`


THERE IS NO GOD EXCEPT ALLAH
read:
MALAYSIA Tanah Tumpah Darahku

LOVE MALAYSIA!!!


Sunday, November 11, 2018

‘I DON’T HAVE A SINGLE CENT LEFT FOR ANOTHER ROUND’: RAFIZI UPSET EVEN AS TECH EXPERT ADVISES DISCONTINUATION OF POLLS – ‘WHAT’S THE POINT, IF THE TABLETS CAN BE BREACHED WHAT MORE THE BACK-END? ‘PREY’ NOT A CYBER ATTACK OR MALWARE BUT IT CAN BE USED TO CONTROL DEVICES. IF AN ATTACKER HAS PHYSICAL ACCESS TO UNPROTECTED TABLETS, IT’S ‘GAME OVER”

RAFIZI Ramli said the e-voting system breach in Julau today confirmed his suspicion of foul play in the party polls, but stopped short of pointing the finger at rival Mohamed Azmin Ali.
“I’m glad we finally got confirmation (on the breach),” said the PKR deputy president candidate.
He said he suspects that polling in Sabah had been compromised as well.
“I found it very difficult to make sense, in terms of the crowd (that turned out) and the results we got. We are dumbfounded, as the results were not what we had expected,” a despondent Rafizi told reporters.
“Now, there is clear confirmation. I hope the party and central election committee (JPP) will get to the bottom of this.”
He said his suspicion was aroused about 1pm, when he saw a man “tampering” with the tablets used in the e-voting process in Julau.
“We even captured on video what he was doing.”
Rafizi said when he and election monitors confronted the man, they were told that he was checking the tablets because he suspected that they had been tampered with.
JPP chairman Rashid Din earlier confirmed that as many as 10 tablets in Julau had been compromised.
Rafizi said the unauthorised application – which Rashid described as “Prey Anti-Theft” software – was designed to “wipe out votes” on the tablets.
The app could only be installed physically, he added.
As a result of the breach, Rashid said, polls in the division have been suspended.
Rafizi, who is former Pandan MP, said he had been well on his way to securing the 3,000 votes he needed to keep up with Azmin, and win Sarawak, when he sensed something was amiss this afternoon.
“I was on the road to winning Julau, and getting the 3,000 votes.”
After JPP confirmed the breach, he said, members who had yet to vote were told not to come.
“We even told some 800 voters not to turn up at 3pm, after there was confirmation that the system had been hacked.
“I could have won Sarawak handsomely.”
Rafizi said it will take a week before any decision on the Julau polls is made. He said he believes that JPP will order a revote.
“I don’t think the results for Julau – whatever the results – will be accepted.”
If a re-poll is called, he said, “I am not certain if anyone has the energy for it”.
“Every time there is a revote, it takes a huge toll on our campaign. To mobilise members in areas like Julau is not easy. The logistics issue is huge.”
And, said Rafizi, he is already broke.
“I don’t have a single sen left to organise another round.”
Julau MP Larry Sng, who is contesting the division chief’s post, and Selangor’s Batu Tiga assemblyman Rodziah Ismail lodged a report on the breach at the Julau police station about 6.30pm.

Tech blogger pours cold water on Julau PKR ‘cyber attack’ claim

Prominent tech blogger Keith Rozario has expressed incredulity over allegations that the computer tablets used for the Julau PKR division elections were subject to a “cyber attack”.
In a series of tweets today, Rozario said the Prey application found on the tablet, which PKR deputy presidential candidate Rafizi Ramli described as a “malware” (malicious software), was a “perfectly legitimate” anti-theft software.
“It’s not malware. It belongs to a category of apps called ‘mobile device management’ (MDM). Typically deployed on corporate devices like smartphones to allow the corporation to control them. Yes, control them!” wrote Rozario.
Rozario explained that some companies used MDMs on devices issued to employees as a form of protection should the device be stolen or if the employee was terminated.
“In order to protect the device from an idiot employee or a malicious actor, or even just a disgruntled staff, they typically install an MDM on their devices to do ‘things’.
“Things like remotely wipe the device, or disconnect it from the email server, or just prevent jailbreaking.
“Prey is an MDM, its presence on a device is not a sign of a ‘cyber-attack’,” wrote Rozario, who said he felt compelled to pen these tweets tonight despite being on holiday.
Rozario is a prominent blogger on digital security. Last November, he set up the sayakenahack.com website which allowed individuals to check if they were victims of a major telecommunications data breach.
‘Not convinced’
On the use of Android tablet computers for the PKR voting system, Rozario said it was difficult to protect devices where an untrusted user had physical access to it.
He explained that this was why iPads menu systems in restaurants and ATM machines are secured in metal enclosures.
“We use to say in infosec (information security), that if an attacker has physical access to the device it’s game over,” he said.
Keith Rozario@keithrozario
I’m actually on holiday at the moment, but I cannot in good faith let this pass.
This is a thread.
malaysiakini.com
✔@malaysiakini
Julau PKR election results suspended after ‘cyber attack’ https://www.malaysiakini.com/news/451306 
View image on Twitter
Rozario also asked aloud if the PKR elections should continue, given that the integrity of the election system had repeatedly been questioned.
“After all would either (deputy presidential candidate) Azmin Ali or Rafizi accept a loss, given these shenanigans, particularly if that loss was very slim? What’s the point of continuing it?” he asked.
“I’m not a PKR member, but as an IT practitioner I wouldn’t be convinced of the results of such setup. Neither should you,” wrote Rozario as a parting shot. – MKINI
THE MALAYSIAN INSIGHT / MKINI

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.