penetration testing. It took less than an hour for hackers to break into the first voting machine at the DEFCON conference in July. This week, DEFCON organizers released a new report that details the results from the Voting Village and the steps needed to ensure election security in the future. Douglas Lute, former U.S. ambassador to NATO and retired U.S. Army lieutenant general, wrote in the report that “last year’s attack on America’s voting process is as serious a threat to our democracy as any I have ever seen in the last 40+ years – potentially more serious than any physical attack on our Nation. Loss of life and damage to property are tragic, but we are resilient and can recover. Losing confidence in the security of our voting process — the fundamental link between the American people and our government — could be much more damaging,” Lute wrote. “In short, this is a serious national security issue that strikes at the core of our democracy.”

National: Voting Machines: A National Security Vulnerability? | Atlantic Council

The political instability that has resulted from Russian meddling in the 2016 US presidential elections has put the focus on voting machines as a national security vulnerability, Douglas Lute, a former US permanent representative to NATO, said at the Atlantic Council on October 10. “I don’t think I’ve seen a more severe threat to American national security than the election hacking experience of 2016,” said Lute. There is a “fundamental democratic connection between the individual voter and the democratic outcome” of an election, he said, adding: “If you can undermine that, you don’t need to attack America with planes and ships. You can attack democracy from the inside.” … Lute delivered a keynote address at the Atlantic Council to call for a sense of urgency among policymakers and all stakeholders able to play a role in the solution to insecure voting machines. He also highlighted the findings presented in the DEF CON Report on Cyber Vulnerabilities in US Election Equipment, Databases, and Infrastructure, launched at the Council, which help to shed light on the technological dimensions of this national security threat. Ultimately, as Lute writes in the foreword, “this report makes one key point: our voting systems are not secure.”

National: Report details election vulnerabilities uncovered at DEFCON | GCN

When attendees at the July DEFCON conference breached every poll book and voting machine that event organizers had in the Voting Machine Hacking Village, elections officials took notice. A new report from DEFCON, the National Governors Association, the Atlantic Council, the Center for Internet Security and a number of universities and top technology vendors provides a more detailed look at just how vulnerable the entire U.S. election system – equipment, databases and infrastructure —  is to hacking and urges policymakers to shore up security gaps. Vulnerabilities start with an insecure supply chain. Many parts used in voting machines are manufactured overseas, and the report authors suggested that bad actors could compromise the equipment “well before that voting machine rolls off the production line.” Voting Village participants found voting machines with universal default passwords and ones that broadcast their own Wi-Fi access point, which would allow hackers to connect. Once hackers gained access, they could escalate their privileges so they could run code, change votes in the database or turn the machine off remotely. Additionally, unprotected, uncovered USB ports provided easy inputs for thumb drives or keyboards.

National: Facebook scrubbed potentially damning Russia data before researchers could analyze it further | Business Insider

Facebook removed thousands of posts shared during the 2016 election by accounts linked to Russia after a Columbia University social-media researcher, Jonathan Albright, used the company’s data-analytics tool to examine the reach of the Russian accounts. Albright, who discovered the content had reached a far broader audience than Facebook had initially acknowledged, told The Washington Post on Wednesday that the data had allowed him “to at least reconstruct some of the pieces of the puzzle” of Russia’s election interference. “Not everything, but it allowed us to make sense of some of this thing,” he said.

National: It Isn’t Even That Difficult To Hack Voting Equipment | HuffPost

You don’t even have to know much about voting machines to hack some of the systems that are still in use across the country. A new report published on Tuesday outlines how amateur hackers were able to “effectively breach” voting equipment, in some cases in a matter of minutes or hours, over just four days in July at DEFCON, an annual hacker conference. The report underscores the vulnerability of U.S. election systems. It also highlights the need for states to improve their security protocols after the Department of Homeland Security said Russian hackers attempted to target them during the 2016 election. “The DEFCON Voting Village showed that technical minds with little or no previous knowledge about voting machines, without even being provided proper documentation or tools, can still learn how to hack the machines within tens of minutes or a few hours,” the report says.

