As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…
Inside the Largest US Voter Data Leak
161–170 of 351 posts
Re: Inside the Largest US Voter Data Leak
#162Speaking as a guy with a lot of experience with voter data ( I built the first "where do I vote" apps for Google and helped found the voting information project): This is actually almost entirely public data. Yes, including addresses and phone numbers and political affiliation. There are some states that is not public as part of the voter file, but you can still get it other ways publicly. For example: USPS, etc. Som…
where can I get access to this data?
Trivially: http://nationbuilder.com/voterfile
etc
As for "For free", states are generally required by law to give it to you if you ask. Some charge fees. Only two have crazy fees (5k and 30k) has a crazy fee (though if you challenge them, ...etc)
https://trello.com/b/IlZkwYc0/national-voter-file-states-pip...
There is a github project i'm aware of to put together all of the data: https://github.com/national-voter-file/national-voter-file
Re: Inside the Largest US Voter Data Leak
#163As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…
What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
Re: Inside the Largest US Voter Data Leak
#164Earlier quoted context omitted.
As I said in the other thread, this is all public data from various sources (except the modeling). It will be fully filled out. It's very common for political orgs to have the entire voter file for the US (or be able to query it using SQL)
its the aggregation and easily searchable format for 2/3 of citizens that makes this REALLY dangerous for identity theft. they were still grossly irresponsible. no consequences will happen though.
Seriously.
You could, in the next 10 minutes, go purchase a national voter file with all this info on 190 million plus voters.
Just Google "national voter file purchase".
Those are pre-aggregated, and honestly, really cheap (Usually ~2k).
You can also aggregate it yourself for less if you want.
Re: Inside the Largest US Voter Data Leak
#165Earlier quoted context omitted.
What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
You can't blame a "careless programmer" when the real problem is organizations simply not committing any resources to security. It's like a hospital only employing 1 nurse and blaming her when patients inevitably die. The organization has a clear responsibility to employee a sufficient number of experts to protect their data. DRA is not unique here but does demonstrate a pattern of companies playing fast and loose wi…
This isn't a very good example. A shortage of nurses will directly correlate to poor patient care and possible death. But a shortage of security experts? Who knows. I worked at an insurance company that left an access database open to the internet FOR YEARS. We ran analytics when I found it and it was never served from our web server.
So since it didn't get into the public does that mean they were responsible for their security? If the answer is "no" then how would you ever measure these unknowns?
Security is a major problem in tech. It's very difficult, it's nuanced and its vast. Security covers so so much that it would be difficult to one or maybe even a handful of security experts to fully over all aspects of an app depending on your scope.
Beyond that though is mistakes happen. People will screw up. Even security people can screw something up. Throwing someone in jail for a screw up reminds me of the war on drugs; it's not going to stop someone from making a mistake or simply not realizing an unknown unknown.
Re: Inside the Largest US Voter Data Leak
#166Earlier quoted context omitted.
>You can't blame a "careless programmer" when the real problem is organizations simply not committing any resources to security. How have you established that they didn't have a sufficient number of experts? What if they purchased a product or service and it simply didn't work? Its rather harsh to point fingers without having all of the information. >We'll keep seeing things like this until our laws are such that ste…
I'm really impressed at the lengths people will go to defend those whose malfeasance or ineptitude unarguably worsen the lives of up to two hundred million people . You seem like a smart person, please tell me how you think it's OK that these folks' contact details and potentially very detailed psychological and political profile information are now likely available on the dark web? Given that this data was collected…
So far I've seen people disagree with simply throwing them in jail and people who want more data (was is a screw up? even security people make mistakes. Did they not have appropriate resources? etc).
I haven't seen anyone say this is OK in any way, shape or form. I see many reasonable discussions.
Re: Inside the Largest US Voter Data Leak
#167Earlier quoted context omitted.
You can get the other info trivially from other public sources.
Please link me to public sources where I can find political data analytics on myself.
I already mentioned the modeling parts are not public.
Re: Inside the Largest US Voter Data Leak
#168Earlier quoted context omitted.
> This is actually almost entirely public data Birthday is an included item. That's definitely private as it is often used to confirm identity. "almost public" is meaningless. One data item, like credit card number, or birthday, can make this a dangerous leak.
Birthday is almost certainly public. You can get it easily from the DMV or from any of several dozen commercial providers that resell government data: https://www.dmv.org/public-records/ That it's used to confirm identity shows how weak identity-theft protections are at most institutions, not what's public information. (For that matter, mother's maiden name is basically public information as well: you can get it from…
Re: Inside the Largest US Voter Data Leak
#169Earlier quoted context omitted.
Personally, while I understand that this is nothing illegal, I think it's terribly wrong. We just handed everyone, including the 5% of society who tend towards sociopathy, a nicely tagged, collated (and yet probably slightly inaccurate) list of minorities. Hate women? You have a nice list which includes the names, addresses, and telephone numbers of all those women. Hate muslims? Boy do I have just the list for you.…
I don't really disagree that this is a shitty data breach, but on the consequences, I'll point out that the 5% of society who tends to sociopathy already have much lower-effort means to target minorities: Hate women? Look for boobs. Hate muslims? Look for brown skin. Hate Republicans? Look for MAGA hats. That these are inaccurate signals is irrelevant: haters gonna hate, and I really don't think they care whether the…
I think your concept of sociopathy qua serial killer is uninformed and stereotypical. Most sociopaths are not stabby weirdos blinded by hatred, they're just self-centred people with different levels of emotional affect/susceptibility than the general population.
It seems not to have occurred to you that (depending on record quality) a database like this would be great resource with which to find and recruit sociopaths of various stripes.
Re: Inside the Largest US Voter Data Leak
#170http://www.cnn.com/2012/02/01/politics/wisconsin-recall-peti...