Live data from Hacker News

Inside the Largest US Voter Data Leak

upguard.com

331–340 of 351 posts

Re: Inside the Largest US Voter Data Leak

#331
post #328

Earlier quoted context omitted.

How is that evidence? Birthday isn't included and it notes, > "Note: Residence address and SSN are confidential except when the requester is authorized by law to receive it."

>The Department of Motor Vehicles (DMV) maintains information on approximately 32 million vehicles/vessels registration (VR), 27 million driver licenses (DL) and/or identification (ID) cards, and over 437,000 occupational licensing (OL) records. >Confidential information is not considered public record. This includes certain DMV personnel matters, physical/mental information, residence address, social security number…

> DOB is listed on ID and not considered confidential information.

Nowhere does it say that. If you think they mean that by omission, I highly doubt it.

Re: Inside the Largest US Voter Data Leak

#332

Earlier quoted context omitted.

So do you consider your daily schedule, gps locations of where you go, to be public information? Nothing about the definition of public or private restrict either to being protected by the government. I can consider some information private without it being protected in the legal sense. That said, I expect that any government entity that released my birthday would be held responsible for a data leak.

> So do you consider your daily schedule, gps locations of where you go, to be public information? Nope. What's your point?

Your words,

> "Just because you don't want something to be public doesn't mean that it isn't public."

In the future, your location data could be tracked, shared/hacked, analyzed to produce more information, and breached just like this RNC dataset.

My point is, something private doesn't become public when a criminal exposes it. It's still private to you.

Re: Inside the Largest US Voter Data Leak

#333

Earlier quoted context omitted.

Please learn how election administration is conducted before continuing to speculate, criticize. An easy way is to see it first hand, by working as a poll judge or inspector. Happy hunting.

Every county is different so some of my statements may not apply everywhere (I live in San Francisco). I've yet to work a poll (next election) but have gotten to know the system here pretty well through the SF elections commission. Our system is very far from perfect. Many counties do not even audit ballots after every election (let alone use only paper ballots). Epollbook software can be all over the place. Voter ve…

Nicely done. We can certainly compare notes.

I still encourage you to work or observe poll sites on election day. Soup to nuts. If you work it, you'll get training, see how the Australian Ballot is supposed to work. It requires many hands, eye balls, proper accounting.

I'm not so worried about identity theft for in person voting. Just doesn't (didn't) seen to happen much on the west coast.

I vigorously opposed closing our poll sites in favor of all mail postal balloting (WA state). With ballot scanners and electronic adjudication of ballots (changing records in the database per "voter intent"), it's roughly equivalent electronic voting machines, with some new vulnerabilities added (eg tabulating ballots as they arrive, effectively a pre-count).

As various members of the election verification network (EVN) determined, auditing elections is infeasible, impractical, and does little or nothing to increase confidence or certainty.

The gold standard for our form of elections, which I continue to advocate, is the Australian Ballot. In place of auditing, use physical chain of custody. (As you likely know, election administration is not banking, where they have double entry bookkeeping.)

---

To truly fix our election integrity woes, we need to do two things.

First, replace our first past the post (FPTP) with a more robust voting system. Like approval voting (for executive races) and proportional representation.

Second, adopt universal voter registration, with automatic updates. Were our government to use any one of the number of existing demographic databases (facebook, seisent, choicepoint, NSA, etc) then we'd know in near real-time who was eligible to vote. And save huge money doing it.

Re: Inside the Largest US Voter Data Leak

#334

Earlier quoted context omitted.

Every county is different so some of my statements may not apply everywhere (I live in San Francisco). I've yet to work a poll (next election) but have gotten to know the system here pretty well through the SF elections commission. Our system is very far from perfect. Many counties do not even audit ballots after every election (let alone use only paper ballots). Epollbook software can be all over the place. Voter ve…

Nicely done. We can certainly compare notes. I still encourage you to work or observe poll sites on election day. Soup to nuts. If you work it, you'll get training, see how the Australian Ballot is supposed to work. It requires many hands, eye balls, proper accounting. I'm not so worried about identity theft for in person voting. Just doesn't (didn't) seen to happen much on the west coast. I vigorously opposed closin…

Certainly agreed re; approval/proportional/similar.

I'm not sure what you mean regarding the EVN. They provide auditing services, don't they? Also recommend auditing paper ballots here:

> Conduct post-election audits before certification of final results

> Without voter-verified paper ballots, effective audits are impossible.

From their top ten list: http://editions.lib.umn.edu/electionacademy/2016/09/08/evns-...

My impression is that SF actually uses a ballot designed for chain of custody accounting, but doesn't use it whatsoever in practice because of the effort involved. I may be wrong on this. But "many hands, eyeballs, proper accounting" is unfortunately not available for our elections in most areas.

