Cyber Security Predictions for 2017

2016 was a big year in the annals of Cyber Security, and 2017 promises to eclipse it.

Creating an Enterprise Data Strategy

An introduction to the process of developing comprehensive strategies for enterprise data manangement and exploitation.

A Framework for Evolutionary Artificial Thought

Let’s start at the beginning – what does this or any such “Framework” buy us?

The Innovation Dilemma

What things actually promote or discourage innovation? We'll examine a few in this post...

Digitial Transformation, Defined

Digitial Transformation is a hot topic in IT and big money maker for consultants - but what does it really mean?.

Showing posts with label Clinton. Show all posts
Showing posts with label Clinton. Show all posts

Friday, December 16, 2016

The 5 Principles of Cyber Warfare

This week we got a partial glimpse into the types of action that the United States might consider to be acts of Cyber Warfare. I had written about this topic 2 weeks ago in regards to Voting Integrity in the face of Russian cyber attacks, but the story has escalated since then – culminating this week in direct accusations against the Russian government. The CIA and even President Obama have directly implicated Putin as being personally involved with the deliberate aim of swaying the 2016 election. In a year of big stories, this may have been the most far reaching in its implications. One of those implications, which has already been alluded to by many in Washington, is that this act may in fact represent a form of Cyber Warfare.

