Voting systems that rely on the Internet are fast becoming a major conflict zone in the battle to secure the 2020 election against hacking.

The development comes as states are scrambling to revamp their voting procedures to respond to the novel coronavirus pandemic. In some cases that means allowing digital voting to play a more prominent role, despite persistent warnings from experts that it's highly insecure and often unverifiable.

The Department of Homeland Security, the FBI and the Election Assistance Commission jumped into the fray on Friday, sending guidance to states warning about the major security challenges posed by all voting systems that use the Internet in some way. The guidance covers ballots sent digitally to voters; ballots sent and marked online but printed out and returned by physical mail; and ballots that are received and returned entirely digitally.

The agencies warned about dangers related to all three systems but especially the third, which they say poses “significant security risks.” Among those risks: Hackers could change large numbers of votes, block votes from being recorded or undermine ballot secrecy.

Securing the 2020 election presents a set of dramatically different challenges than even just a few months ago when it seemed nearly unthinkable states would willingly expose more of their voting processes to the dangers of hacking and most election security debates focused on ensuring votes would be cast with paper ballots that could be audited after the fact. 

The new situation underscores how the coronavirus pandemic has upended every aspect of election security, propelling the 2020 contest into far more dangerous territory. 

The move to voting that relies on the Internet in some fashion has been limited so far. But that could change. 

West Virginia, Delaware and New Jersey have announced plans to pilot app-based voting systems for parts of the electorate in upcoming primaries, including military and overseas voters and voters with disabilities that make voting by mail impractical. 

Other states and counties are contemplating systems to allow voters to receive, mark or return their ballots using online systems. But the focus of the debate is mostly on receiving and marking ballots that voters can later mail to officials or drop off in secure lock boxes. 

But federal officials fear online balloting could become more attractive as states complete primaries delayed by the pandemic and turn their attention to preparing for the general election. 

Those elections will be burdened by a bevy of new costs related to the pandemic but have received only a fraction of the money necessary to implement them from the federal government. It would cost about $2 billion for states to implement all the necessary upgrades to protect voters from both the coronavirus and Russian hacking, according to an estimate by the Brennan Center for Justice at New York University, but Congress has supplied just $400 million so far. 

The letter from DHS and the FBI includes unusually blunt language about the danger of transmitting completed ballots online. 

The final version of the letter, however, is less harsh than a draft version obtained by Kim Zetter for the Guardian. That early draft specifically warned that DHS’s cybersecurity division “discourages electronic ballot return technologies.”

Here are details from the Wall Street Journal’s Dustin Volz, who was first to report on the final version of the letter.

Rep. Jim Langevin (D-R.I.), co-founder of the Congressional Cybersecurity Caucus, applauded the letter, saying it’s important that states maintain ballot integrity at the same time they ensure people aren’t blocked from voting because of the pandemic. 

The letter is less critical of allowing people to fill out their ballots on a home computer before printing them out for mailing, though it warns such a system presents moderate risks and could affect the integrity of a single ballot. 

A group of computer scientists who wrote to DHS Thursday expressed far more concern about those systems. 

They warned about hacks that could destroy the secrecy of the ballot for any voters who used them and urged such ballots be reserved just for people with disabilities that make it impossible to mark ballots by hand. They also want the systems to go offline while the voters are marking their ballots.

The situation is further complicated by President Trump’s railing against voting by mail. 

Voting by mail is the easiest and likeliest solution for large portions of the population if the coronavirus is still making in-person voting dangerous in November. But Trump has attacked the method, claiming without evidence that it leads to widespread voter fraud. 

That’s despite the fact Trump voted by mail himself in Florida this year.

The presidential disdain has been echoed by a handful of lawmakers including House Minority Leader Kevin McCarthy (R-Calif.). And it could make it harder for some Republican election officials to rely as heavily on mail-in voting as they might in November. 

Trump attacked California officials this weekend regarding a special election to replace Rep. Katie Hill (D). Officials in the district have urged people to vote by mail because of the pandemic but are also maintaining several in-person polling sites. 

It was the late decision to add one more in-person site that set Trump off. He claimed without evidence the new location amounted to a “scam” to increase Democratic votes and urged that votes cast there shouldn’t count. 

Lancaster, where the new polling place is located, “has been trending more Democratic. However, it is not the most Democratic area in California, as Trump suggests,” Colby Itkowitz explains.

The decision to add an in-person polling location there was supported by the city’s Republican mayor, she notes. 

The polling site in Lancaster will be one of 13 in the district, Colby reports, compared with about 1,000 during a normal election.

Trump's tweets raised the ire of several congressional Democrats. Here's Rep. Bill Pascrell Jr. (D-N.J.).

Rep. Dean Phillips (D-Minn.):

The keys

The Trump administration plans to accuse China of trying to hack coronavirus vaccine data. 

The accusation from the FBI and DHS is meant to warn China of possible digital retaliation by U.S. government hackers if it doesn’t cease trying to steal data about efforts to treat the virus, The New York Times’s David E. Sanger and Nicole Perlroth report

The warning focuses on data theft by government-backed hackers and “nontraditional actors,” such as researchers and students the Trump administration says are being directed to steal data from inside U.S. academic and private laboratories.

