Security expert uncovers widespread vulnerabilities in US voting and government systems

Skye Jacobs

Posts: 582   +13
Staff
Cutting corners: The presidential election is approaching and if there is anything that unites the US populace it is the desire that voting systems are safe and secure. Unfortunately, they are anything but, according to a security researcher who has uncovered several vulnerabilities in these and other systems used by courts and government agencies. Fixing the problem will require nothing less than a complete overhaul of how these systems handle security.

Jason Parker, an erstwhile software developer turned security researcher, has for the past year been hunting down and reporting critical vulnerabilities in the commercial platforms used by courts, government agencies and police departments across the US.

His efforts have turned up alarming results, finding that 19 of these systems are riddled with vulnerabilities allowing hackers to access confidential information, manipulate legal documents, and compromise personal data.

They also open the door for attackers to falsify registration databases, a scenario that clearly bothers Parker. "These vulnerabilities in a voter registration portal, much like those found in court systems, underscores how inadequate security measures can put citizens' rights and personal information at risk," he said.

The vulnerabilities share two key problems in common. First, the systems' permission controls are not strong enough. Second, user inputs are not properly checked. Many websites use easy-to-guess user ID numbers, and some let users change important data fields. This can grant users access beyond what they are authorized to have. As a result, attackers can gain high-level access to the system without proper authorization.

For example, in Georgia, a flaw in the voter registration cancellation portal could allow attackers to submit cancellation requests using only basic personal information like name and birthdate.

In the Granicus GovQA platform used by government agencies, attackers could easily reset passwords and gain access to usernames and emails by manipulating web addresses. This level of control could allow malicious actors to hijack accounts or change ownership of sensitive public records.

Similarly, a vulnerability in Thomson Reuters' C-Track eFiling system could allow attackers to elevate their user status to court administrator by manipulating fields during registration. This could potentially grant access to view or tamper with sensitive court data.

Court record platforms in several Florida counties, including Sarasota and Hillsborough, had weak access controls that allowed unauthorized access to restricted documents. Among the compromised records were sealed documents, mental health evaluations, and witness lists – private information that should have been securely protected, Parker said.

In Arizona's Maricopa County, the Superior Court eFiling system allowed exploitation of API endpoints to retrieve restricted legal documents. The Catalis EZ-Filing platforms used in multiple states exposed personal information and even sealed court documents in some cases.

In short, "the vulnerabilities discovered in these platforms reveal systemic security failures that span regions and vendors," Parker said. "These platforms are supposed to ensure transparency and fairness, but are failing at the most fundamental level of cybersecurity."

Parker has no illusions that these issues will be an easy fix. The solution is nothing short of a complete overhaul of how security is handled in court and public record systems, he said. Robust permission controls must be immediately implemented, and stricter validation of user inputs enforced. Also, regular security audits and penetration testing should be standard practice, not an afterthought, he advised.

Other remedies he presents are familiar terrain to any security expert but many local governments seem unaware of these basic solutions.

The widespread adoption of multi-factor authentication would prevent attackers from easily taking control of accounts. Ongoing training for IT personnel on the latest security practices is crucial, along with educating users about phishing risks and other common attack vectors.

Unless organizations act quickly, "the consequences could be devastating – not just for the institutions themselves but for the individuals whose privacy they are sworn to protect," he concluded.

Unfortunately, the responses when Parker contacted the various governments about their vulnerabilities were mixed. In many cases the systems were quickly remedied while others dragged their feet. And in one instance in Florida's Lee County, Parker was threatened with legal action.

Permalink to story:

 
And I'm sure this will mena our elections were rigged/this was the most secure election in our history, depending on who you are asking and who won.

The whole system is absolute garbage and needed fixed decades ago.
All hindsight is better than foresight; however, I'd place the "blame" on the endless hunt for profit above all else. Like in other technology areas, for instance, IoT, security is a distant afterthought with profit being the primary motive for sales. At least there will be paper to back up the outcome, in cases where states do not have their heads where the sun doesn't shine.

