I hate to be in the position of defending a leak such as this. But if what they've done is "merely" compiling data that was available from our public profiles, are they obligated to secure that compilation? I'm asking -- I don't know for sure how the data was gathered, it just sounds like it was from scraping public records + public web sites. Also, can someone ask Troy Hunt whether he has or can get access to this d…
Inside the Largest US Voter Data Leak
121–130 of 351 posts
Re: Inside the Largest US Voter Data Leak
#122I hate to be in the position of defending a leak such as this. But if what they've done is "merely" compiling data that was available from our public profiles, are they obligated to secure that compilation? I'm asking -- I don't know for sure how the data was gathered, it just sounds like it was from scraping public records + public web sites. Also, can someone ask Troy Hunt whether he has or can get access to this d…
Voter files being public data depends on which state you're talking about -- you're looking at ~50 different sets of laws and regulations. Some states restrict access to only political parties using it for political uses and prohibit distribution to non-parties/candidates. Some states (Florida, for example) will let anyone just apply to get it. To your latter question, some states, like California, do include email a…
Re: Inside the Largest US Voter Data Leak
#123Earlier quoted context omitted.
That does not even nearly fit on one line, so I broke it up. Yeah, it looks pretty bad. Here's hoping it's only sparsely filled out. State Juriscode Jurisname CountyFIPS MCD CNTY Town Ward Precinct Ballotbox PrecinctName NamePrefix FirstName MiddleName LastName NameSuffix Sex BirthYear BirthMonth BirthDay OfficialParty StateCalcParty RNCCalcParty StateVoterID JurisdictionVoterID LastActiveDate RegistrationDate VoterS…
As I said in the other thread, this is all public data from various sources (except the modeling). It will be fully filled out. It's very common for political orgs to have the entire voter file for the US (or be able to query it using SQL)
Re: Inside the Largest US Voter Data Leak
#124I have this theory that the only way regular people will start caring about privacy breaches such as this one is to use that data against them in a malicious way. Tell the average Joe that the data of all US voters has been leaked, "Hmmm. That's bad." and they move on with their lives as if nothing happened. Instead, if this data is used to impersonate the average Joe on social media or if it's used to trick their mo…
The other thought experiment is to adopt the opposite point of view that privacy is overrated. You can adopt various worldviews from 'everything is grey' to 'this is good, that is bad" but punishing someone to care about same things you care about is a pretty terrible approach. If you can't convince someone, it doesn't mean they're stupid, it could also mean you just aren't that good at communicating, or that perhaps what you think is important isn't all that important.
>Unless the company involved is sued to bankruptcy and the people involved are prosecuted, sending a strong message to companies dealing with user data, nothing will change.
Or we can give them tools that make it easier to secure data. I've always found that if you make it easy for someone, they almost always end up doing the right thing. As it stands the security products/services domain is a complicated maze where you have to be an expert to evaluate how various products work internally and which services, if any are worth purchasing.
Re: Inside the Largest US Voter Data Leak
#125Earlier quoted context omitted.
If this data has private information on non-republicans then jail them for having it, not for leaking it. There is no special purpose in these two groups of colluding Americans that grants them special rights to gather data on their non-associates any differently than any other member of the public.
If they are gathering data through any means it's no different than other marketing firms. I think the real debate needs to be about what any companies can share.
What you can share lets companies store and make decisions based on data they shouldn't have and couldn't share as long as their inputs and outputs look clean.
I,e. Facebook or Google could help you intentionally run a race biased campaign across all their assets as long as they don't tell you any specifics and include a little noise so you can't be sure of any one user's race. All thanks to what they can collect, use, but refuse to share.
Re: Inside the Largest US Voter Data Leak
#126I have this theory that the only way regular people will start caring about privacy breaches such as this one is to use that data against them in a malicious way. Tell the average Joe that the data of all US voters has been leaked, "Hmmm. That's bad." and they move on with their lives as if nothing happened. Instead, if this data is used to impersonate the average Joe on social media or if it's used to trick their mo…
Re: Inside the Largest US Voter Data Leak
#127I hate to be in the position of defending a leak such as this. But if what they've done is "merely" compiling data that was available from our public profiles, are they obligated to secure that compilation? I'm asking -- I don't know for sure how the data was gathered, it just sounds like it was from scraping public records + public web sites. Also, can someone ask Troy Hunt whether he has or can get access to this d…
Personally, while I understand that this is nothing illegal, I think it's terribly wrong. We just handed everyone, including the 5% of society who tend towards sociopathy, a nicely tagged, collated (and yet probably slightly inaccurate) list of minorities. Hate women? You have a nice list which includes the names, addresses, and telephone numbers of all those women. Hate muslims? Boy do I have just the list for you.…
Not many years ago, there used to be a book distributed far and wide with the names, address, and phone number of virtually everyone that lived in your city. This was accepted as normal and routine, and you had to specifically opt out of being included.
Re: Inside the Largest US Voter Data Leak
#128I hate to be in the position of defending a leak such as this. But if what they've done is "merely" compiling data that was available from our public profiles, are they obligated to secure that compilation? I'm asking -- I don't know for sure how the data was gathered, it just sounds like it was from scraping public records + public web sites. Also, can someone ask Troy Hunt whether he has or can get access to this d…
Personally, while I understand that this is nothing illegal, I think it's terribly wrong. We just handed everyone, including the 5% of society who tend towards sociopathy, a nicely tagged, collated (and yet probably slightly inaccurate) list of minorities. Hate women? You have a nice list which includes the names, addresses, and telephone numbers of all those women. Hate muslims? Boy do I have just the list for you.…
Hate women? Look for boobs.
Hate muslims? Look for brown skin.
Hate Republicans? Look for MAGA hats.
That these are inaccurate signals is irrelevant: haters gonna hate, and I really don't think they care whether the brown-skinned person they're harassing is actually a Muslim, they just want a target for their anger.
As for ad networks - they already have much more accurate models of age, ethnicity, and religion than the RNC has. There's a lot more money involved in targeting ads, and so they've put a lot more effort into it than political consultancies. Worrying about them is like closing the barn door after the horse is out.
Re: Inside the Largest US Voter Data Leak
#129As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…
What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
That's not how laws work. Laws can be whatever we write them to be. Losing medical and financial records was once not illegal too.
Re: Inside the Largest US Voter Data Leak
#130Earlier quoted context omitted.
> If you are on the side of revealing this information, you are on the same side as some pretty unpleasant folks. I try to pick my sides based on what seems right, not based on who else picks that side. (I do not have a side in this particular fight.)
> I try to pick my sides based on what seems right, not based on who else picks that side. I look at the picker of sides and their motives to determine the consequences of picking a side. I tend to favor protection of people as a whole.
Taken literally, this suggests that you can't work out the consequences without looking at the supporters. If that's what you mean, I have to say it seems weird to me.
Taken less literally: if you think the consequences of one side winning include "people get harmed", you can just say that. You can point at the consequences instead of the supporters.