The State of Election Security with RAD Security’s Jimmy Mesta
RAD Security CTO Jimmy Mesta dives into the current state of election security as millions of Americans head to the polls.
Transcript
This is Textron tv. Hey guys, thanks with, we're here with Jimmy Mesta, who's the CTO for RAD Security, and we're talking about the state of election security. There are big doings going on here in the United States this weekend.
A lot of folks are wondering, well, just how secure are these election results? Because it seems like in every election cycle there's more scrutiny at the very least. I mean, Jimmy, what do you see going on?
Yeah, yeah. Good to be here, Mike. Um, definitely a lot of scrutiny.
Uh, you know, just disclaimer, I'm not, um, you know, election security, uh, expertise expert by, uh, by all means. There are, there are folks dealing with the physical aspects of these things. Um, but we, we do have a lot to talk about there.
I mean, I think elections are as important as ever, as simple as to admit while on this call, um, while on this recording, I'm getting, you know, uh, phone calls right from, from folks who are trying to make sure I'm signed up to vote and, and pushing their candidate. So there's a lot going on. Information's everywhere.
Um, it's a very crazy time to talk about election security. I feel like the folks who are in charge of securing these systems are, shall we say, maybe overwhelmed and maybe even outclassed, and certainly outgunned when you consider all the folks who are trying to, um, compromised the results in one way or another. Do we need to do more here?
And what is, I think that the answer in most things in security these days is we probably do need to do more. Um, but that's, you know, diving into what needs to be done. Um, you have to look at the, the motivations, right?
The threat actors, like who, who's out there trying to a manipulate results, uh, damage, uh, you know, sort of the outcome or, you know, do something even more sinister, who knows, uh, the, or is this just like, you know, there's rioting on the streets and people burning down, you know, you know, the polling, uh, pickup locations. So I think for me personally, um, the, like, as much as, you know, I'm, I'm deep into cloud security and, and, you know, runtime security, uh, a lot of this starts with phishing and social engineering and, um, you know, getting somebody to do something that they shouldn't. So there's, there's humans behind the security of the election at the end of the day.
You know, there's machines also, but those folks, I'm sure need quite a few things that the average worker doesn't. Right? It intense training on how to recognize phishing sort of attempts.
Um, anything from, uh, you know, physical security, locking the doors and, and you know, making sure your camera system, the supply chain of everything coming in the building isn't tampered with, um, these voting machines while, you know, while robust as we understand them, you know, we don't know all the details. Uh, you know, we want to make sure that nothing's getting in, nothing's getting out. So I think it's, uh, it's a hyper consolidated mix of like physical infrastructure, people and technology together with the entire world watching.
So it's like obviously a recipe for, um, at least something interesting to happen Is you were sensed that the bad guys are capable of getting into those systems and actually changing the votes, or are they more after just the credentials of the people who manage those systems and they're just trying to er wreck havoc as a result by, I don't know, shutting down a polling place at the last minute so that people don't vote? My, again, I don't have any in, in insider knowledge on this, but my take is if we were to take a historical look at attacks in other arenas, right, not necessarily election security, the, there is a, a bias towards, um, towards the havoc end of the spectrum, sort of like, um, whether that is for bragging rights, whether that's for actually, you know, the havoc causing sort of downtime, Jan denial service, et cetera. Um, really the like availability and integrity of the, the CIA triad.
And I think that's the case here where if, you know, you know, maybe votes are people are trying to manipulate votes, I'm sure that there are attempts at that, but if you can stop the flow of, of people being able to vote, um, if you can manipulate the, you know, the workers that are, you know, dealing with these machines that, you know, have clearances, et cetera, um, you start to like erode the trust of the public and then push back the election result dates. Like these things are high impact on a global scale. So I think that's the probably more of the target.
If I were to, if I were to guess, What is your sense of what are the actual cybersecurity capabilities of the people who are managing the elections? 'cause my sense is, um, they don't have a lot of money to play with, and they're basically, you know, have enough money to keep the election going. But I know when I go into my local polling place, I don't get the sense that there's, uh, a lot of it resources to be brought to bear.