Note that there is no list of what it would take to do any of what this "security" researcher lists. Who knows, this "security" researcher could just be out to make a name for himself, not unlike the software vendors out for only profit.
 
This is a really eye-opening post! It’s concerning how many vulnerabilities exist in critical systems that should be safeguarding personal information and ensuring the integrity of court and government processes.:eek:
"Safeguarding personal information" is like pushing snow uphill as long as entities like Google and Facebook continue to gather our data and sell it on the open market.
 
But in the US calling for Voter ID is rrrrrrracist (according to the “pro-democracy party” at least). Even though every other voting country requires a valid ID to vote!

Yeah I've never understood the objection there, it seems so obvious! I would want this if I was having a classroom vote on which pizza to order.

It's because a "valid ID" for voting in the US represents a very specific type of ID of which 11% of americans don't have, the vast majority being minorities or poor people. for example 25% of african americans (actual US citizens) don't have such an ID because of reason like: expires too often, too expensive to renew or make one, too far from where they live to travel, etc.

Before banning citizens from voting you should figure out how to fix this issue. Most countries have mandatory, but free IDs that can easily be obtained and don't expire after just 3-6 years. But everybody in the US yells "communism" when it comes free stuff from the government. (for me it costs 1.5$ to renew it and it last 10 years)

I still don't understand how some states in the US have IDs that expire after 3-4 years, and worse yet, why does an european like me need to explain this?
 
Last edited:
It's because a "valid ID" for voting in the US represents a very specific type of ID of which 11% of americans don't have, the vast majority being minorities or poor people. for example 25% of african americans (actual US citizens) don't have such an ID.
Then they should get an ID. Takes like 15 minutes. This is why you pay attention in school. It's also not "very specific", it's a drivers license, or a state issued ID. REALLY not that hard to understand. Most other countries can manage this, and if you cant understand what a state ID is or do a 10 second google search, you shouldnt be voting.
Before banning citizens from voting you should figure out how to fix this issue. Most countries have mandatory, but free IDs that can easily be obtained and don't expire after just 3-6 years. But everybody in the US yells "communism" when it comes free stuff from the government.
We literally already figured this out. You can get a state ID for $4. If you cant come up with $4 to replace your ID after 6 years, the problem is not "racism", the problem is your entire life is completely screwed up and you need to get it fixed.

And, here in my little red state, there is a program to get you FREE IDs! So, if you are too dysfunctional to find $4 every 6 years to renew, and too stupid to figure out how to sign up for a free one, maybe you shouldn't be voting? Just a thought.
I still don't understand how some states in the US have IDs that expire after 3-4 years, and worse yet, why does an european like me need to explain this?
I always love it when a smug European comes in and thinks they know everything.

As of 2013, EU driver licenses expire after 10-15 years, depending on type and driver age.

EU identity cards are good for a minimum of 5 years and a maximum of 10. German cards are valid for 6 years for those under 24, and ten years for those over.

This took 5 seconds on google to find. This shows why we should need ID to vote, some people are just too ignorant to have a say in society. As for why they expire? It's simple, you need to re-validate things like height, weight, name (marriages are a thing you know), address, if the person is still alive, ece. If you are too irresponsible to maintain a simple ID, you shouldnt have a say in how society functions.

LOL, people above the poverty line have an opinion on voter ID? Shocking!
In my state it's $4 every 8 years. If you cant come up with that, you have royally failed as an adult. Even McD wagies living in NYC shoeboxes can find $0.50 per year.
 
Pragmatically, I just can't understand how a person - even the most disadvantaged - has no ID. Even the most addled homeless that I encounter these days tend to have cellphones, so I tend to believe that if they wanted to vote, they would find a way.

If we look at the argument from two perspectives, I see:

1- There is a percentage of people who allegedly can't afford/figure out ID requirements, therefore we shouldn't have those requirements

2- Do the percentage of the non-ID voters actually vote? How do we know and track that information and avoid serious fraud risks?

Both scenarios present some risk.
 
