Majority of Election Sites in Battleground States Lack Validation, McAfee Finds
WASHINGTON — A vast majority of election-related websites operated by local governments in battleground states lack a key feature that would help distinguish them from those run by commercial entities or criminal hackers — a site that ends in .gov as opposed to .com or other extensions, according to cybersecurity research firm McAfee.
Of 1,117 counties in 13 key states, which account for 201 of the 270 Electoral College votes that determine the winner of presidential contests, 83.3% didn’t have the .gov validation, McAfee found.
When government websites operate using .com or other domain extensions, it becomes easy for foreign adversaries to put up fake sites that imitate government websites and to mount disinformation campaigns aimed at misleading voters, said Steve Grobman, McAfee’s chief technology officer.
“If we look at the battleground states, the local election websites are still not operating with the level of security we’d expect,” Grobman told CQ Roll Call. “We see the vast majority are not using .gov, meaning that normal citizens may not be able to identify if an election website is real or not. And only half of them use encryption, so information they’re transmitting is not secure.”
Attackers trying to mislead voters could set up fake websites ending in .com or .us or other domain extensions, similar to those used by local agencies, making them hard to distinguish from authentic ones, Grobman said.
If all government websites, from federal agencies to local governments, operated only with a .gov domain, then a nationwide campaign could educate citizens and voters to trust only .gov websites, Grobman said.
Minnesota was the worst offender, with 95.4% of its sites lacking the .gov extension, while Texas, Michigan, Nevada, Pennsylvania and Ohio were among the states where more than 80% of sites had no validation through the .gov extension, McAfee found.
In Iowa and New Hampshire — two key states that hold the first caucus and primary, respectively, to pick a party’s presidential candidate — significant majorities of sites lacked the .gov extension, McAfee found. In Iowa, 88.9% operate without .gov, while 90% of New Hampshire sites lack one.
More than two-thirds of Arizona’s websites had the .gov extension, making it the state with the most validation. Still, because one-third of the state’s sites lacked the .gov extension, “hundreds of thousands of voters could still be subjected to disinformation schemes,” McAfee said.
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, or CISA, and some lawmakers have been urging state and local agencies to boost security measures.
“We encourage organizations to move to the .gov domain,” Christopher Krebs, director of CISA, told reporters last week after completing an election security exercise with state and local governments. “We do think that between now and the election, there may be other security measures we can put in place like multifactor authentication on key administrator accounts and ensuring that websites have ‘https’ (prefixes). Ultimately, we’d like everyone in government to be on the .gov domain.”
To obtain a .gov extension, local governments have to get permission from the U.S. government.
A bipartisan bill under consideration in the Senate Homeland Security and Governmental Affairs Committee would require CISA to come up with a plan to migrate all government agencies to the .gov domain. The legislation is sponsored by Sen. Gary Peters, D-Mich., and backed by Sens. Amy Klobuchar, D-Minn.; Maggie Hassan, D-N.H.; Ron Johnson, R-Wis.; Roy Blunt, R-Mo.; and James Lankford, R-Okla.
The .gov extension is a top-level domain name administered by the General Services Administration and available only for U.S. federal, state and local government agencies. Domain names for foreign government agencies typically use .gov, followed by an abbreviation of the country name.
Some U.S. federal agencies follow a different naming convention for their websites. The Pentagon and military services, for example, use the .mil extension.
Nearly half of the local government election websites also lacked another key security feature that’s denoted by “https” in front of a website’s address, McAfee found. Instead, 46.6% of the local government sites were operating with only an “http,” which means that data flows in and out of those websites in an unencrypted form, potentially leaving them vulnerable to manipulation.
In Iowa and New Hampshire, about 30% of election websites operate without the https feature, McAfee found.
Top technology companies, including Google, tell developers that all websites should be protected with the https technology. Without the secure layer, intruders can tamper with communications between users and websites and trick users into giving up sensitive information, Google warned developers last year.
All information that flows between users and websites, including images, cookies, scripts and HTML, can be exploited without https, Google said.
©2020 CQ-Roll Call, Inc., All Rights Reserved
Visit CQ Roll Call at www.rollcall.com
Distributed by Tribune Content Agency, LLC.
In The News
Though the 2020 presidential race has left the forefront of the news cycle due to the growing international concern about the coronavirus, a lack of visibility does not appear to have hurt the campaign of Democratic frontrunner Joe Biden. A Reuters/Ipsos opinion poll released Tuesday found... Read More
A federal judge on Thursday refused to push back the date of Wisconsin's April 7 presidential primary despite concerns about the ongoing coronavirus outbreak. U.S. District Judge William Conley's ruling came after listening to arguments Wednesday over whether the primary should be moved while dire warnings... Read More
WASHINGTON — Since the novel coronavirus was first detected in the District of Columbia about a month ago, the city has requested more than 1 million N95 masks from the national stockpile. The number of these masks the city has received: 5,520. States are receiving just a fraction... Read More
Two months before the novel coronavirus probably began spreading in Wuhan, China, the Trump administration ended a $200 million pandemic early-warning program aimed at training scientists in China and other countries to detect and respond to such a threat. The project, launched by the U.S. Agency... Read More
WASHINGTON (AP) — It may be an odd gesture at a time of social distancing, but President Donald Trump is leaning into his plea to Congress to restore full tax benefits prized by business for fine dining and schmoozing. Trump is seizing on the pandemic crisis... Read More
WASHINGTON - The Democratic National Committee announced Thursday that it will delay its presidential nominating convention until the week of Aug. 17, citing the uncertainty surrounding the coronavirus pandemic and how long it will last. “In our current climate of uncertainty, we believe the smartest approach... Read More