So, what exactly does Cyber Warfare mean and how does it differ – if at all – from Cyber Terrorism? That’s a tough question, one that I’ve not seen answered clearly before. Cyber Terrorism can come from nation states, such as China, North Korea, Iran and so forth, but one might expect that actions perpetrated by nation-states are less like terrorism per se and more like warfare. It is worthwhile at this point to step back into the not too distant past and bring up a similar question that also still applies here – what’s the difference between a “Cold” and a “Hot” war? The Cold War, as you might remember, involved a whole host activities from espionage to proxy wars. The Hot or real war between the super-powers never occurred and it didn’t happen primarily because of the concept of Mutual Assured Destruction through use of our nuclear arsenals. In that case, the distinction between the terms also involved both the nature of the participants as well as the types of activities involved which is similar to the current question.
None of this really helps though to clear up the confusion regarding what is or what isn’t Cyber Warfare. Here are a few reasons why:
  • Cyber Warfare can be both covert and overt – depending on the nature and intent of the attacks as well on the determination as to whether they should be publicized in any way.
  • Cyber Warfare could be conducted by both Nation States and Terrorist organizations. The key distinction here though would be that we wouldn’t necessarily classify acts committed by smaller unknown groups or even individuals as Cyber Warfare. In those instances, the term Cyber Terrorism might be more applicable. However, it is also clear that in Cyber Warfare, as in traditional warfare, non-nation state organizations can and have conducted offensive operations.
  • Cyber Warfare can be a standalone or blended activity (e.g. coordinated with other traditional war-fighting activities). It’s conceivable that an entire conflict could be fought solely within the Cyber Domain. Cyber “Domain” here refers to the notion that Cyber represents one of several potential war-fighting domains such as Land, Sea, Air and Space. The US military formally acknowledged Cyber as such a domain with its creation of US Cyber Command several years ago. Of course the reality of this statement is more complicated than it sounds as Cyber also infiltrates all other warfare domains through the technology implied by it – it is cross-cutting domain and even if an attack were completely limited to Cyber actions it is highly likely that physical capabilities (such war-fighting assets as ships, planes etc.) might be impacted.
  • Cyber Warfare can be directed at the Government or the Industrial Base or both. We can’t say for example, that all attacks against businesses must be considered Terrorism per se – the intent is what’s important. If the intent of an attack is to cripple the country that’s been targeted, then a Cyber attack like that is no different in principle from the types of bombing raids we conducted against Germany in WW2 in order to cripple its industrial base. Today though, the sectors that are perhaps more vulnerable might be Energy and Finance as opposed to Manufacturing. The results might be the same though if the goal is hobble an economy or otherwise disrupt a nation state.
Now, we are ready to consider what the distinctions between Cyber Warfare and Cyber Terrorism really are. They would likely involve the following considerations:
  1. Cyber Warfare must necessarily consist of a sustained campaign of Cyber activities, designed to disrupt any mission critical functions of an enemy at a national level. This doesn’t mean the activities have to occur in many places to effect a national impact, it merely has to be designed to impact an opponent that way (and would also likely encompass more than one attack or incident).
  2. Cyber warfare must necessarily occur between substantial Cyber combatants. The nature of what constitutes a ‘substantial’ combatant lies in what resources they have to bring to bear in any given conflict. A well-established terrorist or rebel group may have the money and personnel to manage sustained attacks. However smaller groups with few resources may only be able to sustain limited operations or a single attack. While there is always the possibility that an individual or a small group might be able to do harm at the national level, it is unlikely that they could sustain this over months or years and it would be more akin to one-off terrorism than warfare in the context of sustained operations and likely outcomes.
  3. Cyber warfare, in general, involves more specific objectives in contrast to Terrorism which is often random in nature and may only be focused on making a statement rather than effecting some desired outcome.
By these definitions, I’d have to say that the Russian hacking of the DNC computers and related activities designed to impact the 2016 election falls under the category of Cyber Warfare rather than Terrorism. And this begs the question, why does all of this matter and why do we need more specific definitions? The bottom line is, that if we don’t have a clear idea of what represents acts of Cyber warfare (either covert or overt), it’s highly likely we won’t be able measure our response properly. Deciding how to respond is obviously a very big deal – as any such decisions could quickly escalate from the Cyber domain into all the others. Perhaps our government does have all of this worked out, and maybe it’s just too secret for any of us to know about. However, from our vantage point now it’s all bit fuzzy. When the President says “we will retaliate in a manner and time of our own choosing” we basically don’t have a clue to what that really means.
Rather than spend a lot of time speculating as to what our response might be, we can instead highlight some principles that may apply to any such situation. The following principles represent a potential framework that might be used to help deal with Cyber warfare as it continues to evolve.
  1. Proactive Awareness – In order to survive or win any Cyber conflict, the nation needs to know when in fact it is under attack. Some attacks are more obvious than others and as the recent election shows, our response can be slow or too late to avoid impacts. Proactive Cyber Awareness is not about hacking into everyone’s cell phones, but rather it is about being able to identify unusual behavior in key systems and sectors across the country (or wherever our interests may be). This means we need more selective and actionable intelligence then we seem to be getting now.
  2. Measured Response – This has been mentioned in the news, but as I noted it’s not been explained by anyone (at least publicly) yet. For this to actually work, someone needs to define the measured responses up front rather than assessing each event as if it were the first time it had been considered. The landscape is fairly complicated so this involves a lot of work and some automation. However, it shouldn’t fully automatic any more than our current traditional war-fighting capabilities are – the human in the loop must always be present.
  3. Defined Escalation Approach – This is a process and it ought to be built atop the measured responses defined previously, the idea being that whenever or wherever Cyber activities begin crossing over to other areas there needs to be another level of safeguards built in to avoid any type of cascading escalation that could lead to something like a nuclear conflict.
  4. Maintain a Consistent Policy - In theory, our management of Cyber war shouldn’t be unique in each potential scenario – there ought to be a consistent expectation as to what will happen if enemies launch attacks against the US. This is a key point in the recent debate over Russia as the situation has also become embroiled in US political differences, confusing the matter. While there will always need to be specific considerations given to certain situations, we should never give an indication to any opponent that Cyber attacks may be permitted without any response coming from the US. This would be an extremely dangerous precedent and helps to explain why the President and CIA made statements this week to the effect that election interference would not go unpunished. Better late than never and like all of warfare, if we're in the game we should build policy around what's necessary to win - as opposed to settling for mere survival. There may such as a thing as a Cyber Maginot Line...
  5. Continuous Innovation – This may be the most important point, given the stark reality that it is easier and more cost effective to mount a Cyber attack than it is to defend against one. Despite the billions spent each year in the US across government and the private sectors, Cyber Security breaches and attacks have only become more prevalent and severe. More focus needs to be given to pushing the envelope on innovation to help reduce the current advantages enjoyed by our Cyber opponents. Today, much if not the majority of innovation has come from the attackers and we’ve been playing catch-up. As in every other realm of warfare, the side with the greatest technological advantage tends to win.
It’s anyone’s guess as to whether the current Russian hacking crisis will boil over into something more, but one thing is certain, the age of Cyber Warfare has most definitely dawned.

