Majority of Election Sites in Battleground States Lack Validation, McAfee Finds
WASHINGTON — A vast majority of election-related websites operated by local governments in battleground states lack a key feature that would help distinguish them from those run by commercial entities or criminal hackers — a site that ends in .gov as opposed to .com or other extensions, according to cybersecurity research firm McAfee.
Of 1,117 counties in 13 key states, which account for 201 of the 270 Electoral College votes that determine the winner of presidential contests, 83.3% didn’t have the .gov validation, McAfee found.
When government websites operate using .com or other domain extensions, it becomes easy for foreign adversaries to put up fake sites that imitate government websites and to mount disinformation campaigns aimed at misleading voters, said Steve Grobman, McAfee’s chief technology officer.
“If we look at the battleground states, the local election websites are still not operating with the level of security we’d expect,” Grobman told CQ Roll Call. “We see the vast majority are not using .gov, meaning that normal citizens may not be able to identify if an election website is real or not. And only half of them use encryption, so information they’re transmitting is not secure.”
Attackers trying to mislead voters could set up fake websites ending in .com or .us or other domain extensions, similar to those used by local agencies, making them hard to distinguish from authentic ones, Grobman said.
If all government websites, from federal agencies to local governments, operated only with a .gov domain, then a nationwide campaign could educate citizens and voters to trust only .gov websites, Grobman said.
Minnesota was the worst offender, with 95.4% of its sites lacking the .gov extension, while Texas, Michigan, Nevada, Pennsylvania and Ohio were among the states where more than 80% of sites had no validation through the .gov extension, McAfee found.
In Iowa and New Hampshire — two key states that hold the first caucus and primary, respectively, to pick a party’s presidential candidate — significant majorities of sites lacked the .gov extension, McAfee found. In Iowa, 88.9% operate without .gov, while 90% of New Hampshire sites lack one.
More than two-thirds of Arizona’s websites had the .gov extension, making it the state with the most validation. Still, because one-third of the state’s sites lacked the .gov extension, “hundreds of thousands of voters could still be subjected to disinformation schemes,” McAfee said.
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, or CISA, and some lawmakers have been urging state and local agencies to boost security measures.
“We encourage organizations to move to the .gov domain,” Christopher Krebs, director of CISA, told reporters last week after completing an election security exercise with state and local governments. “We do think that between now and the election, there may be other security measures we can put in place like multifactor authentication on key administrator accounts and ensuring that websites have ‘https’ (prefixes). Ultimately, we’d like everyone in government to be on the .gov domain.”
To obtain a .gov extension, local governments have to get permission from the U.S. government.
A bipartisan bill under consideration in the Senate Homeland Security and Governmental Affairs Committee would require CISA to come up with a plan to migrate all government agencies to the .gov domain. The legislation is sponsored by Sen. Gary Peters, D-Mich., and backed by Sens. Amy Klobuchar, D-Minn.; Maggie Hassan, D-N.H.; Ron Johnson, R-Wis.; Roy Blunt, R-Mo.; and James Lankford, R-Okla.
The .gov extension is a top-level domain name administered by the General Services Administration and available only for U.S. federal, state and local government agencies. Domain names for foreign government agencies typically use .gov, followed by an abbreviation of the country name.
Some U.S. federal agencies follow a different naming convention for their websites. The Pentagon and military services, for example, use the .mil extension.
Nearly half of the local government election websites also lacked another key security feature that’s denoted by “https” in front of a website’s address, McAfee found. Instead, 46.6% of the local government sites were operating with only an “http,” which means that data flows in and out of those websites in an unencrypted form, potentially leaving them vulnerable to manipulation.
In Iowa and New Hampshire, about 30% of election websites operate without the https feature, McAfee found.
Top technology companies, including Google, tell developers that all websites should be protected with the https technology. Without the secure layer, intruders can tamper with communications between users and websites and trick users into giving up sensitive information, Google warned developers last year.
All information that flows between users and websites, including images, cookies, scripts and HTML, can be exploited without https, Google said.
©2020 CQ-Roll Call, Inc., All Rights Reserved
Visit CQ Roll Call at www.rollcall.com
Distributed by Tribune Content Agency, LLC.
In The News
WASHINGTON (AP) — Democrats in the House appear on the verge of advancing President Joe Biden’s $1.85 trillion-and-growing domestic policy package alongside... Read More
WASHINGTON (AP) — Democrats in the House appear on the verge of advancing President Joe Biden’s $1.85 trillion-and-growing domestic policy package alongside a companion $1 trillion infrastructure bill in what would be a dramatic political accomplishment — if they can push it to passage. The House scrapped votes... Read More
TRENTON, N.J. —The nail biter is over. New Jersey Gov. Phil Murphy has been elected to a second term in... Read More
TRENTON, N.J. —The nail biter is over. New Jersey Gov. Phil Murphy has been elected to a second term in the state’s highest office. As of Thursday morning, the Democratic incumbent was leading Republican challenger Jack Ciattarelli by 37,293 votes, with 91% of the state’s election... Read More
ROME (AP) — President Joe Biden wrapped up his time at the Group of 20 summit on Sunday trying to... Read More
ROME (AP) — President Joe Biden wrapped up his time at the Group of 20 summit on Sunday trying to convince Americans and the wider world that he's got things under control — and taking Russia, China and Saudi Arabia to task for not doing enough... Read More
DETROIT (AP) — A federal judge is considering whether to order financial penalties or other sanctions against some of former... Read More
DETROIT (AP) — A federal judge is considering whether to order financial penalties or other sanctions against some of former President Donald Trump's lawyers who signed onto a lawsuit last year challenging Michigan's election results. The lawsuit alleging widespread fraud was voluntarily dropped after a judge... Read More
WASHINGTON -- A powerful congressional committee is beginning an investigation into reports the Justice Department secretly subpoenaed information about members... Read More
WASHINGTON -- A powerful congressional committee is beginning an investigation into reports the Justice Department secretly subpoenaed information about members of Congress and journalists during the Trump administration. The committee’s chairman said he was concerned the Justice Department “used criminal investigations as a pretext to spy... Read More
ATLANTA (AP) — Amber McReynolds, CEO of The National Vote at Home Institute, helped state and local election officials prepare... Read More
ATLANTA (AP) — Amber McReynolds, CEO of The National Vote at Home Institute, helped state and local election officials prepare for the record number of mailed ballots cast during last year's presidential election. She also was recently confirmed by the Senate to serve on the Board... Read More