Thread #log4j
"The ‘most serious’ security breach ever is unfolding right now. Here’s what you need to know."

Wondering how this affects #voting machines? Is anyone looking into that?
@rad_atl @VickerySec @kiniry @benniejsmith

via @washingtonpost
washingtonpost.com/technology/202…
“The log4j vulnerability is the most serious vulnerability I have seen in my decades-long career,” Jen Easterly, U.S. Cybersecurity and Infrastructure Security Agency director, said in a Thursday interview on CNBC.
"#Log4j is a chunk of code that helps software applications keep track of their past activities. Instead of reinventing a “logging” — or record-keeping — component each time developers build new software, they often use existing code like log4j instead. It’s free on the Internet"
"A few weeks ago, the cybersecurity community realized that by simply asking the program to log a line of malicious code, it would execute that code in the process, effectively letting bad actors grab control of servers that are running #log4j."
"Huge swaths of the computer code that modern life runs on use Java and contain log4j. Cloud storage companies such as Google, Amazon and Microsoft, which provide the digital backbone for millions of other apps, are affected."
"So are giant software sellers whose programs are used by millions, such as IBM, Oracle and Salesforce. Devices that connect to the Internet such as TVs and security cameras are at risk as well."
"That doesn’t mean everything will be hacked, but it just got a lot easier to do so — just as if the locks on half of the homes and businesses in a city suddenly stopped working all at once."
"the vulnerability is straightforward to take advantage of. In the Minecraft video game, it’s as easy as typing a line of malicious code into the public chat box during a game."
"The vulnerability also gives hackers access to the heart of whatever system they’re trying to get into, cutting past all the typical defenses software companies throw up to block attacks. Overall, it’s a cybersecurity expert’s nightmare."
"Computer programmers and security experts have been working night and day since the vulnerability was publicized to fix it in whatever piece of software they’re responsible for... “Some of the people didn’t see sleep for a long time, or they sleep like three hours, four hours."
I'm just wondering if the staff at @essvote & @dominionvoting & @HartInterCivic & @clearballot have staff working around the clock on this? Not a rhetorical question. Would love an answer.
"Hackers have been working just as hard as the security experts to exploit log4j before the bug gets patched... Hackers have already tried to use it to get into nearly half of all corporate networks around the world..."
"Keep an eye out for an influx of phishing messages in the coming days ... If you get an email saying that your account has been compromised or your package failed to deliver, don’t open any links or attachments."
"The best thing regular computer users can do is make sure the apps they use are updated to their most recent versions... Developers will be sending out patches over the coming days to fix any #log4j issues, and downloading those quickly will be important."

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Lulu Friesdat

Lulu Friesdat Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @LuluFriesdat

14 Sep
Thread #FreedomToVoteAct
From a #Security and #Technology POV, there are some excellent points in the new version & some very concerning ones.

BEST SECURITY PROVISION
Preprinted #handmarkedpaperballots are required in the polling place!! This is something many of us fought for
Voting systems that can print on ballots after they are cast are prohibited - but the provision is weak. It can be "through mechanical means or through independently verified protections." I believe that means it is allowed, but you have to check if it's happening. Not great.
The voter's privacy must be maintained. That's great!
Read 12 tweets
24 Apr
1. "Yesterday was such a frustrating day that by evening I had to go to bed with chest pains..."

Thread. What is a #Hybrid #VotingMachine & Why Do I Care?

lulufriesdat.medium.com/yesterday-was-…
#SMARTelections #ElectionProtection
2. "It started out a good day. The day before I celebrated my 14th anniversary with my husband. The cherry blossom tree we planted in the backyard was exploding in pink taffy balls, and the smell of the lilies he got me floated through the living room as I walked to my desk."
3. "From there it went downhill pretty quickly ... For the last 2 years, I have been trying to protect New York voters, and voters across the country from a particularly “bad” type of voting machine known as a “hybrid”.

What is a “hybrid” voting machine?"
#Hacking #Voting
Read 28 tweets
23 Mar
Thread 1. Where has Tracy Campbell documented #ElectionFraud in the US? I made a list of a few places.
Page numbers are from "Deliver the Vote"

Kansas
San Francisco
Minnesota
Wisconsin
D.C.
Baltimore
MA (Constitution)
Chicago

drive.google.com/file/d/1VWTOW4…
2.
New York (p. 64) multiple listings
Arkansas (p. 65)
Mississippi (p. 88)
“Venal” Indiana (p. 95)W. Virginina (p. 95)
Alabama (p. 100, 158)
Louisiana (p. 103)
Wilmington Riots (p. 105)
Louisville KY (p. 106) multiple listings
North Carolina (p. 104)
3. Rhode Island “a state for sale” “bribery of voters with cash at the polls.”
(p. 136)
Adams County OH, (p. 143)
Terre Haute IN (P. 147- 149)
10th Congressional District of PA “wholesale fraud” (1918) (p. 154)
Iowa (p. 157)
Texas (p. 223)
Georgia (p. 282) “extensive fraud”
Read 4 tweets
7 Mar
Thread. 1. Biden’s #BloodySunday Order an Important Step in Promoting Voter Access civilrights.org/2021/03/07/bid… via @civilrightsorg
2. I think most of us could use a refresher on #BloodySunday. That includes me. I found a good detailed description at the Encyclopedia of #Alabama.encyclopediaofalabama.org/article/h-1876 ""Bloody Sunday" refers to the March 7, 1965, civil rights march"
3. The march was supposed to go 'from Selma to the capitol in Montgomery to protest the shooting death of activist Jimmie Lee Jackson. The roughly 600 marchers were violently driven back by Alabama State Troopers, Dallas County Sheriff's deputies, and a horse-mounted posse"
Read 6 tweets
2 Mar
#HR1 #S1 #Amendments - all passed today
includes a new amendment to study #Blockchain voting
amendment #39
Directs the Election Assistance Commission (@EACgov) to conduct a study regarding the use of blockchain technology to enhance voter security in Federal elections.
44
Requires a sufficient number of ballot marking machines equipped for individuals with disabilities, as defined by the Election Assistance Commission in consultation with the Access Board and the National Institute of Standards and Technology, for all in person voting options.
9. Bourdeaux (GA)
...ensures that the number of drop boxes and geographical distribution of drop boxes provide a reasonable opportunity for voters to submit their ballot; permits for the security of drop boxes through remote or electronic surveillance.
#HR1 #S1 #Amendments
Read 6 tweets
17 Dec 20
#SolarWinds hack. Thread.
1. Dominion Voting Systems, a voting machine vendor used in #Election2020, is a Solar Winds client. It does not use Orion, the product at the center of the hack. via attorney Paul Lehto

Solar Winds list of clients is now hidden solarwinds.com/company/custom…
2. Unknown if #hacking investigation is expanding to all #SolarWinds clients, like Dominion Voting Systems.
#ElectionSecurity #ElectionProtection #Election2020results
3. "early signs indicate the reach of the stealthy supplychain attack will have substantial aftershocks; #SolarWinds claims to have 300,000 customers, inc. /National Security Agency all 5 branches of the U.S. military & entities in /health tech telecommunications media & finance"
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(