Copyright 2016, Stephen Lahanas

Saturday, December 10, 2016

Technology & The 2016 Election part 4: A New Age for Political Campaigning

In this latest post in our series, we’ll look at how lessons from the 2016 campaign will be applied in all future campaigns – and not just at the national or presidential level…
Will this year’s election change the way campaigns will be run from here on out? In a word, yes. Is this due to any single innovation or any single campaign or candidate? Not really, the trends that emerged this year encompassed new techniques that worked across campaigns as well as old ones that failed unexpectedly in others. Let’s take look at what worked and what didn’t.
What Worked in 2016 across Campaigns? Here are a few items:
  • Platforms as Memes
  • Momentum Building & Fund Raising through Social Media
  • And Free Media
  • Targeted Polling / Selective GOTV / Sentiment Analysis
Platforms & Candidates as Internet Memes – The two candidates who exploited this best were Bernie Sanders and Donald Trump. Both employed what seemed to be odd or unconventional messaging, but messaging that soon took viral flight. ‘Build the wall,’ ‘Feel the Bern’ and “Drain the Swamp” combined with other images or phrases helped to shape campaign identities and build a sense of community among supporters. The successful Memes were ones that harnessed or stoked discontent but discontent that was coming from both ends of the political spectrum. Memes are somewhat complex and a bit difficult to understand for people who are deliberately setting out to create them – they tend to take on a life of their own and are often unpredictable. I suppose a good analogy to what existed before I politics that was somewhat like this were extremely famous campaign jingles or something like the “Daisy Ad.” Memes combine public relations, advertising, political discourse into neat recognizable bundles – a trend that also extended to other aspects of messaging this year.
Exploitation of Social Media as the Primary Channel to Reach Voters - This was new and as noted in a previous post, President Elect Trump is still using it even now as his primary mode of communicating with the electorate. The traditional media establishment wanted to write off both Bernie and Trump so their campaigns both bypassed it and this year – that actually worked. Social media was how all momentum was created in both campaigns and it was well integrated with the rallies. One might think of these campaigns as ‘crowd-sourced politics’ – with each candidate raising most of their funds from small donors (more the case with Bernie than Trump). This latter development was perhaps the most shocking aspect of the campaign given the recent flood of dark money into politics after the Citizens United decision by the Supreme Court in 2010. Had Bernie won instead of the Billionaire Trump, the crowd-sourcing aspect of the election would have taken on much greater significance, potentially heralding an end to big money influence in politics. The fact that Trump used it to win though makes it all the more fascinating.
Free is Good, and now it’s Effective Too – The King of Tabloids knew from the start that a certain type of communications approach was likely to garner non-stop free election coverage. The fact that other candidates were able to generate almost as much attention without sounding quite so sensational was surprising. If effectiveness is measured in how many people hear a message and actually listen, then the free media given to Sanders and Trump definitely eclipsed traditional media buys this year. In some ways, it might be worthwhile to pronounce the traditional campaign ad as obsolete. Although, that might be a bit premature, as some state races saw effective use of television buys as in Ohio. But in the Ohio Senate race for example, it was a traditional media campaign poised against another poorly funded traditional media campaign instead of a proactive social media campaign. In the future, all media will likely start in Social Media and if it expands into Traditional media buys, it will do so as part of a larger campaign still driven from Social Media (to reinforce its effectiveness). For example, the cost of one professionally produced campaign video distributed let’s say on a state level, one could easily create 100 social media videos or podcasts and distribute them free nationally. The fact that media looks perfect isn’t what should be important here – it’s getting the message across to the audience that needs to hear it. If it isn’t as slick as a Hollywood movie so what – if it looks and feels genuine – so much the better.
Zeroing on the Voters – GOTV – We learned in 2016 that getting out the vote can definitely be more efficient and that discouraging the vote is now a widely accepted campaign practice by many and highly effective. The Trump campaign introduced innovations such as use of a mobile app that allowed door-knocking volunteers to register every house they visited and instantly update the information to the Cloud. This combined with a more targeted type of informal polling, designed to help drive tactics and message, made the Trump campaign particularly effective.
What didn’t work in 2016? That includes…
  • Traditional GOTV
  • Traditional Media
  • Traditional Messaging (conservative versus sensational)
We might even add ‘Traditional Candidates’ to the list, as the overall mode for change seemed to imply that as well. Whether national discontent has been stoked beyond the realm of reason or whether it’s been justified is a difficult question. While ordinary Americans have found it hard to get ahead, the country itself has been doing pretty well by all the objective measures used by both parties in the past. Unemployment for example is down to some of the lowest levels in terms of jobless claims since the 1970’s. This is all the more incredible considering we were on the brink of a Depression in 2008. Be that as it may, though, the perception this year was that government is ineffective and the usual cast of suspects were – well suspect. That led to a lot of what had worked before to fail utterly this year.
