Live data from Hacker News

Inside the Largest US Voter Data Leak

upguard.com

271–280 of 351 posts

Re: Inside the Largest US Voter Data Leak

#271
post #234

I'm just waiting to hear Trump tell Deep Root Analytics, "You're Fired!" It would be good to see him make this a clear case of responsibility. Also, someone on the RNC side needs to get fired, too. I'm not sure who, but errors this big demand it.

Trump only has "signaling authority" over the entities with whom the RNC contracts; he can't actually force a contract termination, but he can express distrust in an entity and encourage the RNC to terminate a contract. I don't see that happening, for a myriad of reasons.

The people involved with the decision to start working with Deep Root are mostly not with the RNC anymore. Even if they were, that's simply not how the industry works.

Re: Inside the Largest US Voter Data Leak

#272

I think people are missing the big legal liability .... this information has been published to the world, it contains estimates of people's deeply held political beliefs - some of it will be wildly wrong and those people might consider that they have been libeled .... roll on the lawsuits

Libel, in the US, requires the publisher to either known the claim is false ormto publish it with reckless disregard for the truth when it is, in fact, false; I don't think that there is anyway that this could be construed to meet that, no matter what legal theory as to who the liable publisher is you use.

Re: Inside the Largest US Voter Data Leak

#274
post #255

Earlier quoted context omitted.

How about making positive proposals of your own instead of negating everyone else's? Clearly many people find the existing rules and practices inadequate and propose heavy burdens of responsibility commensurate with the substantial incentives and rewards that accrue to success in business. CEOs are not an oppressed class groaning under the burden of social structures that keep them locked up in the C-suite. Even if t…

I think you're blowing grovegames' original post out of proportion — he asked some pretty reasonable questions.

Of course they're reasonable. But problematic large scale data breaches are not a new problem. The last financial crisis was almost a decade ago, and yet we haven't developed a new culture of organizational responsibility since, despite the massive societal costs.

Not to make overly sweeping generalizations, but 'hold on, let's think through all the ramifications here instead of being too hasty' is a great way to maintain the status quo while avoiding any responsibility for it. Who benefits? It sure ain't the general public.

Re: Inside the Largest US Voter Data Leak

#275

Earlier quoted context omitted.

I'd like to argue (not for the first time either) that the Constitution is seriously deficient in its failure to enshrine privacy as a personal right. Great as it has been for the last couple of centuries, I think it's obsolete and should be replaced rather than merely amended.

There's no reason that can't be done as an amendment.

It's not the only thing I'd like to change. Besides which, there is already a movement in progress to bring about another article V convention and I'm guessing the goal of the proponents is drastic rather than minimal alteration. Here's a recent summary article on developments:

https://www.washingtonpost.com/opinions/were-surprisingly-cl...

Re: Inside the Largest US Voter Data Leak

#276
post #269

Earlier quoted context omitted.

There's a pretty compelling argument though, that people aren't good at making long-term assessments of diffuse, but potent, risks, and/or are willing to, or can be coerced into, arbitraging long-term interests with short-term exigency. Gresham's law, availability hueristics, optimism bias, distribution of cognitive skills, various aspects of game theory, and more, strongly suggest this. Examples: global warming, pol…

Yeah, and all those biases apply to people on HN too - You (the proverbial) aren't good at making assessments either. Also, flipping it for arguments sake, how come software companies are never penalized for introducing software bugs? How would you like it if an accountant wanted to send you to jail because you introduced a security bug and their critical data got wiped out and they went out of business? Or should we…

Those are actually questions I'm actively exploring.

Some recent discussion (from myself and others) on this G+ thread:

https://plus.google.com/+YonatanZunger/posts/267XsJzKM5B

I've discussed Gresham's Law dynamics numerous times at my subreddit/blog. See particularly:

https://www.reddit.com/r/dredmorbius/comments/2h63fp/is_gres...

I've been meaning to write up a bit expanding market price dynamics beyond the set of goods that Adam Smith defined: labour, capital, commodities, rents, and (indirectly) interest.