All hindsight is better than foresight; however, I'd place the "blame" on the endless hunt for profit above all else. Like in other technology areas, for instance, IoT, security is a distant afterthought with profit being the primary motive for sales. At least there will be paper to back up the outcome, in cases where states do not have their heads where the sun doesn't shine.

Note that there is no list of what it would take to do any of what this "security" researcher lists. Who knows, this "security" researcher could just be out to make a name for himself, not unlike the software vendors out for only profit.
Paper ballots don't help you if someone cancels your voter registration like they tried to do in Arizona and Georgia. God help you if you live in a swing state and are a Democrat. They will do everything they can to take away your right to vote if they think you aren't voting for their guy.
 
Won't be surprised if this is done on purpose. Voting in the U.S. has become a circus and is showing signs of what many other Dictatorial Countries do but the U.S. uses the word "Democracy " to hide behind it.
 
Last edited:
Let's look back on here for the last 8+ years. It appears conspiracy theorist were mostly right.

This is now about Good VS Evil. Censorship vs Truth, Humans vs AI vs Media. It's been an eye-opener these 8 years. It's amazing how some people never give up and fight for what's right. November is going to get crazy.

By the way, here is Italy proving he won. I have 80+ video's of things you will never hear on MSM.
https://www.bitchute.com/video/WvxYKlyoHaoJ
 
Let's look back on here for the last 8+ years. It appears conspiracy theorist were mostly right.

This is now about Good VS Evil. Censorship vs Truth, Humans vs AI vs Media. It's been an eye-opener these 8 years. It's amazing how some people never give up and fight for what's right. November is going to get crazy.

By the way, here is Italy proving he won. I have 80+ video's of things you will never hear on MSM.
https://www.bitchute.com/video/WvxYKlyoHaoJ

Bwahahahahhahahaha. Oh boy. Keep watching and posting videos, just to get that warm echo chamber vibe that says right-whinger conspiracy nutjobs are correct about everything vs. people living in the real world LMAO
 
Mr. Jacobs,
Great article. I followed it to (https://jeltz.org/news.html) . Personally I think Jason Parker should be wearing a red cape. Just like most unknown hero's, they need financial support because they volunteer their super-skills. This guy helps to keep bad actors from screwing with all of our personal-data-integrity. That's important to me & should be to everyone else. No politics, just doing what he knows to be right.
Thanks Mr. Jacobs for bringing attention to the selfless efforts of a unsung hero.
 
Mr. Jacobs,
Great article. I followed it to (https://jeltz.org/news.html) . Personally I think Jason Parker should be wearing a red cape. Just like most unknown hero's, they need financial support because they volunteer their super-skills. This guy helps to keep bad actors from screwing with all of our personal-data-integrity. That's important to me & should be to everyone else. No politics, just doing what he knows to be right.
Thanks Mr. Jacobs for bringing attention to the selfless efforts of a unsung hero.

Thank you, that is very kind.

-Jason
 
Note that there is no list of what it would take to do any of what this "security" researcher lists. Who knows, this "security" researcher could just be out to make a name for himself, not unlike the software vendors out for only profit.
Nearly of my disclosures provide specific details of exactly what's needed to take advantage of them.

To everybody arguing about voter ID: your privilege is showing.
 
Then they should get an ID. Takes like 15 minutes. This is why you pay attention in school. It's also not "very specific", it's a drivers license, or a state issued ID. REALLY not that hard to understand. Most other countries can manage this, and if you cant understand what a state ID is or do a 10 second google search, you shouldnt be voting.

We literally already figured this out. You can get a state ID for $4. If you cant come up with $4 to replace your ID after 6 years, the problem is not "racism", the problem is your entire life is completely screwed up and you need to get it fixed.

And, here in my little red state, there is a program to get you FREE IDs! So, if you are too dysfunctional to find $4 every 6 years to renew, and too stupid to figure out how to sign up for a free one, maybe you shouldn't be voting? Just a thought.

I always love it when a smug European comes in and thinks they know everything.

As of 2013, EU driver licenses expire after 10-15 years, depending on type and driver age.