Traditional GOTV – The key part of this phrase is Get Out, if your voters do not go out and vote, the candidate doesn’t win. This year there were also some fundamental errors made in terms of where to focus the GOTV efforts. The Clinton campaign lost crucial votes from minority communities and women and focused perhaps too much on trying to shore up their union and white working base. This may sound counter-intuitive given all of the commentary after the election about how Clinton lost the white working class male vote. But the fact remains and should have been recognized by the Clinton campaign that she had really lost that vote and should not have wasted time knocking on many doors that turned out to belong to Trump supporters. This was evidence of poor internal polling and an inability to quickly adjust to changing circumstances. In the 3 swing states where recounts were requested, the difference in women, African Americans and Latinos who didn’t vote at all may have carried each of those states for Clinton had she been able to get them out of the house. Previous technology innovations such as Robo-Calling weren’t working so well this year and the Clinton campaign did a relatively poor job of generating enthusiasm in much of the party base. Some of this was due to the harsh Primary but some of it was also a lack of understanding in how to properly use technology to help organize, motivate and target voters.
Traditional Media Didn’t Work – Clinton’s slick media campaign lacked the personal touch that made Bernie more accessible and Trump more exciting. Anything that was too polished, too familiar this year, was likely to remind the voters of how often they’d seen professional politics played before. That didn’t go over so well this election cycle and may not ever again. It seemed at times that the Clinton strategy was to stay above the fray and play it safe, allowing a flood of attacks to go unanswered on social media or traditional media (and using traditional media to try to respond to all of that would have been impractical).
Traditional Messaging Didn’t Work – We’ve gotten used to vague political messages that often didn’t connect with our personal concerns or interests. However, vague personal messaging seem to work pretty well. Those who made their messages more personal this year and found a way to deliver them in a more direct manner, did exceptionally well. Even if you weren’t an insider, sounding like an insider was problematic this year. This is all very understandable though if we consider that people seldom have the opportunity to communicate with their elected representatives – any message or medium that allows there to be a sense that two-way communication is happening is likely to be well-received.
Another reason traditional messaging didn’t work well this year is that the dynamic Social Media driven campaigns of Sanders and Trump understood how to condense their messaging to levels never before experienced in American politics. What does that mean? Didn’t every campaign since Washington’s depend on relatively simplistic slogans? Well, yes and no. In the past there was both the shorthand and the detailed message. The slogans, posters, ads and jingles were the shorthand – but there was generally real substance backing all of that up. This year, in the Trump campaign in particular, substance was viewed as a liability and largely disregarded – it was truly the Twitter platform. Every issue had to be explained in 140 characters or less, with little or no expectation for further elaboration.
From this point forward, we’ll see several important trends emerging in nearly every political campaign for better or worse:
  1. Communications / Media directors will now probably be referred to as Social Media Directors and all communications will be coordinated in that context.
  2. Voter polling and targeting within campaigns will become more selective and more accurate – with a focus on ensuring that the solid base is turned out with less concern about the margins. The margins will likely be dealt with more through messaging than with GOTV.
  3. Messaging will also be likely dedicated in most campaigns to discourage the margins and some of the opposing base to vote at all. While Negative campaigning is nothing new, the art of increasing the opponent’s negative ratings has reached all time heights this year and it’s unlikely that this type of success will be ignored. And more candidates will follow the trend to “Twitterize” their platforms.
  4. Campaign litigation will increase. As more voter suppression laws proliferate and Gerrymandering becomes more prevalent, the focus of election contests for decades to come will address both election outcomes and the underlying electoral systems themselves. It is important to note that at this time, there is one side in American politics that is consistently behind voter suppression but that’s not to say that someday things couldn’t flip – it’s happened before. Campaigns will be facing these types of issues in nearly every election from now on, so if you thought this campaign might finally put an end to the age of Hyper-Controversy, think again, it’s just starting.
In my next post and the last in this series, I’m going to look at how all of these types of changes will impact you the voter and how you can prepare for it in upcoming elections.