Happy to chat more about this - email is in my profile!

Re: Inside the Largest US Voter Data Leak

#335

Earlier quoted context omitted.

Yes, the only reason that anyone cares about their date of birth is that in recent times it has been something that can be used in identity theft. Back in the pre-internet days, nobody cared. People had their SSNs pre-printed on their personal checks too. The solution to all of this data privacy hysteria is to change our approach. The possession of common facts about a person should not be sufficient to masquerade as…

> The solution to all of this data privacy hysteria is to change our approach. The possession of common facts about a person should not be sufficient to masquerade as that person I think the solution is better security. We'll only ever have basic facts to uniquely identify people. Biometrics can be hacked/copied too.

I think the problem could be mostly solved by requiring people who are getting credit to apply somewhere in person. Most credit card banks have branches everywhere (USA). The person has to have their face recorded stored along with credit line. This would have many benefits: legitimate people would think more about how serious getting a credit card is, fraudsters would be less likely to try and get fake credit, and it would be much clearer when the bank gave credit to the wrong person and has to eat the loss. Unlike the past, taking and storing pictures is now a trivial task. This is not likely to happen as the credit companies little liability under the current system.

Re: Inside the Largest US Voter Data Leak

#336

Earlier quoted context omitted.

idbehold can't post his or her name and birthday without revealing he or she is the owner of the idbehold hacker news account. Which is more information than name+birthday, it's name+birthday+hacked news posting history. http://www.dc.state.fl.us/activeinmates/detail.asp?Bookmark=... This is a random guy. His named ERNEST BELL JR and his birthdate is 10/05/1959.

> dbehold can't post his or her name and birthday.. Not sure why you're replying for someone else.. > This is a random guy. His named ERNEST BELL JR and his birthdate is 10/05/1959. Inmates obviously lose some rights when convicted. Data security is minor compared to losing the freedom of movement. Also doesn't surprise me that Florida would make all information on its inmates public.

Plot twist: creepydata is my alternate account and I am Ernest Bell Jr. born 10/05/1959.

Re: Inside the Largest US Voter Data Leak

#337

Earlier quoted context omitted.

It's not the only thing I'd like to change. Besides which, there is already a movement in progress to bring about another article V convention and I'm guessing the goal of the proponents is drastic rather than minimal alteration. Here's a recent summary article on developments: https://www.washingtonpost.com/opinions/were-surprisingly-cl...

The problem is everyone wants different drastic changes.

Obviously. This is going to lead to a bitter conflict in the not-too-distant future, unfortunately.

Re: Inside the Largest US Voter Data Leak

#338

Earlier quoted context omitted.

Of course they're reasonable. But problematic large scale data breaches are not a new problem. The last financial crisis was almost a decade ago, and yet we haven't developed a new culture of organizational responsibility since, despite the massive societal costs. Not to make overly sweeping generalizations, but 'hold on, let's think through all the ramifications here instead of being too hasty' is a great way to mai…

Indeed, lock up a couple CEOs and the others will feel a much stronger need to create better protections. Right?

I don't think it's so simple, but it's clear that most businesses take a reactive rather than a proactive approach to security and many other important considerations. Guillotining a few corporations is likely to have a salutary effect upon the others.

To some extent this is a cultural divide; anglo-Saxon capitalism has an unspoken ethic of 'forge ahead, cross bridges when you come to them' while continental European capitalism is far more accommodating of social considerations and has a 'first do no harm' approach. There are upsides and downsides to both approaches - and of course these are very shallow and incomplete characterizations of complex economic and cultural factors, which I have no intention of trying to defend if someone complains about them.

Re: Inside the Largest US Voter Data Leak

#339
post #328

Earlier quoted context omitted.

>The Department of Motor Vehicles (DMV) maintains information on approximately 32 million vehicles/vessels registration (VR), 27 million driver licenses (DL) and/or identification (ID) cards, and over 437,000 occupational licensing (OL) records. >Confidential information is not considered public record. This includes certain DMV personnel matters, physical/mental information, residence address, social security number…

> DOB is listed on ID and not considered confidential information. Nowhere does it say that. If you think they mean that by omission, I highly doubt it.

Considering it's listed as public record in the first place, I doubt it. I was just directly attacking your claim.

Re: Inside the Largest US Voter Data Leak

#340
post #339

Earlier quoted context omitted.

> DOB is listed on ID and not considered confidential information. Nowhere does it say that. If you think they mean that by omission, I highly doubt it.

Considering it's listed as public record in the first place, I doubt it. I was just directly attacking your claim.

Birthday is not public record, and there is no evidence that it is. That's the point. There's no government entity that will give you a list of people's names and dates of birth.

You cited California DMV which does not give up that information. They won't even give you someone's address unless you're legally entitled, like the police.

Post reply on HN