The Times describes the Chinese hacking campaign as part of a global effort by government-backed hacking teams to try to gain advantage amid the pandemic, including by nations that are typically U.S. allies such as South Korea. 

Iranian hackers may be responsible for an attack that tried to disrupt Israeli water supplies.

The attempted hack sought to cripple water and wastewater systems in two rural districts of Israel as they fight the pandemic, Joby Warrick and Ellen Nakashima report. It's raising alarms among foreign officials who fear it could signal an escalation in digital conflict between the adversaries.

Cyberattacks that intentionally damage critical infrastructure shouldn’t be condoned,” a senior Trump administration official, who declined to discuss the specific incident, told my colleagues. 

The alleged strike occurred on April 24 and 25, was quickly detected and thwarted before it could cause damage. Iran denied any involvement in the attempted hack.

Acting director of national intelligence Richard Grenell created a new top cybersecurity post – irking lawmakers.

The new post will combine four offices that all work on cybersecurity and “provide a single ODNI focal point for the cyber mission,” Grenell said in a statement. It was among several organizational changes he announced Friday.

The move comes as the Senate is considering the nomination of Rep. John Ratcliffe (R-Tex.) to be the next permanent DNI. It also follows a spat between Grenell, who is seen as a Trump loyalist, and House Intelligence Committee Chairman Adam Schiff (D-Calif.) over the firing of the intelligence community inspector general. Schiff had warned Grenell not to make other personnel changes during his short tenure. 

Here are details from Voice of America’s Jeff Seldin:

Senate Intelligence Committee Chairman Richard Burr (R-N.C.) and Vice Chairman Mark Warner (D-Va.) also told Grenell they expected to be consulted about such changes. CBS News’s Olivia Gazis:

Coronavirus report

Iran linked-hackers are also targeting U.S. drugmaker Gilead Sciences, which is working on coronavirus treatments. 

Researchers discovered a fake email login page that appeared to be directed at stealing Gilead employees’ user names and passwords, Reuters’s Jack Stubbs and Christopher Bing report

More news on the coronavirus and cybersecurity:

Contact-tracing apps aim to help health authorities trace paths of coronavirus infection, and in many cases, to notify users that they’ve been near a person infected by Covid-19. Yet while trying to solve one big problem, they create a lot more small ones.
Wall Street Journal

Government Scan

A U.S. Marshals Service data breach exposed the personal information of current and former prisoners. 

The breach may have included prisoners’ home addresses, dates of birth and Social Security numbers – all of which can be used for identity theft and other fraud, TechCrunch's Zack Whittaker reports

It’s not clear how many people were affected by the breach, which the Marshals Service recently notified current and former prisoners about. 

More government cybersecurity news:

The administration and American companies including Intel are looking to jump-start development of new chip factories in the U.S. as concern grows about reliance on Asia.
Wall Street Journal

Hill happenings

A bipartisan group of lawmakers wants to boost state IT money in the next coronavirus stimulus bill.

The effort comes after a wave of cyberattacks in recent years that has locked up city computers in Baltimore, Atlanta and elsewhere. The group is urging colleagues to join them in lobbying House leadership to prioritize the money, the Hill’s Maggie Miller reports

The group Includes Reps. Michael McCaul (R-Tex.), Jim Langevin (D-R.I.), Mike Gallagher (R-Wis.), and Cedric Richmond (D-La.), all of whom hold congressional positions related to cybersecurity. 

More news from the Hill:

The transcripts, 57 in total, include testimony from a spectrum of witnesses, including top officials from the Clinton and Trump campaigns, as well as Obama administration officials.
CBS News

Chat room

Organizers of the DEF CON summer hacking conference in Las Vegas make an annual gag out of declaring it’s been canceled. But the conference is canceled for real this year because of the pandemic. The organizers, who are planning an online conference, still managed to have some fun with the setback. 

Here’s DEF CON Content Director Nikita Kronenberg:

Here are more details:

Daybook

  • House Homeland Security Committee Vice Chairwoman Lauren Underwood (D-Ill.) and Rep. Elissa Slotkin (D-Mich.) will hold a virtual forum on coronavirus misinformation at 1:30 p.m. today. 
  • The IT Sector Coordinating Council Chair Jamie Brown will talk with CISA’s National Risk Management Center Director Bob Kolasky in a webinar titled "IT Industry Briefing on CISA COVID-19 Response Efforts" hosted by CompTIA and ITI  today at 3 p.m.
  • The Senate Homeland Security and Government Affairs Committee will host a virtual roundtable to discuss U.S. cybersecurity and the Cyberspace Solarium Commission Report on Wednesday at 9:30 a.m.
  • The Senate Commerce Committee will host a hearing on the state of broadband amid the covid-19 pandemic on Wednesday at 10 a.m.
  • The Carnegie Endowment for International Peace will hold an online event on “next steps for encryption policy” at 11 a.m. Wednesday. 
  • The Information Technology and Innovation Foundation will host a webinar “Mind the Gap: A Design for a New Energy Technology Commercialization Foundation” on Wednesday at noon.
  • The Open Technology Institute will host an event on the role of technology in pandemic response efforts on May 14 at 11:30 a.m.

Secure log off

In memoriam: