Mike March 11, 2020 11:42 AM

Is there a link to the 10 page complaint, if it is in fact publicly available? I hate when things like this (or similarly, court rulings) are reported without a link to the source.

Kurt Seifried March 11, 2020 12:12 PM

I’m guessing

“And the appropriate steps have been taken to ensure that our cybersecurity is compliant with all applicable laws and security standards.”

Is actually not completely incorrect. Most standards/laws don’t force you to keep up to date or even on supported versions of software.

Nik March 11, 2020 12:57 PM

@myliit :
Last time I voted in Los Angles -2019 was a paper vote with INK-A-VOTE. The machines themselves :

In the area of cryptography and key management, multiple potential and actual vulnerabilities were identified in the InkaVotePlus, including inappropriate use of symmetric cryptography for authenticity checking, use of a very weak homebrewed cipher for the master key algorithm, and key generation with artificially low entropy which facilitates brute force attacks. In addition, the code and comments indicated that a hash (checksum) method that is suitable only for detecting accidental corruption is used inappropriately with the claimed intent of detecting malicious tampering. 106 instances were identified of SQL statements embedded in the code with no evidence of sanitation of the data before it is added to the SQL statement

No worries there. The bigger worry is the history of corruption and funds disappering from LADWP and such. They certainly saved on infrastructure maintenance in order to give large payouts to top officials.

Matt March 11, 2020 1:24 PM

“Most standards/laws don’t force you to keep up to date or even on supported versions of software.”

NIST CSF PR.IP-12: A vulnerability management plan is developed and implemented

Per NIST, that maps to the following:
CIS CSC 4, 18, 20
COBIT 5 BAI03.10, DSS05.01, DSS05.02
ISO/IEC 27001:2013 A.12.6.1, A.14.2.3, A.16.1.3, A.18.2.2, A.18.2.3
NIST SP 800-53 Rev. 4 RA-3, RA-5, SI-2

There are certainly standards and laws that mandate patching and using supported software.