Copyright 2016, Stephen Lahanas

Sunday, December 4, 2016

Technology & Election 2016 part 3 – The Failure of Data Science?

The first reaction on election night, November 8th, 2016 was – what, how did that happen? The entire country and in fact the whole world was more or less shocked at the unexpected outcome. But why was it so unexpected? The top level answer to that is simply that nearly every major poll or projection turned out to be wrong. What kind of numbers are we talking about? For example, Nate Silver’s FiveThirtyEight blog projected Clinton to win by about 5% in the popular vote (with 71% certainty). If we drill down to the state polls we see that the projections showed all 3 key turnover states, Wisconsin, Michigan and Pennsylvania going to Clinton by 3 to 5% in each contest. This is significant because many of these projections (and blogs like FiveThirtyEight) were using aggregates of dozens or hundreds of polls, not just one or a handful and the differences exceeded the margin of error.
Let’s step back for a moment and talk about the typical role that Data Science plays in the election process today. This role encompasses several well-known and some lessor known functions, including:
  • Predictive polling
  • Exit polling
  • Predictive modeling
  • Vote targeting (which facilitates a sort of CRM for campaign marketing as well as Get Out the Vote efforts)
There’s nothing new about polling, it’s been around for a long time. In fact, the last time there was a collective shock like this year’s outcome was in 1948, when the polls had predicted Dewey would win (by 50 to 45% - but Truman won by 50% to 45%). Polls have improved since then and of course, now we have the benefit of the latest data technology as well as 70 years of added experience, so how did nearly every major poll get it wrong this year? There are some theories; they include the following:
  1. A lot of people changed their minds at the last moment and weren’t particularly firm in their previous opinions.
  2. The Russians did it.
  3. Many polls were not properly targeting prospective voters for their models.
  4. Many people who had said they were voting for Clinton didn’t turn out to vote at all (e.g. the lack of enthusiasm)
  5. The poll numbers for the 3rd party candidates may have been inflated, and when it came to election day these candidates received far fewer votes that had been predicted (the implication being they went ahead and voted for one of the main candidates with Trump being the main beneficiary).
To be honest, we may never have a fully satisfactory answer for what happened in the 2016 election. It is likely that we’ve never had a race where both of the main candidates were universally unpopular and that kind of situation might never happen again (and there’s no telling how that may have impacted the polling results). How do we move forward then? Did technology, did Data Science fail us in 2016? Maybe, but probably not. What we witnessed however is that technology is only as good as our ability to apply it. If situations become more dynamic, complex within a relatively short window, do we stick with what we know or do we adjust our models or practices?
I’d like to step back for a moment here and ask a larger question. Do we really want ironclad predictions before elections in the first place? Before the big upset on election night, many pundits were talking about the lessons learned from the 1980 election where results from the East Coast encouraged West Coast voters to stay home thinking their votes didn’t really count. Because of that, the FEC passed a rule prohibiting networks from announcing winners before certain polls close. Don’t polls predicting a sure outcome before an election have a similar chilling effect? This year for example, how many voters may have stayed home because while they weren’t terribly enthused about Clinton, thought she would win? That’s a hard question to ask because people who don’t show up to vote can’t be interviewed in exit polls (or at least typically aren’t interviewed as part of the election post mortem).
What can we do in Future to avoid getting surprised?
I think it is important that in coming up with suggestions here, we need to weigh the relative value of using a particular solution with the potential impacts of using it. In other words, if we view predictive polling as a relativistic activity (e.g. a bit like Heisenberg’s principle in that taking a measure can influence the outcome), then we might conclude that the highest value of such predictive polls relative to possible harm might end several weeks before the election. How then could we be assured that elections are honest, that public sentiment is in fact aligned with election results? Well, that can still come through exit polling – polls taken of actual voters on election day and in addition, sentiment polls taken the day after the election of potential voters who didn’t vote (something that doesn’t typically happen now).  
Suggestion – Place a moratorium on predictive polls at least 2 weeks prior to election day and preferably 4 weeks prior. Why would this work? Here are few potential benefits of doing it:
  • This has the immediate effect of not making the election as much of a horse race and more of a contest of ideas.
  • It has at least the potential of driving up voter participation – a lot can happen in 4 weeks, people can vote based on their opinions and do a little less hedging in making their decisions.
  • It helps to combat Group-think (people swarming to the anticipated victor or becoming despondent about their own preferred candidates)
  • It certainly eliminates the main source of any potential surprise.
  • It may encourage candidates to take a more expansive view towards courting voters, recent trends have focused way too much attention on potential swing states and districts.
As you can tell, this and potentially other suggestions may have relatively little to do with Data Science itself, but have everything to do with how we apply it to given situations. I don’t believe the technology failed us here, I think we failed to recognize how much it already influences election outcomes. In my next post in this series, I’ll talk a bit more about Get Out the Vote (GOTV), politics as demographics and how technology has been and will be used to manage campaigns.

