Maricopa Election Management Server (2020): Difference between revisions
| Line 13: | Line 13: | ||
[[MC EMS 2020 - Election Management System Database Purged|The]] following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation. These were investigated as allegation #3 in the AZ AG's inspector report. Each sub-allegation was assessed independently for governance gaps, which are explained on separate web pages. | [[MC EMS 2020 - Election Management System Database Purged|The]] following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation. These were investigated as allegation #3 in the AZ AG's inspector report. Each sub-allegation was assessed independently for governance gaps, which are explained on separate web pages. | ||
# [[MC EMS 2020 - Election Management System Database Purged|Election Management System Database Purged]] | # [[MC EMS 2020 - Election Management System Database Purged|Election Management System Database Purged]] | ||
# [[ | # [[MC EMS 2020 - Election Files Deleted|Election Files Deleted]] | ||
# [[MC EMS 2020 - Corrupt Ballot Images|Corrupt Ballot Images]] | # [[MC EMS 2020 - Corrupt Ballot Images|Corrupt Ballot Images]] | ||
# [[MC EMS 2020 - Missing Ballot Images|Missing Ballot Images]] | # [[MC EMS 2020 - Missing Ballot Images|Missing Ballot Images]] | ||
Revision as of 14:21, 31 August 2026
In your exploration of election-related anomalies, you are here:
- List of Election Anomalies
- Arizona Attorney General's Inspector's report of Arizona Senate of Allegations
- Allegation #3: Maricopa County Election Department - Election Management System----[Click for Allegation #2 or Allegation #4]
- Arizona Attorney General's Inspector's report of Arizona Senate of Allegations
This page provides an overview of Arizona Attorney General's Office 2020 General Election Investigation Report.
Click on the list of Sub-allegations for an analysis of the potential governance gaps.
The Governance Gap Assessment Team are not IT security experts. The technical aspects of the IT configuration are not being disputed. The assessment for governance gaps sought to understand how data and information was being treated with respect to the US GAO's Standards for Internal Control in the Federal Government.
List of Election Management System Sub-allegations
The following allegations were submitted by the Arizona Senate in 2021 to the Arizona Attorney General for investigation. These were investigated as allegation #3 in the AZ AG's inspector report. Each sub-allegation was assessed independently for governance gaps, which are explained on separate web pages.
- Election Management System Database Purged
- Election Files Deleted
- Corrupt Ballot Images
- Missing Ballot Images
- Failure to Follow Basic Cyber Security Practices
- Subpoenaed Equipment Not Yet Provided
- Anonymous Logins
- Dual Boot System Discovered
- Operating System Logs Not Preserved
- Internet Connections to the EMS
3 - Corrupt Ballot Images
Allegation
The was an allegation of 263,139 unreadable ballot images. This allegation originated with Cyber Ninjas.
Relevant Inspector Notes
The AZ AG's inspector was told, MC Election officials randomly selected images during January 2022 from the date period of allegedly corrupted ballots and were able to open all images.
Inspector's Finding
Undetermined. Agents are pending a date to review archived data to ensure all election files are present.
Governance Gaps Assessment
- As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
- The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
- Sometimes words matter. The allegation was 263,139 ballots were unreadable. MC randomly opened selected images. Agents were unable to determine if the files were present. Given that specific value of 263,139, it's not clear why those ballots were not made available to the inspectors to determine if they were readable.
4 - Missing Ballot Images
Allegation
The total amount of ballot images is allegedly less than the official vote count. The allegation originated from Cyber Ninjas.
Relevant Inspector Notes
- "During the investigation, agents leaned that Maricopa County Election Officials during the Correcting the Record report in January 2022, reviewed the cloned copies of hard drives that were provided to Cyber Ninjas and located the files that were claimed missing."
Inspector's Finding
Undetermined. Agents are pending a date to review archived data to ensure all election files are present.
Governance Gaps Assessment
- As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
- The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
- The AZ AG's inspector's note begs a follow up question. It MC said they found the records, why were the agents able to close this issue as being unfounded.
