A vast majority of election-related websites operated by local governments in battleground states lack a key feature that would help distinguish them from those run by commercial entities or criminal hackers — a site that ends in .gov as opposed to .com or other extensions, according to cybersecurity research firm McAfee.
Of 1,117 counties in 13 key states, which account for 201 of the 270 Electoral College votes that determine the winner of presidential contests, 83.3 percent didn’t have the .gov validation, McAfee found.
When government websites operate using .com or other domain extensions, it becomes easy for foreign adversaries to put up fake sites that imitate government websites and to mount disinformation campaigns aimed at misleading voters, said Steve Grobman, McAfee’s chief technology officer.
“If we look at the battleground states, the local election websites are still not operating with the level of security we’d expect,” Grobman told CQ Roll Call. “We see the vast majority are not using .gov, meaning that normal citizens may not be able to identify if an election website is real or not. And only half of them use encryption, so information they’re transmitting is not secure.”
Attackers trying to mislead voters could set up fake websites ending in .com or .us or other domain extensions, similar to those used by local agencies, making them hard to distinguish from authentic ones, Grobman said.
If all government websites, from federal agencies to local governments, operated only with a .gov domain, then a nationwide campaign could educate citizens and voters to trust only .gov websites, Grobman said.
Minnesota was the worst offender, with 95.4 percent of its sites lacking the .gov extension, while Texas, Michigan, Nevada, Pennsylvania and Ohio were among the states where more than 80 percent of sites had no validation through the .gov extension, McAfee found.
In Iowa and New Hampshire — two key states that hold the first caucus and primary, respectively, to pick a party’s presidential candidate — significant majorities of sites lacked the .gov extension, McAfee found. In Iowa, 88.9 percent operate without .gov, while 90 percent of New Hampshire sites lack one.
More than two-thirds of Arizona’s websites had the .gov extension, making it the state with the most validation. Still, because one-third of the state’s sites lacked the .gov extension, “hundreds of thousands of voters could still be subjected to disinformation schemes,” McAfee said.
More security, more encryption
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, or CISA, and some lawmakers have been urging state and local agencies to boost security measures.
“We encourage organizations to move to the .gov domain,” Christopher Krebs, director of CISA, told reporters last week after completing an election security exercise with state and local governments. “We do think that between now and the election, there may be other security measures we can put in place like multifactor authentication on key administrator accounts and ensuring that websites have ‘https’ [prefixes]. Ultimately, we’d like everyone in government to be on the .gov domain.”
To obtain a .gov extension, local governments have to get permission from the U.S. government.
A bipartisan bill under consideration in the Senate Homeland Security and Governmental Affairs Committee would require CISA to come up with a plan to migrate all government agencies to the .gov domain. The legislation is sponsored by Sen. Gary Peters, D-Mich., and backed by Sens. Amy Klobuchar, D-Minn., Maggie Hassan, D-N.H., Ron Johnson, R-Wis., Roy Blunt, R-Mo., and James Lankford, R-Okla.
The .gov extension is a top-level domain name administered by the General Services Administration and available only for U.S. federal, state and local government agencies. Domain names for foreign government agencies typically use .gov, followed by an abbreviation of the country name.
Some U.S. federal agencies follow a different naming convention for their websites. The Pentagon and military services, for example, use the .mil extension.
Nearly half of the local government election websites also lacked another key security feature that’s denoted by “https” in front of a website’s address, McAfee found. Instead, 46.6 percent of the local government sites were operating with only an “http,” which means that data flows in and out of those websites in an unencrypted form, potentially leaving them vulnerable to manipulation.
In Iowa and New Hampshire, about 30 percent of election websites operate without the https feature, McAfee found.
Top technology companies, including Google, tell developers that all websites should be protected with the https technology. Without the secure layer, intruders can tamper with communications between users and websites and trick users into giving up sensitive information, Google warned developers last year.
All information that flows between users and websites, including images, cookies, scripts and HTML, can be exploited without https, Google said.