Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

German Hackers Say Vote Software a Security ‘Write-off’

German IT security experts said Thursday that they had found “serious flaws” in the ballot software being used for the September 24 elections in which Chancellor Angela Merkel is seeking a fourth term.

German IT security experts said Thursday that they had found “serious flaws” in the ballot software being used for the September 24 elections in which Chancellor Angela Merkel is seeking a fourth term.

The Chaos Computer Club, Europe’s biggest hacker collective, said the system to count and transmit vote results lacked proper encryption and other security tools, labelling it a “write-off”.

The privately developed “PC-Wahl” (PC Election) software — used for years in several of Germany’s 16 states — “should never have been used,” said a CCC spokesman, Linus Neumann.

“The number of possible attack targets and the severity of vulnerabilities exceeded our worst fears,” he said in comments first published by news weekly Die Zeit.

The report highlights fears about cyberattacks before and during the election in Germany, where lawmakers’ PCs were crippled in a 2015 attack which security services pinned on Russia.

The CCC warned that German parliamentary election results could potentially be manipulated remotely because the software failed to meet even “the basic principles of IT security”.

CCC hackers have in the past highlighted IT security flaws in high-profile cases, and their members often give expert testimony in German parliamentary hearings and court cases.

But the developer of the software, Volker Berninger, rejected the criticism, telling Die Zeit that “in the worst-case scenario, someone would create confusion”.

Advertisement. Scroll to continue reading.

“Some wrongful results would be published on the internet, but the correct ones would still exist on paper. This would cause anger and confusion but have no relevance.”

But the CCC said any online attack would have “the potential to permanently undermine confidence in the democratic process”.

“This is simply not the right millennium in which to turn a blind eye to IT security in elections,” Neumann said.

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.