Valimail: 2020 Election Infrastructure Still Vulnerable to Email Hackers
Summary
Valimail found most domains were unprotected from email spoofing, meaning they could easily be impersonated by attackers pretending to play some role in the election infrastructure. “Malicious agents could use the essential and pervasive nature of email to spread uncertainty, confusion, misinformation or doubt, which could, in turn, interfere with a free and fair election.” The report makes a strong case for a widely used industry standard called Domain-based Message Authentication, Reporting, and Conformance, also known as DMARC. “Our message to all domains involved in elections is to check your email authentication and determine your level of protection and vulnerability,” said Seth Blank, vice president of standards and new technologies at Valimail. “Use 2020 as the catalyst to prepare for future elections — prioritize DMARC enforcement for email and multifactor authentication for all systems.” The research in this report stems from an analysis Valimail performed on hundreds of domain name system (DNS) entries related to state and local governments, campaigns, PACs and election system manufacturers. The company’s full line of cloud-native solutions authenticate sender identity to stop phishing, protect brands, and ensure compliance; they are used by organizations ranging from neighborhood shops to some of the world’s largest organizations, including Uber, Splunk, Yelp, Fannie Mae, Mercedes Benz USA, and the U.S. Federal Aviation Administration.