Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Dominion Voting Systems CEO Says Company Has Never Used SolarWinds Orion Platform
Epoch Times ^ | 12/15/2020 | Zachary Steiber

Posted on 12/15/2020 3:30:16 PM PST by SeekAndFind

The CEO of Dominion Voting Systems on Tuesday said the company has never used a platform that experts believe was breached by hackers as far back as last year.

“We don’t use the SolarWinds Orion package that was the subject of the DHS report from the 13th,” CEO John Poulos told legislators in Michigan via video link.

However, a screenshot of a Dominion webpage that The Epoch Times captured shows that Dominion does use SolarWinds technology. Dominion later altered the page to remove any reference to SolarWinds, but the SolarWinds website is still in the page’s source code.

SolarWinds’s technology was exploited by actors who inserted malicious software into updates for its Orion platform, according to officials with the Department of Homeland Security (DHS) and cybersecurity experts.

The DHS’s Cybersecurity and Infrastructure Security Agency (CISA) warned that the compromise of the network “poses unacceptable risks” and ordered federal agencies that use it to revoke internet access to the affected devices.

The attack “was likely the result of a highly sophisticated, targeted, and manual supply chain attack by an outside nation state, but we have not independently verified the identity of the attacker,” the company said in a statement.

Non-Orion products don’t appear to have been compromised, SolarWinds said.

Poulos said Dominion hasn’t ever used the Orion platform. No legislators asked him about what SolarWinds technology the company does use, and Dominion didn’t respond to requests for comment.

Dominion provides voting equipment and software to 28 states.


(Excerpt) Read more at theepochtimes.com ...


TOPICS: Crime/Corruption; News/Current Events; Politics/Elections
KEYWORDS: ceo; dominion; hacking; solarwinds
Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last
To: palmer

See my prev comments on this matter.

Signing your malicious code with a random cert is trivial, but creating your own binary signed by ‘microsoft’, or ‘solarwinds’ or ‘etc’ is hard. Inserting it into their update program is harder. I know cause i have done it. Very stressful, cause its on you if something is wrong and there are insane audit trails that do not go missing.

Unsigned ‘open source’ is not even in the same ball park’

Yes Adobe (flash product) has been a clusterf#(k forever but that has nothing to do with this.


41 posted on 12/15/2020 9:32:09 PM PST by algore
[ Post Reply | Private Reply | To 40 | View Replies]

To: SeekAndFind
Gosh, one more time we are told by the “experts” that we should not believe our eyes when they tell us things, as they get to choose which parts of what they tell us are true and which parts are false.

I would like to see him under oath in a court of law with the threat of perjury and under cross examination make the same statement. I would wager he would take the 5th Amendment.

42 posted on 12/15/2020 10:03:55 PM PST by Robert357
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #43 Removed by Moderator

To: SeekAndFind

Sorry... can someone get me up to speed on what “Solar Winds / Orion” is all about? Having a hard time keeping up with everything lately. Thanks.


44 posted on 12/15/2020 10:08:04 PM PST by nutmeg (Mega prayers for Rush Limbaugh)
[ Post Reply | Private Reply | To 1 | View Replies]

Comment #45 Removed by Moderator

To: SeekAndFind
from Imgflip Meme Generator
"width=500">
46 posted on 12/16/2020 12:30:58 AM PST by Spitzensparkin1 (Donate often, it is our FReeping ammo. Keep the supply train rollin', become a monthly donor. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeekAndFind

What is the version of the software with the known vulnerability? Whether these machines are running Windows or Linux, getting this version info is pretty easy.


47 posted on 12/16/2020 2:45:26 AM PST by nonsporting ("Christ shall be magnified in my body, whether it be by life, or by death." Philippians 1:20b)
[ Post Reply | Private Reply | To 3 | View Replies]

To: algore
but creating your own binary signed by ‘microsoft’, or ‘solarwinds’ or ‘etc’ is hard. Inserting it into their update program is harder. I know cause i have done it.

You mean easier. Just because solarwinds says it was "highly sophisticated" doesn't mean it was. It was very likely trivial to get the malicious software in. The solarwinds code signing cert private keys may or may not have been protected. The attackers may have used their own code signing private key.

Adobe is very relevant. A long vulnerability track record in both cases. Those track records are not an accident or random slop.

48 posted on 12/16/2020 5:54:41 AM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 41 | View Replies]

To: palmer

” The attackers may have used their own code signing private key.”

that fact that you even said that means you are totally clueless.

but don’t let that get in the way of your narrative.


49 posted on 12/16/2020 11:46:24 AM PST by algore
[ Post Reply | Private Reply | To 48 | View Replies]

To: algore
I don't have a narrative, you do. I looked up the attack and it was just a compromise of the integration environment, so they piggybacked on normal code updates. Their shotgun result may have benefitted some adversaries but more targetted attacks on other vulnerable SolarWinds products will be harder to detect.
50 posted on 12/16/2020 2:52:26 PM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 49 | View Replies]

To: malach

The presence of “QSnatch” does not necessarily indicate a hack, that could be intentional.


51 posted on 12/19/2020 9:20:05 AM PST by WHBates
[ Post Reply | Private Reply | To 43 | View Replies]

Comment #52 Removed by Moderator


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson