National: Hackers Get Green Light to Test Election Voting Systems | Robert McMillan and Alexa Corse/Wall Street Journal
Election Systems & Software LLC, the top U.S. seller of voting-machine technology, is calling a truce in its feud with computer-security researchers over the ways they probe for vulnerabilities of the company’s systems. With the U.S. presidential election less than three months away, ES&S Chief Information Security Officer Chris Wlaschin on Wednesday will unveil the company’s outreach effort to security researchers at the annual Black Hat hacker convention that is taking place virtually this year, according to ES&S. Mr. Wlaschin will detail a new vulnerability disclosure policy, which spells out, for example, the “safe harbor” protections that ES&S will provide legitimate researchers if they identify and notify the company of bugs in its systems, ES&S said. Those provisions are standard across many industries, from computer equipment to cars to medical devices, as manufacturers seek outside help to ensure their systems are secure. But the makers of election equipment, ES&S in particular, have been reluctant to allow outside security experts to test their systems, researchers have said. The company’s move follows the Department of Homeland Security last week urging increased cooperation between security researchers, election officials and vendors as it released guidance for election administrators on coordinating to address security vulnerabilities.