Voting system passwords were accidentally posted on the Secretary of State 's website for several months before they were discovered and removed, but the bug posed no immediate threat to the upcoming election, state elections officials said Tuesday.
See also: Elon Musk: Is he paying Americans to support Donald Trump?

The passwords were just one of two required to access any element of Colorado's voting systems and are just one part of a multi-layered security system, said Jack Todd, a spokesman for the Secretary of State's office. The two passwords "are kept in separate places and maintained by different parties," he said.
"They are not a security threat," Colorado Secretary of State Jena Griswold told 9News in an interview. She said employees are changing passwords, reviewing access logs and chain of custody books.
Colorado is often called the gold standard for election security, although there have been some problems in the past. The error drew criticism from the chairman of the Colorado Republican Party at a time of increased scrutiny of the country's election systems, although US elections remain highly reliable.
See also: Ukraine: Russia uses generative AI to spread disinformation
Colorado law requires that voting equipment be monitored and stored in secure locations — access to which is monitored and recorded. Colorado voters fill out paper ballots, which are audited after the election.

Election officials learned last week that the spreadsheet, which contained Colorado's voter codes in a hidden tab, was available online .Once the bug was discovered, they acted immediately and notified the U.S. Cybersecurity and Infrastructure Security Agency.
Colorado Employees Union executive director Matt Crane told 9News that while the error was concerning, the union was satisfied with the Colorado Secretary of State's response.
Colorado GOP Chairman Dave Williamssent a letter to the department on Tuesday demanding, among other things, that the secretary of state confirm that the exposed passwords have since been changed.
See also: Disinformation campaign targets Moldova ahead of referendum
Password leaks are a major security concern in today’s digital landscape. When passwords are compromised, unauthorized individuals can gain access to personal and sensitive information, leading to identity theft, financial loss, and privacy breaches. To mitigate the risks associated with password leaks, it is important for individuals and organizations to adopt strong password practices. This includes using complex passwords with a combination of characters, enabling two-factor authentication, and regularly updating passwords. Awareness and education about potential phishing and security breaches are also crucial to protecting one’s digital identity.
Source: securityweek
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
