Your Web News in One Place

Help Webnuz

Referal links:

Sign up for GreenGeeks web hosting
November 5, 2018 07:52 am PST

Voting machines in Wisconsin and Kentucky are running FTP. Seriously.

FTP -- the "file transfer protocol" -- is a long-supplanted Unix tool for transferring files between computers, once standard but now considered to be too insecure to use; so it's alarming that it's running on the voting machines that will be used in elections in Wisconsin and Kentucky tomorrow.

The FBI has warned that "criminal actors" use FTP in targeting US voting machines. The Wisconsin Elections Commission and DHS have reported hacker attacks on Wisconsin voting machines in the 2016 elections.

Propublica portscanned the voting machines in Kentucky and Wisconsin, which are connected to the fucking internet, and found FTP services being advertised by servers on the machines.

Kentucky's voting machines did not require a password to access their FTP servers.

As of late Wednesday, Kentuckys voter-registration server still allowed users to browse a list of files without a password. Even the names of the files contained clues that could conceivably help an intruder. For example, they indicated that Kentucky may use drivers licenses on file in its motor vehicle software to verify voters identities.

Bradford Queen, a spokesman for Kentuckys secretary of state, declined to say if running an FTP server was problematic. We are constantly guarding against foreign and domestic bad actors and have confidence in the security measures deployed to protect our infrastructure, he said.

ProPublicas claims regarding Kentuckys website lack a complete understanding of the commonwealths full approach to security, which is multi-layered. Defenses exist within each layer to determine and block offending traffic.

File-Sharing Software on State Election Servers Could Expose Them to Intruders [Jack Gillum and Jeff Kao/Propublica] Read the rest


Original Link: http://feeds.boingboing.net/~r/boingboing/iBag/~3/8o2Jeq0Qq5M/no-password-required-in-ky.html

Share this article:    Share on Facebook
View Full Article