Communications

We've Just Seen the First Use of Deepfakes In an Indian Election Campaign (vice.com) 39

The Delhi Bharatiya Janata Party (BJP) has partnered with political communications firm The Ideaz Factory to create "positive campaigns" using deepfakes to reach different linguistic voter bases, reports Nilesh Christopher reports via Motherboard. It marks the debut of deepfakes in election campaigns in India. From the report: On February 7, a day ahead of the Legislative Assembly elections in Delhi, two videos of the Bharatiya Janata Party (BJP) President Manoj Tiwari criticizing the incumbent Delhi government of Arvind Kejriwal went viral on WhatsApp. While one video had Tiwari speak in English, the other was him speaking in the Hindi dialect of Haryanvi. "[Kejriwal] cheated us on the basis of promises. But now Delhi has a chance to change it all. Press the lotus button on February 8 to form the Modi-led government," he said. One may think that this 44-second monologue might be a part of standard political outreach, but there is one thing that's not standard: These videos were not real. [The original video can be viewed here.]

"Deepfake technology has helped us scale campaign efforts like never before," Neelkant Bakshi, co-incharge of social media and IT for BJP Delhi, tells VICE. "The Haryanvi videos let us convincingly approach the target audience even if the candidate didn't speak the language of the voter." Tiwari's fabricated video was used widely to dissuade the large Haryanvi-speaking migrant worker population in Delhi from voting for the rival political party. According to Bakshi, these deepfakes were distributed across 5,800 WhatsApp groups in the Delhi and NCR region, reaching approximately 15 million people.

United States

This Could Be Microsoft's Most Important Product in 2020. If it Works (cnet.com) 142

Alfred Ng, writing for CNET: Building 83 doesn't stand out on Microsoft's massive Redmond, Washington, headquarters. But last week, the nameless structure hosted what might be the software giant's most important product of 2020. Tucked away in the corner of a meeting room, a sign reading "ElectionGuard" identifies a touchscreen that asks people to cast their votes. An Xbox adaptive controller is connected to it, as are an all-white printer and a white ballot box for paper votes. If you didn't look carefully, you might have mistaken all that for an array of office supplies. ElectionGuard is open-source voting-machine software that Microsoft announced in May 2019. In Microsoft's demo, voters make their choices by touchscreen before printing out two copies. A voter is supposed to double-check one copy before placing it into a ballot box to be counted by election workers. The other is a backup record with a QR code the voter can use to check that the vote was counted after polls close. With ElectionGuard, Microsoft isn't setting out to create an unhackable vote -- no one thinks that's possible -- but rather a vote in which hacks would be quickly noticed.

The product demo was far quieter than the typical big tech launch. No flashy lights or hordes of company employees cheering their own product, like Microsoft's dual screen phone, its highly anticipated dual-screen laptop or its new Xbox Series X. And yet, if everything goes right, ElectionGuard could have an impact that lasts well beyond the flashy products in Microsoft's pipeline. ElectionGuard addresses what has become a crucial concern in US democracy: the integrity of the vote. The software is designed to establish end-to-end verification for voting machines. A voter can check whether his or her vote was counted. If a hacker had managed to alter a vote, it would be immediately obvious because encryption attached to the vote wouldn't have changed. The open-source software has been available since last September. But Microsoft gets its first real-world test on Tuesday, when ElectionGuard is used in a local vote in Fulton, Wisconsin.

Facebook

Facebook Says Political Candidates Can Use Paid Memes (axios.com) 21

Facebook said Friday that political candidates, campaigns and groups can use paid branded content across its platforms, a clarification prompted by a move from Michael Bloomberg's campaign to pay top Instagram influencers to post memes on its behalf. Axios reports: Its policy didn't explicitly state that it was OK for candidates to use branded content posts, but after hearing from various campaigns about the issue, Facebook moved to clarify its stance. Facebook has agreed that branded content should be allowed to be used by candidates, as long as the candidates are authorized and the creators disclose paid partnerships through branded content tools, according to a spokesperson.

Facebook previously prohibited political candidates and campaigns from running branded content by default because it wanted to avoid any risk that such actions could be viewed as accounts giving monetary contributions to campaigns. It's tweaking its approach now -- only in the U.S. -- because it believes that this is no longer a concern, given that it doesn't provide payments as a feature of its branded content tools. If a campaign were to buy ads to boost its branded content, then it would be subject to Facebook's advertising policies. That paid promotion would then need to be included in Facebook public, searchable political ad library for seven years.

Democrats

Nevada Democrats To Use iPads Loaded With Google Forms To Track Caucus (cnet.com) 145

An anonymous reader quotes a report from CNET: Nevada's Democratic Party said Thursday it plans to use iPads loaded with survey app Google Forms to calculate voting results in next week's caucuses. The system is an effort to avoid a repeat of the Iowa caucus chaos. The app will be loaded onto 2,000 iPads purchased by the party and distributed to precinct chairs, according to a memo signed by party Executive Director Alana Mounce seen by the Associated Press Thursday. Google's app will calculate and submit results electronically, while a second step will rely on submissions also being made by phone. Nevada's caucuses will be held on Feb. 22.
Security

MIT Researchers Disclose Vulnerabilities in Voatz Mobile Voting Election App (zdnet.com) 38

Academics from MIT's computer science laboratory have published a security audit today of Voatz, a mobile app used for online voting during the 2018 US midterm elections and scheduled to be used again in the upcoming 2020 presidential election. From a report: MIT academics claim they identified bugs that could allow hackers to "alter, stop, or expose how an individual user has voted." "We additionally find that Voatz has a number of privacy issues stemming from their use of third party services for crucial app functionality," the research team said in a technical paper released today. "Our findings serve as a concrete illustration of the common wisdom against Internet voting, and of the importance of transparency to the legitimacy of elections," researchers added. MIT academics urge states to continue using paper ballots rather than mobile apps that transmit votes over the internet. They say the current paper ballot voting system is designed to be transparent, and allow citizens and political parties to observe the voting process. "Voatz's app and infrastructure were completely closed-source," said James Koppel, one of the MIT academics.
Democrats

Analysis Shows Andrew Yang Was Snubbed By Mainstream Media in its Coverage (vocal.media) 194

Scott Santens, writing for Vocal: Back in June of 2019, I tweeted about the latest egregious example of MSNBC excluding Democratic Presidential candidate Andrew Yang from their ongoing coverage of the 2020 Presidential candidates. There had been previous examples, but that was the worst up to that point because they had photos of all 20 candidates who were going to be in the first debates, and instead of including Yang as one of them, they included someone who wasn't even going to be there. I then started to add each new example as a new reply, and that ongoing thread has now been covered over and over again with each new example as a source of entertaining absurdity. It's been covered by traditional media outlets like The Guardian, Vox, and The Hill. It's also been covered by new media like Ethan and Hila Klein of the H3 Podcast for their two million subscribers. I have gotten many requests to put the entire thread in one place outside of Twitter, so this article has been created to meet that request. Each time a new example occurs, I will update the thread on Twitter, and update this page on Vocal too. I have also made a point here of expanding on the thread in a way I can't on Twitter, by expanding the timeline with earlier examples that had occurred before I started my thread. So instead of starting in June, this timeline starts back in March.
Security

Trump Signs Order To Test Vulnerabilities of US Infrastructure To GPS Outage (reuters.com) 165

U.S. President Donald Trump on Wednesday signed an executive order directing U.S. agencies to test the vulnerabilities of critical infrastructure systems in the event of a disruption or manipulation of global positioning system services (GPS). From a report: GPS is critical to a variety of purposes ranging from electrical power grids, weather forecasting, traffic signals, smartphone applications and vehicle navigation systems. The order said "disruption or manipulation of these services has the potential to adversely affect the national and economic security of the United States."
Democrats

Andrew Yang Drops Out of Presidential Race (washingtonpost.com) 329

Andrew Yang, tech entrepreneur and founder of Venture for America, will end his campaign for president after a disappointing showing in the New Hampshire primary. The Washington Post reports: "I am a numbers guy," Yang said in an interview before addressing supporters at Manchester's Puritan Backroom. "In most of these [upcoming] states, I'm not going to be at a threshold where I get delegates, which makes sticking around not necessarily helpful or productive in terms of furthering the goals of this campaign. If I become persuaded that there's a particular candidate that gives us a superior chance of beating Donald Trump, and I think it's important to make that opinion known, then I would consider it for sure," Yang said. He also said he would be open to becoming another candidate's running mate or joining a presidential Cabinet.

In his stump speech, Yang warned of the societal and economic changes automation would continue to bring to the United States. He proposed countering it by implementing universal basic income in the form of a $1,000-a-month "Freedom Dividend" for U.S. citizens. His sometimes bleak message on the campaign trail was contrasted with his upbeat, irreverent style of campaigning: Yang once crowd-surfed at a candidate forum and sometimes challenged other celebrities to pickup basketball games. He half-danced onto just about every stage to the '90s Mark Morrison R&B hit "Return of the Mack" and spawned a loyal following of supporters who dubbed themselves the "Yang Gang." They often showed up at his events wearing trademark "math" hats, a nod both to his self-described emphasis on facts and research and to the geek culture that surrounded his candidacy. "This is the nerdiest campaign in history," Yang told The Washington Post last year.
Yang was also the first presidential candidate to use campaign funds for a pilot program meant to resemble his universal basic income proposal. "He told CNN on Monday that the concept of a freedom dividend was 'not going anywhere,' and emphasized on Tuesday that he had forced a new idea into Democratic politics," reports The Washington Post. "He made that point with math."

"Now, 66 percent of Democrats support a universal basic income," Yang said. "It's got 72 percent of young people, aged 18 to 34."
Facebook

FTC Will Review Past Mergers by Facebook, Google and Other Big Tech Companies (washingtonpost.com) 35

The new effort by the Federal Trade Commission will require all five big technology companies to provide information about the smaller players they've purchased over the past 10 years, including documents for deals that may not have been large enough to warrant deep, closer inspection by government watchdogs at the time. From a report: The records the FTC amasses could ultimately influence its thinking about Silicon Valley and its size, sparking investigations, resulting in tough punishments or prompting the commission to seek further enforcement powers from Congress once it concludes its work. "This initiative will enable the Commission to take a closer look at acquisitions in this important sector, and also to evaluate whether the federal agencies are getting adequate notice of transactions that might harm competition," FTC Chairman Joe Simons said in a statement.

The inquiry announced Tuesday differs from a traditional investigation: Using its so-called 6(b) authority, the FTC can embark on wide-ranging reviews of entire industries without necessarily bringing a law-enforcement action. The agency in the past has invoked such powers to delve deep into drug prices, alcohol ads and gas gouging, experts said, often ushering about major changes in the markets and companies it studies. With big tech, the FTC is particularly interested in the smaller startups purchased by Apple, Amazon, Facebook, Google and Microsoft. Such deals typically aren't large enough to require companies under law to report them to agencies like the FTC, which would then review them for competition concerns. The document demands sent to all five tech giants require them to demystify these transactions, explaining their acquisition strategies and the ways they ingested startups -- and the data they amassed -- into their own services.

Security

Personal Data of All 6.5 Million Israeli Voters Is Exposed (nytimes.com) 28

A software flaw exposed the personal data of every eligible voter in Israel -- including full names, addresses and identity card numbers for 6.5 million people -- raising concerns about identity theft and electoral manipulation, three weeks before the country's national election. The New York Times reports: The security lapse was tied to a mobile app used by Prime Minister Benjamin Netanyahu and his Likud party to communicate with voters, offering news and information about the March 2 election. Until it was fixed, the flaw made it possible, without advanced technical skills, to view and download the government's entire voter registry, though it was unclear how many people did so. How the breach occurred remains uncertain, but Israel's Privacy Protection Authority, a unit of the Justice Ministry, said it was looking into the matter -- though it stopped short of announcing a full-fledged investigation. The app's maker, in a statement, played down the potential consequences, describing the leak as a "one-off incident that was immediately dealt with" and saying it had since bolstered the site's security. "Ran Bar-Zik, the programmer who revealed the breach, explained that visitors to the Elector app's website could right-click to 'view source,' an action that reveals the code behind a web page," the report adds.

"That page of code included the user names and passwords of site administrators with access to the voter registry, and using those credentials would allow anyone to view and download the information. Mr. Bar-Zik, a software developer for Verizon Media who wrote the Sunday article in Haaretz, said he chose the name and password of the Likud party administrator and logged in."

The flaw was first reported on Sunday by the newspaper Haaretz.
The Almighty Buck

Trump's 2021 Budget Drowns Science Agencies in Red Ink, Again (sciencemag.org) 413

It's another sea of red ink for federal research funding programs in President Donald Trump's latest budget proposal. The 2021 budget request to Congress released today calls for deep, often double-digit cuts to R&D spending at major science agencies. From a report: At the same time, the president wants to put more money into a handful of areas -- notably artificial intelligence (AI) and quantum information science (QIS) -- to create the new technology needed for what the budget request calls "industries of the future." Here is a rundown of some of the numbers from the budget request's R&D chapter. (The numbers reflect the portion of each agency's budget classified as research, which in most cases is less than its overall budget.)

1. National Institutes of Health: a cut of 7%, or $2.942 billion, to $36.965 billion.
2. National Science Foundation (NSF): a cut of 6%, or $424 million, to $6.328 billion.
3. Department of Energy's (DOE's) Office of Science: a cut of 17%, or $1.164 billion, to $5.760 billion.
4. NASA science: a cut of 11%, or $758 million, to $6.261 billion.
5. DOE's Advanced Research Projects Agency-Energy: a cut of 173%, which would not only eliminate the $425 million agency, but also force it to return $311 million to the U.S. Department of the Treasury.
6. U.S. Department of Agriculture's (USDA's) Agricultural Research Service: a cut of 12%, or $190 million, to $1.435 billion.
7. National Institute of Standards and Technology: a cut of 19%, or $154 million, to $653 million.
8. National Oceanic and Atmospheric Administration: a cut of 31%, or $300 million, to $678 million.
9. Environmental Protection Agency science and technology: a cut of 37%, or $174 million, to $318 million.
10. Department of Homeland Security science and technology: a cut of 15%, or $65 million, to $357 million.
11. U.S. Geological Survey: a cut of 30%, or $200 million, to $460 million.

Businesses

Amazon Wants Trump To Testify in Battle Over $10 Billion Pentagon Contract (cnn.com) 82

Amazon has asked a federal court for permission to get testimony from President Donald Trump and Defense Secretary Mark Esper as part of its ongoing protest over the Defense Department's handling of a multibillion-dollar cloud computing contract, according to a court filing unsealed Monday. From a report: The document also seeks permission to depose former Defense Secretary James Mattis and what he may have known about Trump's attitude toward the contract, known as the Joint Enterprise Defense Infrastructure. The decision on the motion to depose is expected in the coming weeks. It is incredibly rare, if not unprecedented, for a sitting US president to be deposed in a contract protest. In a footnote of the court filing, Amazon notes that "a deposition of a sitting President of the United States presents unique circumstances." Amazon argues in the document that the Pentagon's explanation for awarding the contract to Microsoft left out "crucial information and details that led to this flawed and potentially detrimental decision regarding DoD's future cloud infrastructure."
Facebook

Twitter and Facebook Criticized For Not Removing False Claims About Iowa Voters (siliconvalley.com) 109

What happened when conservative activist Tom Fitton issued an inaccurate press release last week about Iowa's voter registration rolls? After being debunked by Republican state officials -- and identified as "false" by the Associated Press -- the false claims simply remained on both Facebook and Twitter.

The Associated Press reports: Fitton, founder of Judicial Watch, tweeted a report claiming that eight Iowa counties have more people registered to vote than are actually eligible to vote. [Republican] Iowa Secretary of State Paul Pate moved quickly to counter the false information... Pate tweeted a link to the secretary of state's website, for those who wanted to check the numbers. "The county population numbers you claim are way too low. Dallas County's population, according to the U.S. Census Bureau, is nearly 9,000+ more than you claim, and Johnson County's is nearly 7,000 higher," Pate tweeted.

But the false information circulated Sunday and throughout the day on social media.

One tweet was retweeted over 40,000 times. But according to another report, that was just the beginning... The claim was amplified on Twitter by Fox TV host Sean Hannity, a close confidant of President Donald Trump... Fitton admitted in an interview that he "used older statistics and census numbers to reach his conclusion," the Associated Press reported. Judicial Watch's posts were still on Twitter and Facebook as of Wednesday afternoon.

A Twitter spokesperson said the Judicial Watch tweet was "not in violation of our election integrity policy as it does not suppress voter turnout or mislead people about when, where, or how to vote." Twitter last year banned political advertising on its platform.

Facebook, which controversially allows politicians to lie in political ads, did not provide a response to this news organization's inquiry about the Judicial Watch post. Facebook's director of product management has said the firm does not fact-check political ads for truthfulness and that those ads should be regulated by the federal government, not social media companies.

The Republican Secretary of State said in a statement that the false claims "erode voter confidence in elections."
Software

Shadow's Cancelled Nevada Caucus App Had Errors, Too (vice.com) 81

New submitter em1ly writes: A source familiar with the Nevada version of the error-ridden Iowa caucus app spoke to Motherboard about even more issues with the app. From the report: "After logging into the app, users were presented with a dashboard letting them submit how many caucus attendees they wished to add for each candidate, according to the app. A pop-up then asked, 'Are you sure you want to submit the first alignment? Please ensure all in-person participant counts are correct before confirming.' But submitting the counts for the first alignment did not work, according to a source. Motherboard granted the source anonymity to speak candidly about a technical issue. 'Error,' a second pop-up reads. 'Could not submit alignment.'" A Shadow spokesperson told Motherboard that "Because the deadline for the Nevada app was later, Shadow's Nevada app was still in beta testing, and that testing identified some errors that were being fixed." They also said that the app was on track for a "successful rollout" with the Nevada Democratic Party.

"There was a new release ready to test in Nevada following the Iowa caucuses. That version wasn't ready for use and has not been, and will not be released," they added.

Nevada Democrats have already said they will not use the app.
The Internet

Google and Facebook Turn Their Backs On Undersea Cable To China (techcrunch.com) 30

An anonymous reader quotes a report from TechCrunch: Google and Facebook seem to have resigned themselves to losing part of the longest and highest profile internet cable they have invested in to date. In a filing with the Federal Communications Commission last week, the two companies requested permission to activate the Pacific Light Cable Network (PLCN) between the US and the Philippines and Taiwan, leaving its controversial Hong Kong and Chinese sections dormant. Globally, around 380 submarine cables carry over 99.5 percent of all transoceanic data traffic. Every time you visit a foreign website or send an email abroad, you are using a fiber-optic cable on the seabed. Satellites, even large planned networks like SpaceX's Starlink system, cannot move data as quickly and cheaply as underwater cables.

When it was announced in 2017, the 13,000-kilometer PLCN was touted as the first subsea cable directly connecting Hong Kong and the United States, allowing Google and Facebook to connect speedily and securely with data centers in Asia and unlock new markets. The 120 terabit-per-second cable was due to begin commercial operation in the summer of 2018. Instead, it has been PLCN itself that has been disrupted, by an ongoing regulatory battle in the US that has become politicized by trade and technology spats with China.

Security

The Iowa Caucuses App Could Have Been Hacked (propublica.org) 120

A security firm consulted by ProPublica found that the "IowaReporter" app used to count and report votes from individual precincts in the Iowa Democratic caucuses was vulnerable to hacking. From the report: The IowaReporterApp was so insecure that vote totals, passwords and other sensitive information could have been intercepted or even changed, according to officials at Massachusetts-based Veracode, a security firm that reviewed the software at ProPublica's request. Because of a lack of safeguards, transmissions to and from the phone were left largely unprotected. Chris Wysopal, Veracode's chief technology officer, said the problems were elementary. He called it a "poor decision" to release the software without first fixing them. "It is important for all mobile apps that deal with sensitive data to have adequate security testing, and have any vulnerabilities fixed before being released for use," he said.

There's no evidence that hackers intercepted or tampered with caucus results. An attack would have required some degree of sophistication, but it would have been much easier to pull off had a precinct worker used an open Wi-Fi hotspot to report votes instead of a cell data plan. The U.S. Department of Homeland Security offered to test the app for the Iowa Democratic Party, but the party never took the government up on it, according to a U.S. official familiar with the matter who was not authorized to speak publicly. The official said the party did participate in a dry run, known as a tabletop exercise. The party did not respond to requests for comment on this issue.
Gerard Niemira, Shadow's CEO, said in a statement to ProPublica that "we are committed to the security of our products, including the app used during the Iowa caucuses. While there were reporting delays, what was most important is that the data was accurate and the caucus reporting process remained secure throughout."

"Our app underwent multiple, rigorous tests by a third party, but we learned today that a researcher found a vulnerability in our app. As with all software, sometimes vulnerabilities are discovered after they are released." He added that no "hack or intrusion" occurred during the caucuses, and that "the integrity of the vote in Iowa was not compromised in any way." The app is not currently in use, he said.

NBC News is also reporting that the phone number used to report Iowa caucus results was posted on 4chan on Monday night "along with encouragement to 'clog the lines,' an indication that jammed phone lines that left some caucus managers on hold for hours may have in part been due to prank calls."
Software

Motherboard Publishes 'Shadow' App That Blew Up the Iowa Caucus (vice.com) 222

Motherboard has chosen to publish the app used to tabulate early voting results in Iowa's Democratic Presidential primary. According to editor-in-chief Jason Koebler, "Trust and transparency are core to the U.S. electoral process," and "that's why Motherboard is publishing the app that malfunctioned in Iowa. From the report: The app, called IowaReporter, ultimately won't affect the vote totals of the Iowa caucuses, which are being recounted with paper ballots and other hard documentation. But the app's failure -- and the widespread attention this failure has received -- spurred chaos on election night, followed by speculation, conspiracy theories, and political jockeying. To try to combat that misinformation, it's necessary to offer complete transparency on what the app is, what it can and cannot do, and why it failed.

Motherboard obtained a copy of the app. By decompiling and analyzing it, it's possible to learn more about how the app was built and what might have gone wrong during the Iowa caucus. We reached out to several security researchers and asked them to analyze it for us, and have published an article about their findings. Motherboard waited to publish the app until Shadow, which controls the app's back-end servers and accounts, confirmed that it had been taken offline. [Shadow Inc. CEO Gerard Niemira] stressed that no voter data could be accessed from the app or from any of the databases it used. What we are publishing is an inert app that is no longer being used for an election, that the DNC has stated will not be used in future elections, and that is no longer connected to backend servers or services.
You can download the Android .apk file here.

UPDATE 2/6/20: A security firm consulted by ProPublica found that the "IowaReporter" app was also vulnerable to hacking. "The IowaReporterApp was so insecure that vote totals, passwords and other sensitive information could have been intercepted or even changed," reports ProPublica. "Because of a lack of safeguards, transmissions to and from the phone were left largely unprotected."
Republicans

Split Senate Acquits Trump of Impeachment Charges (politico.com) 690

The Senate on Wednesday acquitted President Donald Trump on two articles of impeachment, rejecting the House's charges that he should be removed from office for abusing his power and obstructing the congressional investigation into his conduct. Politico reports: The vote capped a frenetic four-month push by House Democrats to investigate and impeach Trump for allegedly withholding U.S. military aid from Ukraine to pressure its leaders to investigate his Democratic rivals, including former Vice President Joe Biden. The impeachment articles also charged Trump with obstructing the House's investigation into the matter.

The first article, abuse of power, failed 48-52 -- well short of the 67-vote super-majority required to remove Trump from office. Utah Sen. Mitt Romney was the lone Republican to vote in favor of the abuse of power charge. The second article, obstruction of Congress, failed 47-53 -- a party-line vote. All Democratic senators voted to convict Trump on both counts. Chief Justice John Roberts, who presided over just the third presidential impeachment trial in U.S. history, announced the result on each article of impeachment Wednesday afternoon, bringing the three-week trial to a close.
"The Senate, having tried Donald Trump, president of the United States, upon two articles of impeachment exhibited against him by the House of Representatives, and two-thirds of the senators present not having found him guilty of the charges contained therein: it is, therefore, ordered and adjudged that the said Donald John Trump be, and he is hereby, acquitted of the charges in said articles," Roberts said.
Democrats

How a Bad App Plunged Iowa Into Chaos (theatlantic.com) 269

Zeynep Tufekci, writing for The Atlantic yesterday: The morning after caucus-goers filed into high-school gyms across Iowa, the state's Democratic Party is still unable to produce results. The app it developed for precisely this purpose seems to have crashed. The party was questioned before by experts about the wisdom of using a secretive app that would be deployed at a crucial juncture, but the concerns were brushed away. Troy Price, the state party's chairman, claimed that if anything went wrong with the app, staffers would be ready "with a backup and a backup to that backup and a backup to the backup to the backup." And yet, more than 12 hours after the end of the caucus, they are unable to produce results. Last night, some precinct officials even waited on hold for an hour to report the results -- and got hung up on. It appears that the Iowa Democrats nixed the plan to have precincts call in their results, and instead hired a for-profit tech firm, aptly named Shadow, to tally the caucus results. The party paid Shadow $60,000 to develop an app that would tally the results, but gave the company only two months to do it. Worried about Russian hacking, the party addressed security in all the wrong ways: It did not open up the app to outside testing or challenge by independent security experts.

This method is sometimes dubbed "security through obscurity," and while there are instances for which it might be appropriate, it is a fragile method, especially unsuited to anything public on the internet that might invite an attack. For example, putting a spare key in a secret place in your backyard isn't a terrible practice, because the odds are low that someone will be highly motivated to break into any given house and manage to look exactly in the right place (well, unless you put it under the mat). But when there are more significant incentives and the system is open to challenge by anyone in the world, as with anything on the internet, someone will likely find a way to get the keys, as the Motion Picture Association of America found out when its supposedly obscure digital keys, meant to prevent copyright infringement, quickly leaked. Shadow's app was going to be used widely on caucus day, and independent security experts warned that this method wasn't going to work. The company didn't listen. If Shadow had opened up the app to experts, they likely would have found many bugs, and the app would have been much stronger as a result. But even that process would not have made the app secure.

Democrats

Iowa Caucus Debacle is One of the Most Stunning Tech Failures Ever (cnbc.com) 439

The Iowa caucus debacle represents one of the most stunning failures of information security ever. From a column: This failure was delivered by the same Iowa Democratic Party officials who have said for the last four years they were "ramping up" their technology capabilities, convening seemingly endless security task forces to ensure foreign powers did not disenfranchise voters, and collaborating with federal agencies like the Department of Homeland Security to make sure everyone was in the loop on voting security. Voters will be paying close attention to how party leaders ensure that votes going forward have clear contingency plans in place, not just to protect against hackers, but from all types of technology failures, including applications that might not work.

Iowa officials counting the results coming in Monday from the caucusing app reported irregularities that required them to switch from the app to counting votes manually. Party officials said the "underlying data" put into the app was fine, but it is unclear as of yet how they know this or even what they consider "underlying data." "Last night, more than 1,600 precinct caucuses gathered across the state of Iowa and at satellite caucuses around the world," the Iowa Democratic Party said in a statement Tuesday. "As precinct caucus results started coming in, the IDP ran them through an accuracy and quality check. It became clear that there were inconsistencies with the reports. The underlying cause of these inconsistencies was not immediately clear, and required investigation, which took time."

Slashdot Top Deals