Live data from Hacker News

Inside the Largest US Voter Data Leak

upguard.com

241–250 of 351 posts

Re: Inside the Largest US Voter Data Leak

#241

Earlier quoted context omitted.

Um, no. Your birthday is certainly not private information. Births are openly published in the local paper and online. Not to mention stuff like this - http://www.wfsb.com/story/26835982/website-displaying-voters...

Um, yes. It certainly is. I don't want it released publicly, nor have I consented to release it to any website. If there are websites out there sharing that private information, they're doing it without my consent.

You may consider it private, but that doesn't make it legally private. Which is the kind of privacy under discussion in this thread.

Re: Inside the Largest US Voter Data Leak

#242

Earlier quoted context omitted.

Um, no. Your birthday is certainly not private information. Births are openly published in the local paper and online. Not to mention stuff like this - http://www.wfsb.com/story/26835982/website-displaying-voters...

Um, yes. It certainly is. I don't want it released publicly, nor have I consented to release it to any website. If there are websites out there sharing that private information, they're doing it without my consent.

[deleted]

Re: Inside the Largest US Voter Data Leak

#243

Earlier quoted context omitted.

> This is actually almost entirely public data Birthday is an included item. That's definitely private as it is often used to confirm identity. "almost public" is meaningless. One data item, like credit card number, or birthday, can make this a dangerous leak.

Birthday is almost certainly public. You can get it easily from the DMV or from any of several dozen commercial providers that resell government data: https://www.dmv.org/public-records/ That it's used to confirm identity shows how weak identity-theft protections are at most institutions, not what's public information. (For that matter, mother's maiden name is basically public information as well: you can get it from…

"from the DMV"? no.

> DMV.org is a privately owned website that is not owned or operated by any state government agency.

Re: Inside the Largest US Voter Data Leak

#244

Earlier quoted context omitted.

>?A careless programmer makes a bad choice and the CEO has to go to jail? Come on An institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely? Come on. A CEO is responsible for his organization. If you ruin lives, you have to pay the price. Can't handle the heat? Don't take the job. I hate how CEO's get hundred million dollar para…

This isn't social security numbers. This is all publicly available data scrapping stuff. Like your public Facebook profile. If you don't want that stuff to be leaked, then don't put your info publicly on Facebook.

Don't want your freedoms threatened? Avoid attention by never exercising them!

I reject the argument that those who aggregate vast troves of data about people, publicly available or voluntarily shared though they may be, are exempt from any sort of responsibility for the curation and deployment of said data. Informational asymmetries lead to power imbalances, and sufficiently severe power imbalances lead to oppression.

Re: Inside the Largest US Voter Data Leak

#245
post #141

Earlier quoted context omitted.

Let's slide a little more down that slope, then. Where personal data and privacy is concerned, I'd rather err on the side of caution, than the world we live in now.

Dunno about anybody else, but I'd like to find a convenient canyon.

Literally everyone wants that, the problem is there isn't one, at least that anyone's been able to identify as of yet.

Re: Inside the Largest US Voter Data Leak

#246

Earlier quoted context omitted.

I think data that has to do with voting records, or suspected voting records, would be very reasonable to be under the purview of being treated as sensitive data that, if breached, should have consequences to a company.

I'm not saying this shouldn't have consequences. What I'm saying is this is far too nuanced to just say "lock up the CEO"

How about making positive proposals of your own instead of negating everyone else's? Clearly many people find the existing rules and practices inadequate and propose heavy burdens of responsibility commensurate with the substantial incentives and rewards that accrue to success in business.

CEOs are not an oppressed class groaning under the burden of social structures that keep them locked up in the C-suite. Even if they are confronted with draconian penalties for naive misadventure, most CEOs of medium and large firms can afford A+ legal representation. If you're more worried about them than you are about the potential first and second-order effects upon tens or (in this case) hundreds of millions of people, then you are essentially choosing to be a pawn of the powerful.

Re: Inside the Largest US Voter Data Leak

#247

As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change. If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months). At least CEOs I have reported to as CTO were very sensitive for implemention i…

Voter records are public data. What would they be penalized for?

There's more than voter data here.

The size and scope of the data are larger than most voter record data.

The data appear to include proprietary data from various sources who may not agree with the terms of disclosure here.

Scale matters.

Re: Inside the Largest US Voter Data Leak

#249
post #235

Earlier quoted context omitted.

We've been having reasonable discussions on these topics for many years. Discussions that never lead to decisions and actions are a sideshow. I'm calling for action - strong user-centric privacy protections with strict liability and significant personal and organization penalties for negligence, similar to the French model.

Criminalizing something doesn't mean you've "done something about it". It just means you've applied a traditionally flawed approach to fix a systemic problem that could be better handled through education, training and awareness. However, those things are much harder to do than to simply write something into the legal code without the public being any more prepared to deal with the situation.

a systemic problem that could be better handled through education, training and awareness

How's that been working out for you? This isn't a new problem. Where are those educational, training, and social awareness resources? What budgets have been allocated to them? What mechanisms put in place to monitor the effectiveness of the deployment? How many more years of theoretical discussions about ideal solutions should we have before acting, notwithstanding the possibility of error? If your cautious incrementalist approach is so great (and heaven knows I've spent many years thinking and advocating within that framework) why does the problem keep getting worse? How long and to what extent are you willing to wait for this informed public to manifest and (somehow) overcome all the countervailing forces that have economic and political interests in quite different outcomes?

And why, I ask myself, did you respond to my positive proposal about "strong user-centric privacy protections with strict liability and significant personal and organization penalties for negligence" by ignoring it and instead knocking down a straw man of 'criminalization' that I took care to avoid?

You don't want to be the person responsible for taking or advocating for a decision that might work out poorly, fine. But reiterating the reasons for your hesitancy achieves nothing.

Re: Inside the Largest US Voter Data Leak

#250

Earlier quoted context omitted.

Treat everything as PII and we are good. The constitution has an amendment to protect our rights. That seems important. I know of no guaranteed right of corporations to infringe on our privacy and to provide access our data. Forty years ago we didn't have this issue because there wasn't so much data for them to try to get their grubby greedy hands on. They don't need our data (ANY OF IT)!

The US constitution forbids the US government from acting in certain ways, it in no way impedes upon private organizations. Tort law and the like is what holds private organizations accountable. i.e. The fourth amendment does not protect you from a private entity or individual; laws covering trespassing, theft, breaking and entering do. Please don't drag the constitution into an argument it does not have a place in.

I'd like to argue (not for the first time either) that the Constitution is seriously deficient in its failure to enshrine privacy as a personal right. Great as it has been for the last couple of centuries, I think it's obsolete and should be replaced rather than merely amended.
Post reply on HN