How Can Election Systems Resist Global Threats?

260 views
β€’
March 7, 2019
by
RSAC Cybersecurity
YouTube video player
How Can Election Systems Resist Global Threats?

TL;DR

Election security requires protecting the entire election ecosystem, including voter registration, districting, ballot creation, poll books, voting systems, reporting, auditing, electricity, and telecommunications. Resilience also depends on addressing online misinformation and false claims about results, because adversaries can undermine public confidence without changing votes or directly compromising voting machines.

Transcript

Hi, everyone. Thank you for coming back after lunch. Um, this is the law track T07, Elections at Risk: Global Threats and Local Impact. Um, if you were here the, in the last session, you know that our moderator is Michael Eisenberg, Principal Cyber Policy Council at MITRE. He's joined by, um, some returning panelists and also new ones that he'll in... Read More

Key Insights

  • Election security is an ecosystem problem involving voter registration, candidates, campaigns, districting, ballot creation, ballot production, poll books, voting systems, reporting, auditing, media, and governing policies. An attacker seeking to affect an election could target any combination of these connected components.
  • Voter registration is foundational because it determines eligibility, supports districting, and supplies information reflected in poll books when people appear to vote. Attacks against registration systems can therefore affect several downstream election functions, even without compromising the machines used to record or tabulate votes.
  • Ballot administration includes creating ballots with candidates and local issues, then producing them for paper, absentee, or digital voting methods. Each available voting option needs policies and procedures designed to preserve integrity, and one part of the process can influence another.
  • Election infrastructure depends on electricity and telecommunications in addition to systems managed directly by election officials. These dependencies enlarge the potential attack surface and show why security planning must account for supporting services, operational practices, and technology beyond individual voting devices.
  • Misinformation is a distinct election threat because it can spread quickly online and create false beliefs about the integrity of results. Its effects are perceptual rather than identical to a technical intrusion, but election policies must still address its capacity to weaken public confidence.
  • The 2016 election threat included both technical probing and an influence campaign. State voter registration systems were probed and attacked, while foreign adversaries conducted vigorous online influence efforts that the panel said continued beyond the election itself.
  • Election administrators control only part of the election environment. Campaign activity, media coverage, and social media communication operate outside their direct authority, making misinformation difficult for election officials to manage through procedures or voting-system security alone.
  • Social media governance raises competing concerns about election integrity and free speech. The panel asks whether platform proprietors should curate potentially harmful content or remain insulated under a common-carrier-like approach that accepts postings regardless of their truthfulness.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What parts of the election ecosystem need protection?

The election ecosystem includes voter registration, candidate filing, campaigns, media interactions, districting, ballot creation, ballot production, poll books, voting and tabulation systems, election reporting, and auditing. Rules, regulations, and policies govern these components, while electricity and telecommunications support election operations. Security planning should consider every part because adversaries may target several connected processes rather than only voting machines.

Q: Why is focusing only on voting machines insufficient?

Voting machines represent only one portion of a much larger election attack surface. An adversary could target voter registration, districting information, ballot preparation, poll books, reporting, audits, telecommunications, electricity, campaigns, media, or public perceptions. Examining only whether a machine can be hacked can distract from vulnerabilities elsewhere that may influence election administration, outcomes, or confidence in reported results.

Q: How does voter registration affect election security?

Voter registration grounds several important election functions. Registration information helps determine whether a person is eligible to vote, appears in the poll book used when voters arrive, and contributes to districting decisions that determine how votes are grouped. Because registration data connects to multiple downstream processes, probing or attacking state registration systems can create risks beyond the registration database itself.

Q: How can misinformation threaten an election without changing votes?

Misinformation can spread false claims about election integrity, reported outcomes, or the reliability of election processes. Those claims may reduce public confidence even when an attacker has not altered ballots or compromised tabulation equipment. The panel describes this as a perceptual threat that differs from a cyberattack but remains important because confidence is essential to a resilient voting process.

Q: What election threats were identified from the 2016 election?

The panel identifies two connected categories of threat associated with the 2016 election. State voter registration systems were probed and attacked, demonstrating technical interest in election infrastructure. At the same time, foreign adversaries conducted a vigorous influence campaign, and misinformation spread rapidly online. The panel treats this combination of system attacks and psychological influence as central to modern election-security planning.

Q: Which election activities are outside administrators' control?

Campaign activity, media activity, and broader online communication are outside the direct control of election administrators. Officials can establish procedures for registration, ballots, poll books, voting systems, reporting, and audits, but they cannot directly govern every message circulating through campaigns or social media. This division complicates attempts to counter misinformation and protect public confidence through administrative controls alone.

Q: How should election policies adapt to modern threats?

Election policies should move beyond a static model focused only on fraud and cheating. They need to address technical attacks against registration, voting, and tally systems, while also building resilience against misinformation and false claims about results. Because different voting options and infrastructure components create distinct risks, each requires appropriate procedures, integrity checks, reporting practices, and auditing mechanisms.

Q: What role do social media platforms have in election security?

The panel presents social media responsibility as an unresolved legal and policy question. Platforms distribute content that may affect elections, including false information that election officials cannot directly control. Policymakers must consider whether proprietors should curate such content or operate under a common-carrier-like model, while also respecting core free speech principles and evaluating the consequences for election integrity.

Summary & Key Takeaways

  • The election ecosystem extends from voter registration and candidate filing through campaigning, districting, ballot creation, voting, reporting, and auditing. Each component creates potential vulnerabilities, while governing rules, regulations, and policies shape how the system operates. Effective security analysis must therefore examine the full attack surface instead of focusing exclusively on voting machines.

  • Election infrastructure includes many processes that require their own policies and procedures to preserve integrity. Electricity and telecommunications are also important dependencies and possible attack targets. Some elements fall under election administrators' control, but campaigns, media, and other parts of the broader information environment remain outside their direct authority.

  • The influence campaign surrounding the 2016 election showed that election threats are both technical and perceptual. State voter registration systems were probed and attacked, while misinformation spread rapidly online. Updated election policies must address cyberattacks, false integrity claims, public confidence, free speech principles, and the responsibilities of social media proprietors.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š