Live data from Hacker News

Inside the Largest US Voter Data Leak

upguard.com

191–200 of 351 posts

Re: Inside the Largest US Voter Data Leak

#191

As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…

What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.

As of right now there is not a Federal law describing exactly what is PII data (which would be a prerequisite for this).

There are many (48) different state laws that do define what PII is and how organizations (commercial and governmental) are to handle data breach notifications. If you want to see what a crazy patchwork map of laws this is checkout:

https://blog.varonis.com/us-state-data-breach-definitions/

These only come into play if a certain minimum number of state residents have had their data compromised and if that data is of a certain class.

Typical classes are:

- Account info - Financial info - Health Info - Health Insurance info - DNA - SSN - Biometrics, etc.

And I'm not a lawyer, and we likely don't have all the facts, but at first glance the data released in this breach doesn't meet any of those classifications. It looks pretty much like the data you'd get out of a phone book (name, address, phone number) with a few data points like geocoding and their guess as to your religion and politics.

Which isn't to say that it's great, or that it's not a problem that this was all released, but it is pretty much public data.

Re: Inside the Largest US Voter Data Leak

#192

As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…

Voter records are public data. What would they be penalized for?

Re: Inside the Largest US Voter Data Leak

#193

Earlier quoted context omitted.

What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.

>?A careless programmer makes a bad choice and the CEO has to go to jail? Come on An institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely? Come on. A CEO is responsible for his organization. If you ruin lives, you have to pay the price. Can't handle the heat? Don't take the job. I hate how CEO's get hundred million dollar para…

An institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely?

I'm going to agree with you in wanting to see someone punished for this, I'm not sure if I'm on the side of jail time in the absence of malicious intent.

Re: Inside the Largest US Voter Data Leak

#194

Earlier quoted context omitted.

> This is actually almost entirely public data Birthday is an included item. That's definitely private as it is often used to confirm identity. "almost public" is meaningless. One data item, like credit card number, or birthday, can make this a dangerous leak.

Birthday is almost certainly public. You can get it easily from the DMV or from any of several dozen commercial providers that resell government data: https://www.dmv.org/public-records/ That it's used to confirm identity shows how weak identity-theft protections are at most institutions, not what's public information. (For that matter, mother's maiden name is basically public information as well: you can get it from…

The site you linked to is not affiliated with any state DMV. It links to a sketchy background check service that appears to be a scam.

Edit: spelling

Re: Inside the Largest US Voter Data Leak

#195

Except this isn't a leak. This is publicly searchable information. I don't know why people are blowing this out of proportion.

Because technologists don't know everything about laws and society, even though they like to think they do. You might add that not only is it searchable, but the Freedom of Information Act and its derivative implementations in state laws mandate that it be made accessible in this way for no cost other than the expense in compiling the records.

People getting angry when "government transparency" is supposedly such a good thing no one questions? Go figure...

Re: Inside the Largest US Voter Data Leak

#196
post #129

Earlier quoted context omitted.

What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.

> What law did they break, exactly? That's not how laws work. Laws can be whatever we write them to be. Losing medical and financial records was once not illegal too.

It absolutely is how criminal laws work under the Constitutional prohibition of ex post facto laws; while we can write forward looking criminal laws however we want (within other Constitutional limits), we can't apply those new laws to past conduct.

Re: Inside the Largest US Voter Data Leak

#197

Speaking as a guy with a lot of experience with voter data ( I built the first "where do I vote" apps for Google and helped found the voting information project): This is actually almost entirely public data. Yes, including addresses and phone numbers and political affiliation. There are some states that is not public as part of the voter file, but you can still get it other ways publicly. For example: USPS, etc. Som…

> This is actually almost entirely public data Birthday is an included item. That's definitely private as it is often used to confirm identity. "almost public" is meaningless. One data item, like credit card number, or birthday, can make this a dangerous leak.

> Birthday is an included item. That's definitely private as it is often used to confirm identity.

Lots of things that are actually not private data are used to confirm identity; “it is used to confirm identity” is not a disproof that a piece of information is public information.

Re: Inside the Largest US Voter Data Leak

#198

Earlier quoted context omitted.

What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.

>?A careless programmer makes a bad choice and the CEO has to go to jail? Come on An institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely? Come on. A CEO is responsible for his organization. If you ruin lives, you have to pay the price. Can't handle the heat? Don't take the job. I hate how CEO's get hundred million dollar para…

But what law specifically was broken? Should we have a law that punishes the CEO for data breeches? Is a CEO responsible if his experts recommended the practice? Is the CEO responsible if their staff went around and did this without conscent? That seems rife for abuse. Don't like your CEO, leak some data and have him go to jail.

Re: Inside the Largest US Voter Data Leak

#199

“‘Microtargeting is trying to unravel your political DNA,’ [Gage] said. ‘The more information I have about you, the better.’ The more information [Gage] has, the better he can group people into "target clusters" with names such as ‘Flag and Family Republicans’ or ‘Tax and Terrorism Moderates.’ Once a person is defined, finding the right message from the campaign becomes fairly simple.” Neal Stephenson wrote a book ca…

I agree, but citizen education should not imho be the only approach here. I'm for much more muscular privacy laws and a slightly narrower tolerance on what's acceptable political speech.

Of course education is great, but look at the vast financial and operational asymmetries between even the most informed individual and well-resourced corporate actors like political parties. I have a super-strong political immune system but being politically engaged and navigating social media is exhausting. For the sake of objectivity I have to systematically expose myself to opinions I find disagreeable lest I retreat into a bubble and be surrounded by confirmation bias, but continuous exposure to countervailing political ideologies is intellectually and morally tiring, given the intense polarization and visceral rhetoric that prevails in today's political discourse.

Despite not liking programming, I've been seriously thinking about building a virtual assistant that I can train to pre-emptively tag people using my peculiar ideological criteria so that I can avoid or at least prepare for certain interactions that I know are going to be psychically difficult. By my value calculus, tuning out of politics is irresponsible at best and suicidal at worst; only communicating with people whose values you share exposes you to confirmation bias, and and inevitably exposes one to manipulation; observation of and argumentation with antagonists is psychically expensive and potentially dangerous.

so much as I agree with you on education, it's not something we can just put on the to-do list and wait a generation to benefit from. And that would be true even if we had a well-functioning educational sector rather than one that fails a large number of children and adults by leaving them only semi-literate and -numerate. People who can't read or reckon well are poorly positioned to identify fallacious political discourse.

Re: Inside the Largest US Voter Data Leak

#200
post #4

Earlier quoted context omitted.

Here is the direct link to Upguard's write up (most of the Gizmodo details are here): https://www.upguard.com/breaches/the-rnc-files It is mostly publicly available data, but not always easily accessible (states have varying requirements and methods of acquisition), firms go through quite a bit to get aggregate files in all 50 states. For them to be put up with no protection is jarring. But not surprising with other…

Yes me too, for research >COUGH http://docs.api.gop.com/2.1 down now LOL! (Зеркало скоро доступно)

I'll keep my eyes peeled LOL
Post reply on HN