National: How DEFCON Turned an Event Into a Major Initiative | Associations Now

Organizers of the long-running DEFCON hacking conference have teamed with a variety of groups, including the National Governors Association, on an initiative to boost electoral security. The new coalition comes on the heels of a new report highlighting how insecure many voting machines really are. The DEFCON hacking conference, which has existed in one form or another for nearly a quarter century, is getting into the election security business—with the help of a number of associations and nonprofits. A September report [PDF] outlines the results of the first-ever “Voting Machine Hacking Village,” held at the DEFCON conference in Las Vegas last summer. The exercise revealed significant vulnerabilities in digital voting machines and in the ways they’re used to tally votes. And this week it led to the announcement of a coalition on election security that includes the National Governors Association, the Atlantic Council, the Center for Internet Security, and a variety of academic groups, among others.

National: What’s the Likelihood That a National U.S. Election Could Be Hacked? | Popular Mechanics

The electronic voting machine, now used to some degree in all 50 states, is the functional equivalent of an unoccupied Lamborghini left running at midnight with vanity plates that say STEALME. This summer, hobbyist hackers with no specialized expertise who attended a convention called Defcon were able to compromise four different voting machines, one in less than 30 minutes. “Unfortunately, they were much easier than, say, a home router or mobile device,” says Defcon organizer Jeff Moss. … Online voting is hardly a fix. “There are so many problems and insecurities in internet voting, it’s not something we should even begin to consider in the next ten years,” says Princeton University professor of computer science Andrew Appel.

National: A warning from the Senate Intelligence Committee has vulnerable lawmakers fretting about election security | Politico

Democratic senators fighting to hold on to their seats next year are increasingly worried about a troubling reality: Russia appears set to mess with U.S. elections — again. The bipartisan leaders of the Senate Intelligence Committee warned last week that Russia’s second straight attempt to upend a major election appears certain. They pointed to hacked emails, fake news stories and other evidence of interference in France, Montenegro and elsewhere over the past year as signs Moscow remains determined to monkey with voting. Democratic senators such as Heidi Heitkamp of North Dakota, Bob Casey of Pennsylvania and Jon Tester of Montana — who hail from states President Donald Trump won in 2016 — know they’re already facing stiff reelection challenges.

National: Obama-linked group asks for temporary injunction against Trump fraud commission | McClatchy

A group of former Obama Administration lawyers on Wednesday moved for a temporary injunction against President Donald Trump’s voting fraud commission, saying the committee caused an “immediate blow to the proper functioning of our democracy” when it requested voter data from all 50 states without following legally mandated procedures. The motion, filed in U.S. District Court in Washington, D.C., by Protect Democracy Project and United to Protect Democracy, cited reports of people withdrawing their voter registration in response to the Trump commission’s request for information — proof, the motion argues, that the court should stop the Trump group from collecting the data now before it does more harm. The motion also argues that the requests “may increase the vulnerability of voter registration systems to hackers” and, contrary to federal law, gives Protect Democracy insufficient time to respond and mobilize the public to its actions.

National: Hacking the Election: Security Flaws Need Fixing, Researchers Say | AFP

Hackers could have easily infiltrated US voting machines in 2016 and are likely to try again in light of vulnerabilities in electronic polling systems, a group of researchers said Tuesday. A report with detailed findings from a July hacker conference which demonstrated how voting machines could be manipulated concluded that numerous vulnerabilities exist, posing a national security threat. The researchers analyzed the results of the “voting village” hacking contest at the DefCon gathering of hackers in Las Vegas this year, which showed how ballot machines could be compromised within minutes. “These machines were pretty easy to hack,” said Jeff Moss, the DefCon founder who presented the report at the Atlantic Council in Washington. “The problem is not going away. It’s only going to accelerate.”

National: U.S. voting machines are susceptible to hacking by foreign actors | CBS

Hacking and national security experts say that U.S. voting machines are vulnerable and could allow Russia to access to them, according to a new report out of DEFCON, one of the world’s longest-running hacker conferences. The report concludes that it is incredibly easy to hack U.S. voting machines, and the system is not nearly as safe as it’s portrayed by election officials because many voting machines contain foreign-manufactured internal parts that may be susceptible to tampering. Hackers also do not need advanced knowledge of voting machines to hack them — it would take only a few minutes or hours for someone with the technical knowledge to infiltrate the machines. At the Voting Village conference in July, DEFCON set up a hacking village to draw attention to cyber vulnerabilities in U.S. election infrastructure. It invited participants to hack 25 pieces of election equipment including voting machines and electronic poll books, and produced a report afterwards.