Copyright 2016, Stephen Lahanas 

Saturday, December 3, 2016

Technology & the 2016 Election Part 2: Voting Integrity

This is my second post on how the 2016 was defined not so much by flamboyant personalities but rather by the influences of technology in the election process. Today, I’m going to take a look at voting integrity, foreign influence and cyber threats.
At this very moment, election officials in Wisconsin are preparing to conduct an election recount requested by 3rd party candidate, Jill Stein. The request came after an blog post appeared written by a professor Alex Halderman who is on the board of advisors for the Verified Voting organization. In that post, Halderman stated that while there was no obvious evidence of voter fraud in the election, there were legitimate concerns regarding voting integrity based on a number of factors that have emerged from this year’s election.
So, why should we care about those concerns, isn’t just politics as usual? Good question. Here are some of the elements of this year’s election which seem a bit unusual:
  • Initial claims that all of the elections (and I refer to elections here because each State manages them somewhat differently, but we’ll come back that in a moment) were going to be rigged – this in itself was very strange and went so far as Trump stating he might not support the results if he lost. I can’t be sure of it, but I’m fairly certain that might be the first time in American history where a major candidate made such a statement.
  • Documented instances of election-related hacking by a foreign power and warnings of potential further acts from the US Intelligence Community. This accusation didn’t come from one party or another – it came from the FBI in October.
  • Potential interference by the same foreign power in other elections – There are indications that Russia may have also been involved in trying to influence the Brexit vote in the United Kingdom and this week, the head of German intelligence made an announcement that Russians may be prepared to launch attacks next year (with the aim of disrupting elections).
  • Discrepancies in exit polling and ballot results in some locations. Only one poll out of 100’s accurately predicted the national outcome and many state level polls turned out to be wrong as well. While this in itself may be explainable due to margin of error and last minute shifts in sentiment, when take into context with the rest of what’s been happening it seems at least a little bit fishy.
It is worth noting here that when we’re talking about potential election Fraud, there is a somewhat bizarre disconnect in the US as to what election fraud actually represents. Let’s take a look at that for a moment…
The Question of Election Fraud – The Big Picture
One thing that has puzzled me over the years, especially since the emergence of electronic voting, is why in the US, almost all discussion of voter fraud happens within the context of individual voter fraud. To me this is bit like saying that the only important crime that occurs is shoplifting at convenience stores while hacking into accounts and stealing billions of dollars isn’t troubling at all. Granted, petty theft is real and it is a problem, but one would have to ask does it represent a threat to our financial system? Obviously, it doesn’t. And perhaps this isn’t the best analogy ever (as there is far more petty theft than documented voter fraud on the individual level) but it helps to make the point in terms of scale and impact. We can’t see the forest for the trees here – we’ve simply been having the wrong conversation. The conversation should be about how intelligent enemies of Democracy, nation-states or terrorists could use their resources to influence or disrupt our political system by manipulating the American electoral process. And we need to keep in mind that this is not a partisan contention tied to any one election – it should be of equal importance to all sides within our political spectrum and applies to all current and future election cycles.
Another key point is the pragmatic nature of effective election manipulation. How would one of these rogue nations or organizations go about interfering in the American election process? Well, it would happen in one of the following ways (or potentially through a combination of them):
  • Through infection / control of individual voting machines with malware designed to manipulate votes. Moderately Effective
  • Through infection / control of election ‘back office’ systems, designated to aggregate vote totals. Now many people may not realize but these systems have been around for quite some time (since the 1960’s).  Most Effective
  • Through interception of vote totals between systems (data in transit). Moderately Effective
  • Through manipulation of Voter Registration information systems / data. Moderately Effective
We could also add to these the relatively intangible types of interference like those mentioned in part one of this article where I described briefly how fake news is being used to help shift voter sentiments. All of these things are hardly new (except that the technology has simply made it easier to manipulate large numbers of votes simultaneously) and have occurred in other countries before – some of them might be considered “Black Ops” and at one time were just standard features of Cold War proxy contests in the American & Soviet spheres of influence. The thing is though, back during the Cold War, these types of things happened elsewhere, not in the United States itself.