That's a good point. These are mostly local workers, right? And like, some of them, even as far as volunteering to do certain parts of the job, I'm sure.
Uh, yeah. I live in a small town, and you're right, when I go to the polling center, it's, um, it's not exactly like fortified. Uh, you know, it's kind of, you know, it's got the, the hometown feel.
Uh, so we, we ended up putting a lot of trust in, in the folks collecting the ballots, the machines that kind of, you know, run the, um, you know, the, the vote counting, uh, who's handling them. And then we can only hope that we have some level of, of video surveillance is probably about all we have at the local polling stations, right? Like, if we're lucky, um, and even then that's not, we all know that's not great.
There's a lot of blind spots there. So I think, um, we are, we are somewhat, uh, you know, under prepared for, for this, you know, act, an actual attack on this distributed system that we call like a polling center. Um, you know, and that's been questioned over the years and maybe rightfully so, and, and maybe we need, uh, to revisit the old conversation about, you know, electronic voting, which has its own can of worms that we're not gonna probably get into in detail here.
Well, if it's electronic, it's connected to something and if it's connected to something, it's vulnerable, right? So that's always the, the general thought process. In theory, um, cybersecurity professionals could volunteer their expertise to help out their local polling stations as it were, since they are a man by volunteers.
But I asked somebody about that and I guess kind of shook their head and said, well, I frankly wouldn't have the ability to vet all those people. And for all I know, they're there to do as much harm as good because sometimes they know the bad guys insert themselves into a process and, uh, make it appear that they're here to help when they're trying to do as much malicious damage as they can with the keys to the kingdom as they were. Yeah.
I don't know if sec cybersecurity professionals are even, I don't know if a lot of them are even qualified or suited to be contributing in a meaningful way to this sort of problem. Right. Um, I think cybersecurity is so varied in what you can work on.
It's not, you know, you know, there, there's not a lot of people who are, are experts in this exact arena, and it might cause more harm than good to keep adding more people opinions to the mix. Um, and, and that's interesting. I actually saw today, uh, or article came out little earlier this week or late last week.
The Department of Defense is, is out recruiting, um, you know, tech, tech and security individ like executives, individuals for like, almost like a reserve, you know, and almost like a military reserve function, um, from the private sector. And I think that's a really interesting model. Like if, if there are people who are prepared year round for election security, have the training, have the know, know how, know the systems work can help locally, but also at the like distributed system scale, I think that could work.
But I don't think the weekend, every four years, the weekend warrior who wants to come help, I just don't know how helpful that would be. It might be harmful Sometimes when I talk to folks about this, they say, well, the best thing we can do is train these election workers to recognize phishing campaigns and all those other things. But frankly, in the age of ai, it's getting harder to detect those things.
And it seems like if I am just some mere mortal, um, I'm probably gonna bite on some deep fake link and not think twice about it till it's too late. So are we asking too much of people and do we need a better set of defenses? Yeah.
This has been going on for years, trying to, like where do you, where do you kind of, uh, position the responsibility of, you know, systems that are inherently, you know, uh, yep. Anyone can call my phone, anyone can send me an email. Anyone can, can do these things.
They're, they're pretty open systems of communication. And when you start assuming that you gave a training and that everyone rocked every part of that training and can put it into action at like an organizational level, um, that doesn't work, right? There's a reason why we still send the phishing emails once a year and hospitals and banks and whatever kind of, you know, industry and the hit rate's still pretty high where people click them, put their information in, and then they have to go take additional training, right?
Like that's, we've been doing that for 25 years. Um, and to think that election and security folks can ramp up on that to know all of the ways that they can be phished and or targeted, um, from a social engineering standpoint, it just isn't, I don't think it's reasonable. I mean, we've all walked into the polling centers.
It's not that they're, you know, ill-equipped folks, but they're, they're, that's not even their day job typically to like deal with nation state phishing attacks. Um, so we shouldn't, we shouldn't expect that. We need better, better systems, um, downstream that can stop bad things from happening, not rely on the human element, which is always flawed.
