Leaked NSA report highlights deep flaws in US elections

Republican presidential candidate Donald Trump, left, stands with Democratic presidential candidate Hillary Clinton before the first presidential debate at Hofstra University, Monday, Sept. 26, 2016, in Hempstead, N.Y. (AP Photo/ Evan Vucci)

HOUSTON (AP) — A newly leaked intelligence document outlining alleged attempts by Russian military intelligence to hack into U.S. election systems is the latest piece of evidence suggesting a broad, sophisticated foreign attack on the integrity of U.S. elections.

And it underscores the contention of security experts and computer scientists that the highly decentralized, often ramshackle U.S. election system remains profoundly vulnerable to trickery or sabotage .

The document, purportedly produced by the U.S. National Security Agency, does not indicate whether actual vote-tampering occurred. But it adds significant new detail to previous U.S. intelligence assessments that alleged that Russia-backed hackers had compromised elements of America’s electoral machinery, and suggests that attackers may also have been laying groundwork for future subversive activity.

The operation described in the document could have given “the Russians a foothold into the IT systems of elections offices around the country that they could use to infect machines and launch a vote-stealing attack,” said J. Alex Halderman, a University of Michigan computer scientist. “We don’t have evidence that that happened,” he said, “but that’s a very real possibility.”

Computer scientists have proven in the lab that once they’re inside an election network, sophisticated attackers could manipulate pre-election programming and alter results without leaving a trace.

Sen. Mark Warner of Virginia, the ranking Democrat on the Senate intelligence committee, said Tuesday that hacking into state voting systems ahead of the Nov. 8 vote was more widespread than has been disclosed.

Attempts by Russia to “break into a number of our state voting processes” was “broad-based,” he said, without offering details. In Moscow, a Kremlin spokesman categorically denied Tuesday that Moscow had tried to hack the U.S. elections.

Warner did not directly address the classified intelligence report published Monday by The Intercept, an online news outlet. The Associated Press has not independently verified the authenticity of the report, although its apparent leaker, an NSA contract worker, was arrested last weekend in Georgia.

The NSA document says Russian military intelligence first targeted employees of a Florida voting systems supplier in August. Apparently exploiting technical data obtained in that operation, the cyber spies later sent phishing emails to more than 100 local U.S. election officials just days ahead of the Nov. 8 vote, intent on stealing their login credentials and breaking into the their systems, the document says.

The emails packed malware into Microsoft Word documents and were forged to give the appearance of being sent by the system vendor, VR Systems of Tallahassee, Florida.

The Department of Homeland Security knew in September that hackers believed to be Russian agents had targeted the voter registration systems of more than 20 states. To date, no evidence of tampering with vote tallies or registration rolls has emerged.

The U.S. elections system is a patchwork of more than 3,000 jurisdictions overseen by the states with nearly no federal oversight or standards. The attack sketched out in the NSA document appears designed specifically to cope with that sprawl.

The NSA document did not name any of the states where local officials were targeted by the emails masquerading as being from VR Systems.

But in September, the FBI held a conference call with all 67 county elections supervisors in the battleground state of Florida to inform them of infiltration of VR Systems without naming the company. Ion Sancho, who retired as Leon County supervisor in December, said he later learned from industry contacts that it was VR Systems.

VR Systems officials did not respond directly to questions emailed by the AP. In a statement, the company said it only knows of a “handful” of customers who received the fraudulent email, adding that it had “no indication” that anyone had clicked on the malware. The NSA document says at least one account was likely compromised.

The company makes software for on-site voter registration at polling stations and backend systems for voting management, according to its website, which says it has customers in California, Florida, Illinois, Indiana, New York, North Carolina, Virginia, and West Virginia.

VR Systems’ electronic poll books — electronic systems used to verify registered voters at polling places — experienced problems on Nov. 8 in Durham County, North Carolina. The issue forced officials to abandon the system, issue paper ballots and extend voting hours.

North Carolina’s state elections director said Tuesday that officials would investigate to see if officials in Durham County were targeted and possibly compromised.

Iowa University’s Douglas Jones is among computer scientists who say voter registration systems are particularly vulnerable to tampering, in part because they are on the internet.

Someone trying to cause chaos and discredit an election could delete names from registration rolls prior to voting — or request absentee ballots en masse. In the latter case, a voter showing up at the polls on Election Day would be recorded as having already cast their ballot. That could force voters to file provisional ballots, and provoke long lines.

There is no evidence any of that happened last Election Day.

WDTN.com provides commenting to allow for constructive discussion on the stories we cover. In order to comment here, you acknowledge you have read and agreed to our Terms of Service. Commenters who violate these terms, including use of vulgar language or racial slurs, will be banned. Please be respectful of the opinions of others and keep the conversation on topic and civil. If you see an inappropriate comment, please flag it for our moderators to review.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s