Bottom line - If someone really wanted to influence an election, they could do it in a number of meaningful ways and all of those ways involve technology at a system rather than an individual level.
This seems less about politics and more like Cyber Security, doesn’t it? In Cyber Security, the obvious question that one starts with regardless of the industry or context is this; if it is reasonable to assume that a vulnerability exists that someone, sometime, somewhere eventually could exploit – will it actually be exploited? The answer to this question is almost always yes and this has been borne out by events. While there is often a time delay between the appearance of a perceived vulnerability and the exploitation of that vulnerability, eventually the exploit does happen. Moreover, the incentive to perform an exploit is almost always directly proportional to the perceived value of the attack. What could be more valuable than changing the outcome of an American national election? Not much.
Elections and Foreign Interference
One of the most fascinating aspects of this election has been the unprecedented nature of foreign involvement or intervention in the process itself. And almost as surprising perhaps is the reaction or lack of reaction among the electorate in response. Until early this year, China had been the long-time headline grabber in relation to high profile hacks in the US. This year, Russia emerged as the most publicized perpetrator of cyber incursions, but the reality is that there are a number of other nations  and groups that are perhaps equally equipped to cause damage to either our political or economic systems. The identity of this moment’s headliner is much less important than the idea that we have weaknesses that any such attacker could choose to exploit. But that begs the question, what is it about our election process that makes it vulnerable. Here are a few points to consider:
  • We don’t have one election process, the reality is we have 50. Worse, we don’t have an ironclad underlying set of agreed upon technical standards which are consistent across all 50 states and there is no real authority to enforce it if we did anyway. There have been some standards developed by NIST and through a series of bills passed by Congress since 2000. But adherence to the standards (which are still somewhat inadequate) is contingent upon each State’s interpretation of them.
  • Even within a given state, from one State administration to the next, many if not most of the rules can change depending on the political agenda of whomever is in charge.
  • Conflicts of interest regarding who can own and sell electronic voting related equipment have never fully been resolved.
  • Then there is the Electoral College, which presents unique challenges to the country and one glaring vulnerability. The vulnerability boils down to this – given the way the college works – any attacker need only manipulate votes in a handful of states by a relatively small percentage to change the overall national result. Of course, this only applies to the national election but that is our most important one. For this to work, the polls in the targeted states would have to be within the statistical margin of error (1 to 3%), but that’s not uncommon at all. As we’ve seen time and again that margins of popular votes and electoral votes aren’t always aligned so an expected outcome can appear ‘normal.’ And this is why the current recount challenges have been targeted to Wisconsin, Michigan and Pennsylvania as all three came with 1% or less margins of victory. If we added the total of the 3 states’ electoral votes it comes to 46, which conceivably if all awarded to Clinton would flip the outcome of the election. I’m not saying that will happen, but it presents an example of the point here, that 3 states can easily tip a national election one way or the other.
So, what can we do if we do wish to recognize this threat and not dismiss it as politics as usual? Here are a couple of suggestions:
  • Provide tougher standards which ought to be applied uniformly across all 50 states for voting system security.
  • Ensure finally that every voting machine has a paper audit (e.g. prints a paper receipt ballot).
  • Regularly audit, monitor and test voting system security before during and after elections. Such audits must include random recounting of the paper trail (as opposed to an electronic recount) as well as examination of code both at the voting machine and back office level.
  • Give a more active role to America’s intelligence community to detect and counteract foreign threats or intrusions into our political processes. This is the real mission for which these agencies are chartered – it’s time we made election protection a national priority.  
  • Block spam / fake news sites from broadcasting into the US – specifically filtering out content originating from places where such campaigns a known to happen (Eastern Europe, etc.)
  • In situations where large scale breaches are detected, be prepared to redo elections as needed using paper ballots only (and provide funds to support these contingencies).
Ultimately, our form of government is only strong as the processes used to run it. Of those processes, elections are perhaps the most important single component. We can lose confidence in government but there’s always the hope of electing a better one, but if we lose confidence in voting, where does that leave us?

Copyright 2016, Stephen Lahanas