Most of 'em don't even have a day job. They're retired, right? So, you know, they're, Yeah, exactly Right.
Yeah. So, um, Um, to that end, can the training get any better? Because, uh, to be honest, you know, when I look at a lot of the cybersecurity training, it's roughly equivalent to go a traffic school and just about as exciting.
Um, so can we make it more interesting and immersive in a way that, you know, maybe it'll stick better? Yeah, I mean, that's an area I personally have worked. I, I mean, I've done training off and on for eight years now, um, in a variety of, of areas, mostly technical training for developers and things, but similar concept.
Um, I I, I do think the, like, you know, I'm starting my, my video training with my four quiz questions at the end. Um, it's turned into like HR training, right? Where you're like, I get it.
You know, like, um, I can answer these questions, I'm not really paying attention. Yeah. I'm probably not the, uh, we could do better.
Um, I think it's really hard at scale when people are so busy to put in the time and effort to level skills up that people don't have, just don't have, right? So, um, there's, there's an element of training that I think using, you know, hands-on, um, sort of hands-on exercises mixed with real world scenarios mixed with a constant drip feed of training versus like once a year we're gonna do these like 12 exercises and then you're never gonna talk about this again. I think you need to like shift your mindset versus trying to jam it all into one event.
Um, but that, that's my theory and I think you could possibly deploy that into voting. But again, if you're retired, like I, it, it, it just, it depends what part of the system you're trying to, to defend. If it's, if it's a someone who's behind closed doors, you know, working on these machines and you know, kind of who is a trusted source, they should be getting training year round that is relevant to their job, um, not just like right before they have to do the job.
So it can help, but it's not the full, it's not the full picture. All these elections are run locally. Is there a responsibility on the part of the federal governments, the national governments to help secure these things?
And should they be devoting resources, I don't know, through CSA or somebody else to help all these small little towns and say Montana, who just aren't gonna have their resources to fight the fight? Oh, um, I do think we need more centralized support, right? I think there's, uh, it, we're kidding ourselves to, to think that, like, there's a pre-brief document somebody reads and then they set up these pretty elaborate in-person events.
Um, but, you know, obviously like, yeah, I don't work in government. I don't know that could be taken as that's over overreaching, um, and into some way. But it does feel like there's, there's a place to put some funds into making sure elections not just are safe from adversaries, but run as smoothly and they're accurate, right?
I think we all deserve that as voting citizens in this country, and that government should probably help make sure that that happened smoothly. So if you're a Bening man, one of the odds that you think that we're gonna have to do, uh, one or more elections over again in the next few years, because it will be discovered that something got hacked and that there was some sort of unfair unseen finger put on the scale of the election. And we're just gonna have to have a giant do-over, Do over, um, I, I don't think e even if those things happen and the public is aware they could be happening and we're not, we have no knowledge, right?
Uh, I don't, I don't know what goes on behind closed doors in Washington DC I think a do-over would be, um, I don't think that would happen in the next few years. I think we would just push through when, and like people would wave their hands and we would move along with the election. Uh, it feels like a do-over is an extreme move for some, like, just logistically.
Um, uh, 'cause then you lose, you erode the trust of people. They cha maybe they changed their minds. Uh, it would just, I would maybe want to go to a deserted island for a few months if we were in that state and not turn my phone on.
Um, uh, because that would make for quite a spectacle, um, in the media. So I don't think we'd push to do overstate, but who knows? I don't know.
Weirder things have happened. All right, folks. Well, the one thing for certain is that democracy is under attack regardless of what your favorite color or shirt is for political persuasion.
And we should all have a collective conversation about how to thwart these attacks because, well, if the fundamentals are not trusted, then it makes every other conversation that much more difficult. Hey, Jimmy, thanks for being on the show. All right, thank you.
Go vote either way. If it gets hacked or not, we should all be out there. There you go.
And back to you guys in the studio.