5 - Failure to Follow Basic Cyber Security Practices
Allegation
The Basic Cyber Security Practices were allegedly not followed. The allegation originated from Cyber Ninjas. They explained the Department of Homeland Security's Cybersecurity & Infrastructure Security Agency (CISA) has guidelines, which MC was not following.
Relevant Inspector Notes
- The EMS server along other election equipment is configured in an air gapped standalone system (no outside connectivity outside of the control access room).
- CISA guidelines are not applicable because of the air gapped configuration.
- The EMS server along with the other election equipment resides inside a controlled access room under 24-hour video monitoring.
- A two-person rule is required to enter the room.
Inspector's Finding
Unfounded Allegation. The inspector found no indication of malicious or criminal acts performed by Maricopa County Elections Officials.
Governance Gaps Assessment
- The AZ AG's inspector explains the equipment is under 24-hour surveillance. However, the inspector did not claim to have reviewed the surveillance videos. In fact, the surveillance videos were likely unavailable given the common practice to overwrite the video data with new surveillance video data after a sufficient time has elapsed to retrieve video data from the suspected time frame. Without an independent review of the surveillance video by the inspector, there seems to be an overreliance on the simple existence of the 24-hour camera to make the assertion of "no malicious or criminal acts.
- The AZ AG's inspector relied on the MC leadership team claiming that a two-person rule is required to enter the room. There is no indication that the 24-hour video data was reviewed to confirm the two-person rule was always applied.
- The AZ AG's inspector did not report on the existence of an entry and exit log for each person, which was maintained by a third independent person uninvolved with the EMS activities.
- The AZ AG's inspector had already noted that procedure violations had occurred during drop box collections. It would have seemed critical for the inspector to claim "no indication of malicious or criminal acts" if objective data was not reviewed to confirm compliance with the two-person rule.
- The AZ AG's inspector was told of a two-person rule. During the inspector's investigation of the drop box collection allegations, the two-person rule was more specific. One member of each political party (i.e., Democrat and Republican) had to be assigned to a collection team. The consequence of malicious and criminal performed on the EMS would be far more serious than a drop box collection, but the teaming requirement is less restrictive. In this case, the two-person rule is being questioned as being too lenient for the associated risk.
- The AZ AG's inspector was told the Maricopa County within compliance of state and federal law as it pertains to these areas. Federal laws and Arizona Statutes are essentially policy statements, which affected entities are obligated to follow. Laws and statutes do not typically provide the necessary details form implementation of the laws and statutes. The inspector did not identify any IT standards for data security that MC Elections were following. They only claim to be in compliance with laws and statutes without any standard.
6 - Subpoenaed Equipment Not Yet Provided
Allegation
Cyber Ninjas alleges the Maricopa County Recorder's Office did not provide all of the equipment requested under the subpoena.
Relevant Inspector Notes
"During an interview with Mr. Gates from the Maricopa County Board of Supervisors, all data and equipment was provided as requested by the subpoena and that items not subpoenaed were not provided to the State Senate. He further related that sensitive routers and log files were not provided and were part of the settlement agreement. Mr. Gates stated he is not aware of what was provided to Cyber Ninjas by the Senate and that question should be directed to Senate President Fann."
Inspector's Finding
Unfounded Allegation. According to statements made by Mr. Bill Gates and a letter dated September 17, 2021 by State Senate President Karen Fann to Attorney General Mark Brnovich, all materials were provided to the State Senate by Maricopa County.
Governance Gaps Assessment
- It's interesting to note that the allegation was against the Maricopa County Recorder's Office (MCRO). However, the AZ AG's inspector directed his questions to the Chairman of the Maricopa County Board of Supervisors (MCBOS). The MCRO does not report to the MCBOS.
- The equipment was not voluntarily released to the Arizona State Senate, which was in an oversight role. Apparently, the issue was litigated, and the scope of equipment was agreed upon in a court settlement.
- The AZ AG's inspector reports that the Chairman of the MCBOS is withholding sensitive routers and log files as part of the settlement agreement.
7 - Anonymous Logins
Allegation
Anonymous logins allegedly occurred. The allegation originated from Cyber Ninjas.
