Live data from Hacker News

Turkish Citizenship Database Leaked

ibtimes.co.uk

281–286 of 286 posts

Re: Turkish Citizenship Database Leaked

#281
post #214

Some readers have complained about this data being posted here. That's reasonable, but so is the community discussion. So we changed the URL from http://185.100.87.84/ to the least bad news article we could google. If someone has a better URL, we can change it again.

sadasdas

Re: Turkish Citizenship Database Leaked

#282

The leak reported to be from YSG [1], organization that manages the election registers. Software used by them developed by Cybersoft [2]. Cybersoft was part of the system who developed the new identity system in Turkey. The practices used by Cybersoft reported to be horrible. I know someone who worked on that project (about 15 years ago), reportedly they were really bad, playing games on servers where the all identit…

I've been working for Cybersoft for the last 20 years, and I know we have not developed that system, whatever system is in question. We never had contracted work for either the NVI - Nufus Vatandaslik Isleri (General Directorate of Civil Registration and Nationality http://www.nvi.gov.tr/English,En_Html.html), the owner of the data on Turkish citizens, or the YSK - Yuksek Secim Kurulu (Directorate of Elections http://www.ysk.gov.tr/ - they lack content on the English page) the state organizer for elections, and a client of NVI for voter information.

As far as I know, development of the NVI system for "Central Population Management System (MERNİS), Identity Share System and Address Registration System" was contracted to and is still maintained by Kale Yazilim (http://www.kaleyazilim.com.tr/EN/Pages/Haberler.aspx). Likewise the development of the YSK system was contracted to and still maintained by HAVELSAN (http://www.havelsan.com.tr/ENG/Main/urun/2321/the-supreme-el...). Both projects were contracted when AKP was ruling, though I'm not sure why we are discussing this aspect. If the software leaked information, it is the usual suspect: the Turkish government awards contracts on price-point and the easy way to build cheap software is to forgo testing and quality assurance. As Murphy's law states: "Never forget that your weapon was made by the lowest bidder." You get what you payed for.

As a reference system we developed, check out the General Directorate of Revenues' automation for its 1000+ tax offices and the 2003 ComputerWorld Honors winning Internet Tax Office.

Last, we have English content at http://www.cybersoft.com.tr/ENG/?q=node, where you can check our references.

Re: Turkish Citizenship Database Leaked

#283
post #129

TR citizen here, for the last 10 years only those who are really close to AKP got the government contracts including software like this etc. for stupid amounts of money with no know-how. Therefore this is absolutely normal -at least for us-, only thing that surprised me about this leak is this got into front page of HN. Those software "companies" take millions of liras, usually for stupid CRUD stuff, develop it in li…

UPDATE: It turns out the database that was claimed captured by hacking is actually a semi-public data. What's correct is the origin of the source of the database. However that database having limited information about voters are shared by the state agency and distributed to the political parties before the public polls by the mandate of voting laws. The database is actually from 2010 and was not obtained by hacking or anything but leaked by one of the political parties.

When I saw the news I did download the database and searched for myself. My information was not there. Because I am not a registered voter since I live in States. However all my siblings' and parents' information there unfortunately.

There's a fierce political rivalry in Turkey increasingly becoming uglier by day. The story was smelling from the beginning anyway, like implicating president, accusing cronyism and trying to score for some political agenda.

Re: Turkish Citizenship Database Leaked

#285

Here is new leak – USA Driver's Licens Database https://news.ycombinator.com/item?id=11454106

This is a hoax. I looked at the torrent file, the hash for every part is 7d76d48d64d7ac5411d714a4bb83f37e3e5b8df6, which is the sha1sum of 2MiB of zero bytes. I told Transmission to verify local data, and it now thinks it has the whole file.

Re: Turkish Citizenship Database Leaked

#286
post #18

Cryptographers: 1 -- Idiots: 0

The winners here are fraudsters and the losers are the Turkish people. Cryptographers never enter into the equation.

I definitely agree. If only a single cryptographer would have been part of the equation, no one would have had a reason to write “Bit shifting isn't encryption” . Looking at my comment again again, I guess it was simply too short to be understood as a cinical “read it with a smile” kind of thing. Just to be sure no one gets me wrong: I surely did not want to hype any of the bad guys, nor make fun of the victims… the innocent Turkish citizens involved. Yet, I can’t help to shake my head that a Turkish governmental agency was stupid enough to use a near to “xor-by-one” snakeoil crypto thingy instead of well-vetted and security proven cryptographic algorithms and protocols. If they would have, there wouldn’t be a problem – just a blob of encrypted data. Which is why I said: “cryptographers 1 – Idiots 0”… which was merely meant to be interpreted as “roll your own crypto, eat your own poison – no cryptographer would have stepped into the stupid pitfall of using home-brew toys instead of well-vetted algos & protocols”. Hope that somewhat is able to explain what I meant with my comment. If my cynical comment was misunderstood due to its minimalism – my bad. Downvotes correctly punished me accordingly for my comment being too short to be understood upon first glimpse – next time, I’ll be sure to be clearer.
Post reply on HN