Skip to main content

EVS 6.0.4.3

Tuesday, January 02, 2024
Testing standard
Testing Lab
Certification Date
03/11/2020
Certification Status
Certified System
Testing Application Date
01/03/2020
Testing Status
Certified
Application Accepted Date
01/09/2020
Testing Documents Media
Test Report Media
Advisory Notice Media
Product
Version
6.0.4.3
Forum

2020 Elections Disability, Accessibility and Security Forum

As the 2020 elections rapidly approach, the US Election Assistance Commission (EAC) designed a forum to address growing concerns regarding accessibility and security. This all-day forum brought together state and local election officials, people with disabilities, disability advocates, and election security experts to discuss issues and advance solutions.
Start Time
Thursday, February 20, 2020 9:00 AM
End Time
Thursday, February 20, 2020 3:00 PM
Conference Call

Technical Guidelines Development Committee Conference Call - 020720

The Technical Guidelines Development Committee (TGDC) discussed the Voluntary Voting System Guidelines 2.0 (VVSG 2.0) Technical Requirements and goals for 2020, and voted on recommending the requirements to the EAC's Acting Executive Director.
Start Time
Friday, February 07, 2020 1:00 PM
End Time
Friday, February 07, 2020 3:00 PM

The EAC will publish a list of voting systems that have been certified with this patch. Additionally, you should reach out to your voting system vendor for information on whether an update is necessary and what their implementation plan is in the event you require an update.

The EAC has reached out to voting system manufacturers and test labs reminding them that software de minimis changes are available for this type of update. We encourage manufacturers to submit updates to affected systems as soon as possible. The Testing and Certification program stands ready to expedite review of these changes.

Since the ECC vulnerability described above requires that malicious software be loaded on to a vulnerable system in some manner, security measures designed to protect against accidental or unauthorized software installation should be implemented and/or existing procedures reviewed. For voting systems, precautions should be taken when transporting media (USB, flash drives, DVD-ROM, etc.) between components connected to public networks such as the internet and certified voting system components. This could include setting up a stand-alone PC (not connected to the internet or voting system) that has been patched and has up-to-date anti-malware/anti-virus software installed that is used to scan any media before it is introduced to the voting system. Additionally, we recommend that physical security best practices should be followed, including sealing USB, CD/DVD readers, and other external connections when not in use.

While voting systems operate in an air-gapped environment that may mitigate the Remote Desktop Protocol (RDP) vulnerability described in the notice, the EAC considers the Elliptic Curve Cryptography (ECC) validation vulnerability a significant threat to voting system security. According to information in DHS Emergency Directive 20-02, “This vulnerability may allow malicious software to bypass the trust store, allowing unwanted or malicious software to masquerade as authentically signed by a trusted or trustworthy organization, which may deceive users or thwart malware detection methods like anti-virus”. This vulnerability affects systems using Windows 10, Server 2016, and Server 2019. Please reach out to your voting system vendor for further information on whether or not your specific configuration is affected and their mitigation plans.

Voting Systems Testing Updates

Voting System Anomaly Reporting - January 28, 2020

With the 2020 election year kicking in to full swing, I thought it was a great time to remind everyone of an important pillar of the EAC’s Testing and Certification program – voting system anomaly reporting.

Tuesday, January 28, 2020
Subscribe to