EU identity cards are good for a minimum of 5 years and a maximum of 10. German cards are valid for 6 years for those under 24, and ten years for those over.

This took 5 seconds on google to find. This shows why we should need ID to vote, some people are just too ignorant to have a say in society. As for why they expire? It's simple, you need to re-validate things like height, weight, name (marriages are a thing you know), address, if the person is still alive, ece. If you are too irresponsible to maintain a simple ID, you shouldnt have a say in how society functions.


In my state it's $4 every 8 years. If you cant come up with that, you have royally failed as an adult. Even McD wagies living in NYC shoeboxes can find $0.50 per year.
"We literally already figured this out. " - you clearly haven't. and stop talking about just one state or one place. the US is a big place.
 
Pragmatically, I just can't understand how a person - even the most disadvantaged - has no ID. Even the most addled homeless that I encounter these days tend to have cellphones, so I tend to believe that if they wanted to vote, they would find a way.

If we look at the argument from two perspectives, I see:

1- There is a percentage of people who allegedly can't afford/figure out ID requirements, therefore we shouldn't have those requirements

2- Do the percentage of the non-ID voters actually vote? How do we know and track that information and avoid serious fraud risks?

Both scenarios present some risk.
Wow, are you serious?

My answer for #1.) (allegedly can't afford/figure out ID requirements) if a US citizen lacks the ability to comprehend the simple & basic requirements to apply for a local state identification card. Then they are most likely to be mentally retarded, or so illiterate that should not vote. Their vote should be considered as a double vote by the same person. Cause these people have no independent thoughts. They'll mark the ballot where they're told to, by their coach or guardians.
I'll guarantee Joe Traitors administration has voter registration cards mailed out to every mentally disabled group home in the US. Just to take advantage of their disabilities. If they're caught, the accusers get sued in high-court to block it.

My answer to #2.) (Do the percentage of the non-ID voters actually vote?)
Let's hope not! I was always told to show my ID before I was handed my voting ballot card. Up until this administrations hi jinks & unAmerican policies.
Democrats are terrified of loosing. Their scared, desperate to hold on to the authority & power of the citizens freedoms & choices.

Joe Traitor & Giggles have let in over 20 million illegal aliens. All on the gamble of getting non-voter ID laws passed nationwide.

On the night Joe Traitor won this election, backstage with a hot-mic still on. He told Harris & Sanders that he was the bridge, & the rest is up to you two. Then Joe said to Bernie Sanders " Bern, the US can easily absorb 20 Million migrants" .

This week here in California, my crooked Governor Gavin Newsum, signed an executive order to make it illegal for anyone to ask someone to show their ID before getting a voter ballot card. (How does this benefit citizens or ensure fair voting practices?)

If you're a US citizen, then you or your forefathers were also a migrant from elsewhere. But, we were all vetted at some point. Most of us love our country & remain patriotic to our flag & sovereignty. But, now we have around 5000 convicted murderers & 11,000 sexual predators roaming free amongst us law abiding citizens & our children.
If it were 20 million Ukrainian migrants, I would be okay with it cause the Ukrainian's are civilized & educated. They would acclimate to the US & become productive, patriotic citizens.

To all the tree-huggers out there, I apologize if this offends you. But, we all have family that we love & naturally want to protect, right?
But, a little bit of brutal honesty may enlighten you.
 
Wow, are you serious?

My answer for #1.) (allegedly can't afford/figure out ID requirements) if a US citizen lacks the ability to comprehend the simple & basic requirements to apply for a local state identification card. Then they are most likely to be mentally retarded, or so illiterate that should not vote. Their vote should be considered as a double vote by the same person. Cause these people have no independent thoughts. They'll mark the ballot where they're told to, by their coach or guardians.
I'll guarantee Joe Traitors administration has voter registration cards mailed out to every mentally disabled group home in the US. Just to take advantage of their disabilities. If they're caught, the accusers get sued in high-court to block it.

