Close Menu
  • Home
  • News
    • Local
    • National
    • State
    • World
  • Obituaries
  • Events
  • Sports
  • Politics
  • Business
  • Entertainment
  • Health
  • Tech
  • Real Estate
  • Jobs
  • Weather
    • Climate
    • Hurricane Videos
  • Classifieds
    • Classifed Ads
We're Social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Trending
  • Fossil Workforce appoints Pamela Edwards to its Board of Administrators
  • The Anti-Tradwife: Boyfriends Who Cook For their Girlfriends
  • DeSean Jackson compares school soccer to NFL separate company
  • All About Intestine Fitness โ€” Remedy for Dim Ladies
  • The best way to Fortify Your Technical Overview Checks
  • Leading edge Techniques It’s Powering the Global
  • Gainesville guy entered space thru window, attempted to strangle lady, government say
  • This Pocket of Italy Is Trending With American Vacationers for Summer time 2025
Facebook X (Twitter) Instagram
Savannah Herald
  • Home
  • News
    • Local
    • National
    • State
    • World
  • Obituaries
  • Events
  • Sports
  • Politics
  • Business
  • Entertainment
  • Health
  • Tech
  • Real Estate
  • Jobs
  • Weather
    • Climate
    • Hurricane Videos
  • Classifieds
    • Classifed Ads
Savannah Herald
Home»Politics»Georgia voter cancellation portal requires second round of security fixes
Politics

Georgia voter cancellation portal requires second round of security fixes

Savannah HeraldBy Savannah HeraldSeptember 24, 20247 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


To build confidence in voting rolls, Georgia digitized a cancellation process.

Instead, they exposed voter data to exploitation.

The website launched this week by Georgiaโ€™s secretary of state intended to help individuals to cancel their voter status and to increase confidence in the stateโ€™s electoral rolls has instead exposed private personal data of voters, according to an investigation by The Current.ย 

Oversights by IT workers during a test phase meant that for at least two days vital data such as driverโ€™s license information or partial Social Security numbers would have been visible to malicious actors.ย  Georgia Secretary of State Brad Raffensperger unveiled the site on Monday.

The Current discovered one security flaw on Wednesday โ€” and immediately alerted the Secretary of Stateโ€™s office. The story was held for publication until the agency worked with the IT vendor, MTX Group, to correct the issues.ย 

Gabriel Sterling, chief operating officer for the Georgia Secretary of Stateโ€™s office, told The Current on Wednesday afternoon that approximately a couple hundred people had visited the site before the software fix.ย 

โ€œWe launched something, we found some issues, no one was impacted in any real way that we can discover, weโ€™ve taken steps to mitigate it and make sure it doesnโ€™t happen,โ€ Sterling said.ย 

The issue is the second security flaw discovered since the site came online. The first, reported by The Associated Press, has also been fixed, according to Sterling.

The partial Social Security numbers and driversโ€™ license numbers exposed inadvertently on Georgiaโ€™s voter cancellation site are part of data necessary to initiate a voter registration cancellation, along with a personโ€™s date of birth and county of residence. This personal information is valued by hackers to perpetuate identity or credit fraud.

The Current, while using the new site, discovered that sensitive personal information displayed in the computer code sent from the cancellation portal to some usersโ€™ browsers. That flaw was related to an even more obvious security problem first reported by the AP: One page inside the portal very briefly displayed personal information in plain text.ย ย 

Sterling said his office has been testing the portal internally for weeks. One of the problems had been fixed during testing, but a last-minute change elsewhere invalidated the fix, he said. The problem identified by The Current was on a list of things that needed to be checked, but it wasnโ€™t checked, he said.ย 

The cancellation portal is part of a larger $5.1 million overhaul of the stateโ€™s voter registration system. Those changes include storing information in cloud-based servers run by the company Salesforce, which uses security standards laid out for agencies like the Federal Bureau of Investigation and the U.S. Department of Defense.ย Not even the MTX Group programmers can see votersโ€™ information, he said.

Georgiaโ€™s new election laws allow unlimited numbers of challenges to voter registration, part of a series of changes that the Republican-led state government has made to voting law amid pressure from the pernicious but wrong opinion that voting fraud is rampant in the Peach State. The brunt of those registration challenges falls on county election officials.

Though this portal was designed for individuals to remove only themselves or deceased relatives, it comes at a time when voter-list vigilantes are appearing at county election boards with thousands of names they want removed from voter rolls. Voting rights advocates are on high alert, and didnโ€™t care for the language that first appeared on the new Secretary of State page: โ€œPlease enter the information for the voter you are wanting to cancel.โ€

Despite the initial flaws in the cancellation portal โ€” which Sterling emphasized were fixed within hours โ€”ย the new digitized system is more secure than depending on paper and the mail, he said.ย 

Sterling said fewer than 20 people visited the site before Mondayโ€™s flaw was fixed; and a couple hundred people had initiated cancellation requests as of Wednesday afternoon.ย 

โ€œAt the end of the day โ€ฆย  all these county [election office] folks, a human being still has to look at this to see if it seems right to them,โ€ Sterling said. Anyone whose registration is canceled should receive a postcard in the mail double-checking the deletion.

Raffenspergerโ€™s office called the site โ€œsecureโ€ when they announced its debut via press release Monday. The office touted it as a simple way for anyone moving out of state to remove themselves from the Georgia voter list, or to do so for a deceased family member.ย ย 

โ€œIt will also help keep Georgiaโ€™s voter registration database up-to-date without having to rely on postcards being sent and returned by an increasingly inefficient postal system,โ€ Raffensperger was quoted as saying in the Monday release.ย 

Georgia Democrats this week have panned Raffenbergerโ€™s voter cancellation initiative, and the security snafus have enhanced the mistrust among many members of the stateโ€™s minority party. As Georgia moves from long-term Republican dominance to a place where more Democrats register to vote, margins as small as 12,000 votes matter in statewide elections. Democrats fear the portal will be abused by conspiracy theorists and bad actors to wrongly disenfranchise voters.ย 

One Democratic state senator said she saw her own personal information in plain text on the site. Her caucus called for the cancellation portal to be taken down altogether.ย 

The state cancellation site still starts by asking for a personโ€™s name, date of birth and county of residence to start the voter cancellation process.ย ย 

Next, the site asks for the voterโ€™s drivers license number or the last four digits of their Social Security number.

For a short period Monday morning, if a user clicked an option saying they donโ€™t have a driverโ€™s license, the site generated a form for the user to print and return by mail or email. Pressing that button to create the form exposed the personal information.ย 

August 1, 2024, 10:57 a.m.: Clarification:ย  One reference in this story has been updated to clarify the day on which one flaw was fixed on the Secretary of Stateโ€™s site.

Related

Methods:

The Current found the security flaw by reading the computer files that the Secretary of Stateโ€™s website sent to browsers. Firefox, Chrome, or Safari read those files and follow the instructions in them in order to display websites.ย  But humans can also read those files, just like humans can read a Word document.ย  And sometimes, humans find things that programmers have failed to encrypt or otherwise hide.

One way computers send information to each other is a format called JSON. Typically, JSON holds words and phrases that are in plain English but that are wrapped in formatting marks that tell a browser what parts to display and how to display them.

Any user can see what kind of JSON or other files their browser is receiving. It’s like opening the hood of a car to look at the engine.

Opening the hood is done a little differently in every browser, but the end goal is to find the “network monitor.โ€ In Firefox, for example, open “Web Developer Tools” and a “network” tab is toward the bottom of the screen.

In the case of the voter cancellation portal, the JSON sent by the state included unencrypted PII.ย  For a while Monday morning, that PII was displayed in plain text in a browser window within the portal, visible to any user.ย  For at least another day, that unencrypted PII was still sent to the browser via JSON, but not displayed in the browser window.

Type of Story: News

Based on facts, either observed and verified firsthand by the reporter, or reported and verified from knowledgeable sources.





Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Savannah Herald
  • Website

Related Posts

Politics May 29, 2025

President Trump Grants Complete Liniency to Unvaxxed Army Place of job Convicted for Now not Following COVID Laws โ€“ Twitchy

Politics May 28, 2025

People the city halls close ailing through disagreement shy participants of Georgia congressional delegation

Politics May 28, 2025

She Endured: Lara Trump Finds How the Jake Tapper ‘Apology’ Went Ill

Politics May 27, 2025

Memphis Grizzlies plank NBA playoffs document NABJ Lightless Information & Perspectives

Politics May 26, 2025

The Senate Is Shedding One Of Its Few Difference Average Republicans

Politics May 25, 2025

THE BLACK DOLLAR DOESNโ€™T STAY

Comments are closed.

Don't Miss
Gaming January 28, 2025

AI in 2025: Shifting past code technology to clever building platforms

The instrument building park of 2024 has evident each the prospective and barriers of flow…

Local economic expert: Port strike will have no 'noticeable effect' on grocery supply

October 2, 2024

Coastal Empire reels from Hurricane Helene: Over 60,000 in Chatham County still without power

September 30, 2024

Can AI make video games more immersive? Some studios turn to AI-fueled NPCs for more interaction

September 26, 2024

Which Meals Purpose Heartburn?

February 2, 2025
Categories
  • Business
  • Classifed Ads
  • Climate
  • Education
  • Entertainment
  • Gaming
  • Health
  • Local
  • National
  • Politics
  • Science
  • Sports
  • State
  • Tech
  • Tourism
  • World
About Us
About Us

Savannah Herald is your trusted source for the pulse of Coastal Georgia and beyond. We're committed to delivering authentic, timely news that resonates with our community.

From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
We cover:
๐Ÿ›๏ธ Politics
๐Ÿ’ผ Business
๐ŸŽญ Entertainment
๐Ÿ€ Sports
๐Ÿฉบ Health
๐Ÿ’ป Technology
Savannah Herald: Savannah's Black Voice ๐Ÿ’ช๐Ÿพ

Our Picks

Mel Sings Her Shot At Alex In ‘How To Die Alone’ Finale Episode

September 26, 2024

BWHI Menopause Survey Virtual Toolkit

February 8, 2025

Southwest’s 2025 Agenda Is Right here โ€” and It Features a Unutilized Pass-country Path

December 17, 2024

What Are Apple’s Mail Divisions and Learn how to Flip Them Off on iPhone

February 12, 2025

2024 Tropical Hurricane Has Arrived

November 12, 2024
Categories
  • Business
  • Classifed Ads
  • Climate
  • Education
  • Entertainment
  • Gaming
  • Health
  • Local
  • National
  • Politics
  • Science
  • Sports
  • State
  • Tech
  • Tourism
  • World
  • Privacy Policy
  • Disclaimer
  • Terms and Conditions
  • About Us
  • Contact Us
  • Opt-Out Preferences
Copyright ยฉ 2002-2025 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.