In particular, the question of risk pricing, which is treated almost wholly as a financial question rather than an economic one.

The question of pricing under duress is a key one -- the Backward-'S' bending supply curve is a curious economic anomaly:

https://www.reddit.com/r/dredmorbius/comments/53mcxn/backwar...

Also the behaviour of natural resource stocks under supplier pressure -- the price will fall to the lowest levels possible, and supplied volume will increase, if possible, for a number of highly perverse reasons. The collapse of oil prices following the East Texas oilfield discovery, from ~$1/bbl to first $0.13/bbl, then $0.02/bbl, before wellhead production was siezed at force of arms by the Oklahoma and Texas national guard, and Texas rangers, comes to mind.

https://www.reddit.com/r/dredmorbius/comments/6etqey/oil_is_...

Re: Inside the Largest US Voter Data Leak

#277

Earlier quoted context omitted.

There's no reason that can't be done as an amendment.

It's not the only thing I'd like to change. Besides which, there is already a movement in progress to bring about another article V convention and I'm guessing the goal of the proponents is drastic rather than minimal alteration. Here's a recent summary article on developments: https://www.washingtonpost.com/opinions/were-surprisingly-cl...

The problem is everyone wants different drastic changes.

Re: Inside the Largest US Voter Data Leak

#278
post #235

Earlier quoted context omitted.

Criminalizing something doesn't mean you've "done something about it". It just means you've applied a traditionally flawed approach to fix a systemic problem that could be better handled through education, training and awareness. However, those things are much harder to do than to simply write something into the legal code without the public being any more prepared to deal with the situation.

a systemic problem that could be better handled through education, training and awareness How's that been working out for you? This isn't a new problem. Where are those educational, training, and social awareness resources? What budgets have been allocated to them? What mechanisms put in place to monitor the effectiveness of the deployment? How many more years of theoretical discussions about ideal solutions should w…

>Where are those educational, training, and social awareness resources? What budgets have been allocated to them? What mechanisms put in place to monitor the effectiveness of the deployment?

Just because there is no information about that in the article, doesn't mean they weren't in place.

> If your cautious incrementalist approach is so great (and heaven knows I've spent many years thinking and advocating within that framework) why does the problem keep getting worse?

How do we know its getting worse? I work with a LOT of non-technical people, and they are very good at detecting spam emails, and not clicking on the fake bluescreen popups, etc using just their intuition and general awareness. They DO pay attention whenever articles about viruses and hacking and whatnot hit the front page.

>You don't want to be the person responsible for taking or advocating for a decision that might work out poorly, fine. But reiterating the reasons for your hesitancy achieves nothing.

Would you consider flipping it then? Let's also put software developers who introduce security bugs in jail. Oh, but software is so so complex!! A million different pieces working together, and I didn't write all that other code, so how could __I__ possibly be held responsible?! Well, people to people interactions are complex too, and putting a process in place where every person is supposed to follow a protocol is hard too.

Re: Inside the Largest US Voter Data Leak

#279

Earlier quoted context omitted.

Birthday is almost certainly public. You can get it easily from the DMV or from any of several dozen commercial providers that resell government data: https://www.dmv.org/public-records/ That it's used to confirm identity shows how weak identity-theft protections are at most institutions, not what's public information. (For that matter, mother's maiden name is basically public information as well: you can get it from…

"from the DMV"? no. > DMV.org is a privately owned website that is not owned or operated by any state government agency.

DMV as in Department of Motor Vehicles. Many states have names like that hence "DMV"

Re: Inside the Largest US Voter Data Leak

#280

Earlier quoted context omitted.

Um, no. Your birthday is certainly not private information. Births are openly published in the local paper and online. Not to mention stuff like this - http://www.wfsb.com/story/26835982/website-displaying-voters...

Um, yes. It certainly is. I don't want it released publicly, nor have I consented to release it to any website. If there are websites out there sharing that private information, they're doing it without my consent.

Did you read The link I posted? If you are a registered voter in Connecticut your birthday is public information by law.
Post reply on HN