My answer to #2.) (Do the percentage of the non-ID voters actually vote?)
Let's hope not! I was always told to show my ID before I was handed my voting ballot card. Up until this administrations hi jinks & unAmerican policies.
Democrats are terrified of loosing. Their scared, desperate to hold on to the authority & power of the citizens freedoms & choices.

Joe Traitor & Giggles have let in over 20 million illegal aliens. All on the gamble of getting non-voter ID laws passed nationwide.

On the night Joe Traitor won this election, backstage with a hot-mic still on. He told Harris & Sanders that he was the bridge, & the rest is up to you two. Then Joe said to Bernie Sanders " Bern, the US can easily absorb 20 Million migrants" .

This week here in California, my crooked Governor Gavin Newsum, signed an executive order to make it illegal for anyone to ask someone to show their ID before getting a voter ballot card. (How does this benefit citizens or ensure fair voting practices?)

If you're a US citizen, then you or your forefathers were also a migrant from elsewhere. But, we were all vetted at some point. Most of us love our country & remain patriotic to our flag & sovereignty. But, now we have around 5000 convicted murderers & 11,000 sexual predators roaming free amongst us law abiding citizens & our children.
If it were 20 million Ukrainian migrants, I would be okay with it cause the Ukrainian's are civilized & educated. They would acclimate to the US & become productive, patriotic citizens.

To all the tree-huggers out there, I apologize if this offends you. But, we all have family that we love & naturally want to protect, right?
But, a little bit of brutal honesty may enlighten you.
I'll also be brutally honest: you don't understand the issue at hand at all and insulting people who don't have an ID that the GOP wants is not a solution to anything.

You either make proper ID standards and remove most barriers to getting an ID by people who can't travel long distances (working two jobs is not easy) and reduce the cost (I paid 4$ for mine which last 10 years), or you stop complaining about it. You have states where you have to renew them as often as 3-4 years, that's ridiculous. As it stands, all the GOP cares about is that the group of voters they want to remove are mostly dem voters (poor families, minorities, etc). Nothing more, nothing less.

FYI many of the things you are complaining about are non-issues or outright lies. And I would expect nothing less from a party who voted against expanding the Child Tax Credit bill, border bill, FEMA funding bill and many other good bills just so that they give dems a "win".

I heard trump supporters were literally attacking FEMA workers... how does somebody associate with such ppl?
 
Then they should get an ID. Takes like 15 minutes. This is why you pay attention in school. It's also not "very specific", it's a drivers license, or a state issued ID. REALLY not that hard to understand. Most other countries can manage this, and if you cant understand what a state ID is or do a 10 second google search, you shouldnt be voting.

We literally already figured this out. You can get a state ID for $4. If you cant come up with $4 to replace your ID after 6 years, the problem is not "racism", the problem is your entire life is completely screwed up and you need to get it fixed.

And, here in my little red state, there is a program to get you FREE IDs! So, if you are too dysfunctional to find $4 every 6 years to renew, and too stupid to figure out how to sign up for a free one, maybe you shouldn't be voting? Just a thought.

I always love it when a smug European comes in and thinks they know everything.

As of 2013, EU driver licenses expire after 10-15 years, depending on type and driver age.

EU identity cards are good for a minimum of 5 years and a maximum of 10. German cards are valid for 6 years for those under 24, and ten years for those over.

This took 5 seconds on google to find. This shows why we should need ID to vote, some people are just too ignorant to have a say in society. As for why they expire? It's simple, you need to re-validate things like height, weight, name (marriages are a thing you know), address, if the person is still alive, ece. If you are too irresponsible to maintain a simple ID, you shouldnt have a say in how society functions.


In my state it's $4 every 8 years. If you cant come up with that, you have royally failed as an adult. Even McD wagies living in NYC shoeboxes can find $0.50 per year.
My home country charges over a hundred euros for a ten year passport. I have let it expire because I don't need to travel internationally now. The country I live in now issued me with a residence card that also lasts ten years. Free of charge. Another reason I.D. documents need to have renewals is the photo. People change as they grow older. Simples.
 
Back