The AZ AG's inspector notes, "Cyber Ninjas stated there are common functions in Windows which will record login activity to security logs. Logins exhibit known recording sequences within the logs that allow analysis to determine the origination of the requesting function and determine the legitimacy of the logged action."
Paraphrased by the Governance Gap Assessment team: Cyber Ninjas appears to have observed a record of actions being taken within a Window-based computer. However, they were unable to determine who was performing the functions. The concern appears to be with the anonymity of the log in, not the actual changes made by the person with the anonymous login.
Relevant Inspector Notes
"Within the PacketWatch report, there was a section identified specific to these allegations. Per PacketWatch they reviewed logs from 11/18/2020 - 3/5/2021. During that time frame, they observed 205 Logon Type 3 evens and 5 of them had "anonymous logon" as the account name. PacketWatch indicated they further reviewed the logons and indicated they are normal interactions between Windows-based devices that are connected on the same network where one or more of them have resources shared (shared drives, printers, etc.) to the network. Packet Watch further stated there were no logged events in the proximity of these events to indicate the "anonymous" user was running any "script-based activity."
Inspector's Finding
Undetermined - The allegations by Cyber Ninjas appear to have different activity dates as to that which was reviewed by PacketWatch. Agents have a pending request to review anonymous logins with Election Officials.
Governance Gaps Assessment
- As of the winter of 2021, all of the election files were still not available for inspection by the AZ AG's inspectors, after more than one year had elapsed since the General Election of 2121.
- The report states follow up is needed but does not identify any one person accountable for the follow up. This issue remains unresolved based on the contents.
- It's unclear why the AZ AG's inspector spent time using a prior report by PacketWatch. The PacketWatch report addressed a different time frame than the Cyber Ninjas allegations. Therefore, the PacketWatch report was irrelevant from the perspective of addressing the allegations.
- That said, the AZ AG's use of the PacketWatch report seemed to support Cyber Ninjas allegations. The detection of anonymous logins in different time frames by separate entity (i.e., PacketWatch) than reported by Cyber Ninjas would confirm anonymous logons.
- There is the possibility that script-based activities had been run by an anonymous logon during Cyber Ninjas time frame given those events were not reviewed by the inspector.
- MC staff was apparently silent on the issue. The PacketWatch report was already completed and available for review by the AZ AG's inspector. However, there inspector did not note that the County had taken any investigative or corrective actions to address anonymous logons.
8 - Dual Boot System Discovered
Allegation
Cyber Ninjas analyzed a system labeled Adjudication 2 and revealed the system contained two bootable hard drives. Cyber Ninjas stated neither Pro V&V not SLI identified this in their report.Relevant Inspector Notes
- By review of a publicly available document, Correcting the Record - January 2022, there was a second hard drive found on one computer.
- The second hard drive was not powered on or used at any time while in Maricopa County's possession.
- The second hard drive did not play a role in any Maricopa County election as it was not plugged into the computer, and therefore not operational.
- County Election Officials stated SLI confirmed the presence of this drive on an adjudication state labeled "ADJ-54."
- During the SLI audit, the drive was photographed and forensic clone was created for analysis.
- SLI determined the drive was not plugged in and was last used on 7/31/2019, which was prior to County Elections receiving items.
Inspector's Finding
Undetermined.
- County Elections makes statements about SLI Compliance findings related to dual boot systems. However, within the SLI report, there is no mention of this finding.
- Furthermore, County Elections stated they did not retain copies of photos for this portion of the SLI report but stated that are available by request from SLI.
- Elections was unsure if it was the same computer identified by Cyber Ninjas, based upon the two dates available from Cyber Ninjas and SLI, and the different naming conventions. It is unclear if they were referring to the same computer.
Governance Gaps Assessment
x
9 - Operating System Logs Not Preserved
Allegation
Relevant Inspector Notes
Inspector's Finding
Governance Gaps Assessment
x
10 - Internet Connections to the EMS
Allegation
Relevant Inspector Notes
Inspector's Finding
Governance Gaps Assessment
x
