Live data from Hacker News

Inside the Largest US Voter Data Leak

upguard.com

251–260 of 351 posts

Re: Inside the Largest US Voter Data Leak

#251
post #124

I have this theory that the only way regular people will start caring about privacy breaches such as this one is to use that data against them in a malicious way. Tell the average Joe that the data of all US voters has been leaked, "Hmmm. That's bad." and they move on with their lives as if nothing happened. Instead, if this data is used to impersonate the average Joe on social media or if it's used to trick their mo…

>I have this theory that the only way regular people will start caring about privacy breaches such as this one is to use that data against them in a malicious way The other thought experiment is to adopt the opposite point of view that privacy is overrated. You can adopt various worldviews from 'everything is grey' to 'this is good, that is bad" but punishing someone to care about same things you care about is a pret…

There's a pretty compelling argument though, that people aren't good at making long-term assessments of diffuse, but potent, risks, and/or are willing to, or can be coerced into, arbitraging long-term interests with short-term exigency.

Gresham's law, availability hueristics, optimism bias, distribution of cognitive skills, various aspects of game theory, and more, strongly suggest this.

Examples: global warming, pollution risks, resource depletion, moral and morale hazard, just off the top of my head.

Re: Inside the Largest US Voter Data Leak

#252

Earlier quoted context omitted.

> Birthday is an included item. That's definitely private as it is often used to confirm identity. mylife.com publicly posts birthdays so apparently not

No kidding, but I don't want that information out there, and I imagine most people don't. Just because some skeezy website shares all my personal information does not make it public information. It's private to me and I'd rather it remain undistributed, where possible. Overall point being, this US voter data leak is bad. That appears to have released information on all of us that we consider private.

> Just because some skeezy website shares all my personal information does not make it public information.

I kinda think it does mean exactly that. Just because you don't want something to be public doesn't mean that it isn't public.

Re: Inside the Largest US Voter Data Leak

#253
post #58

Earlier quoted context omitted.

In the United States, the First Amendment protects your right to compile publicly available data in any way you see fit. I have experience working on a political campaign and they ALL have databases such as this.

What is the publically available source to view voting history ? I thought that was protected information.

http://elections.sos.ga.gov/Elections/voterabsenteefile.do

That file will tell me when you voted, if it is a primary which party ballot you pulled, and if you voted in person, absentee, or early in person.

Re: Inside the Largest US Voter Data Leak

#254

Earlier quoted context omitted.

The US constitution forbids the US government from acting in certain ways, it in no way impedes upon private organizations. Tort law and the like is what holds private organizations accountable. i.e. The fourth amendment does not protect you from a private entity or individual; laws covering trespassing, theft, breaking and entering do. Please don't drag the constitution into an argument it does not have a place in.

I'd like to argue (not for the first time either) that the Constitution is seriously deficient in its failure to enshrine privacy as a personal right. Great as it has been for the last couple of centuries, I think it's obsolete and should be replaced rather than merely amended.

There's no reason that can't be done as an amendment.

Re: Inside the Largest US Voter Data Leak

#255

Earlier quoted context omitted.

I'm not saying this shouldn't have consequences. What I'm saying is this is far too nuanced to just say "lock up the CEO"

How about making positive proposals of your own instead of negating everyone else's? Clearly many people find the existing rules and practices inadequate and propose heavy burdens of responsibility commensurate with the substantial incentives and rewards that accrue to success in business. CEOs are not an oppressed class groaning under the burden of social structures that keep them locked up in the C-suite. Even if t…

I think you're blowing grovegames' original post out of proportion — he asked some pretty reasonable questions.

Re: Inside the Largest US Voter Data Leak

#256
post #129

Earlier quoted context omitted.

What law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.

> What law did they break, exactly? That's not how laws work. Laws can be whatever we write them to be. Losing medical and financial records was once not illegal too.

No, that's not how laws work. The law comes first. Then its application to behavior. If they didn't break any existing laws then there's nothing to do but propose a new law.

Re: Inside the Largest US Voter Data Leak

#257

Earlier quoted context omitted.

No kidding, but I don't want that information out there, and I imagine most people don't. Just because some skeezy website shares all my personal information does not make it public information. It's private to me and I'd rather it remain undistributed, where possible. Overall point being, this US voter data leak is bad. That appears to have released information on all of us that we consider private.

> Just because some skeezy website shares all my personal information does not make it public information. I kinda think it does mean exactly that. Just because you don't want something to be public doesn't mean that it isn't public.

[deleted]

Re: Inside the Largest US Voter Data Leak

#258
post #160
post #129

Earlier quoted context omitted.

> What law did they break, exactly? That's not how laws work. Laws can be whatever we write them to be. Losing medical and financial records was once not illegal too.

Not retroactively, that would be a disaster.

And specifically mentioned in the constitution (twice!) as something the government can't do.

Re: Inside the Largest US Voter Data Leak

#259

I hate to be in the position of defending a leak such as this. But if what they've done is "merely" compiling data that was available from our public profiles, are they obligated to secure that compilation? I'm asking -- I don't know for sure how the data was gathered, it just sounds like it was from scraping public records + public web sites. Also, can someone ask Troy Hunt whether he has or can get access to this d…

It's an interesting question, because there is a comparable in the intelligence community called aggregation. Effectively two pieces of information when separate, might not be classified, but if they are linked with a third or combined they become classified. Add more and it changes the classification further. I wonder if there should be something similar for data aggregation companies. Like what we see with HIPAA.

That's not a bad idea, but the specifics would be pretty hard to nail down.

Re: Inside the Largest US Voter Data Leak

#260

Earlier quoted context omitted.

But what law specifically was broken? Should we have a law that punishes the CEO for data breeches? Is a CEO responsible if his experts recommended the practice? Is the CEO responsible if their staff went around and did this without conscent? That seems rife for abuse. Don't like your CEO, leak some data and have him go to jail.

I think data that has to do with voting records, or suspected voting records, would be very reasonable to be under the purview of being treated as sensitive data that, if breached, should have consequences to a company.

If these are voting records, which are public, it may well be that haven't done anything prohibited even if they intentionally distributed all this data to everyone.

As in, the company didn't want to distribute this data, so it's a breach, and the person who did that would be guilty of stealing the company's confidentional information (i.e. the modelling info) but it seems quite likely that purely (re-)distributing the core data of people's names and addresses doesn't actually violate any US laws at all; US privacy laws (outside of medical data) are very lax compared to e.g. EU.

I could imagine that victims of a future identity theft might have a civil claim against company if/when real losses have occurred, but it's quite possible that if the CEO personally published all this data, filmed all of this, and sent to the prosecutor's office, that no crime (according to current USA privacy laws) could be found there.

Post reply on HN