Live data from Hacker News

An Electronic Voting Firm Exposes 1.8M Chicagoans

upguard.com

31–40 of 76 posts

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#31
post #29

Earlier quoted context omitted.

Last four of social is so abused it shouldn't count, and date of birth is in nearly every company's loyalty database. That leaves drivers license and state ID number as the leaked data. I'm honestly not sure how important or secure those are.

> Last four of social is so abused it shouldn't count Yet it does. Almost every single business/government service in America uses DoB + last 4 SSN to identify you. The two together make fraud trivial.

Exactly. Every leak already has it. Every company already has it. The fact that fraud is trivial is already true, and this leak really adds little to it.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#32
post #7

Isn't this considered public data anyways? Illinois (and I believe every other US state) requires that certain voter data be publicly accessible. To access it in bulk, you'll have to pay a small fee, but anyone can get this. A misconfigured AWS instance is always an issue. I'm not trying to downplay that. Only that this data being released to the public isn't anything new - the public already had access to it. https:…

No. The Chicago Tribune [0] reported on the type of data exposed: > The files included names, addresses, dates of birth, the last four digits of many voters' Social Security numbers, driver's license and state ID numbers for the 1.8 million who are registered to vote in Chicago. [0] http://www.chicagotribune.com/news/local/politics/ct-chicago...

fuck. I live in Chicago.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#33

Isn't this considered public data anyways? Illinois (and I believe every other US state) requires that certain voter data be publicly accessible. To access it in bulk, you'll have to pay a small fee, but anyone can get this. A misconfigured AWS instance is always an issue. I'm not trying to downplay that. Only that this data being released to the public isn't anything new - the public already had access to it. https:…

Considering this was Chris Vickery, my money is on it being an unsecured Mongo instance on AWS. He's spent the last 2+ years consistently probing for Mongo instances (mostly via Shodan) and then ransoming the owners if he can find them.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#34
post #9

Earlier quoted context omitted.

According to Forbes [0]: - Name - Street address - Party affiliation - Elections in which you did (or did not) vote - Phone number - Email address [0] https://www.forbes.com/sites/metabrown/2015/12/28/voter-data...

Last four of social is so abused it shouldn't count, and date of birth is in nearly every company's loyalty database. That leaves drivers license and state ID number as the leaked data. I'm honestly not sure how important or secure those are.

Illinois is one of the states where driver's license numbers are computed from all the other information: http://www.highprogrammer.com/alan/numbers/dl_us_shared.html

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#36

Isn't this considered public data anyways? Illinois (and I believe every other US state) requires that certain voter data be publicly accessible. To access it in bulk, you'll have to pay a small fee, but anyone can get this. A misconfigured AWS instance is always an issue. I'm not trying to downplay that. Only that this data being released to the public isn't anything new - the public already had access to it. https:…

Voter registration data is available for purchase, but only by registered political committees and can't be used for commercial purposes. This also doesn't include a lot of the breached data like partial SS#'s and drivers license #'s. As a Chicagoan I'm not too happy about this breach, and there has been surprisingly little coverage of it locally.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#37
post #2

Source blog post (and free of CNN's obnoxious autoplay video): https://www.upguard.com/breaches/cloud-leak-chicago-voters As soon as I read the headline, I immediately thought "AWS misconfiguration". A few recent massive government-data breaches (by contractors) have fallen into that category: June 2017: http://gizmodo.com/gop-data-firm-accidentally-leaks-personal... May 2017: http://gizmodo.com/top-defense-contracto…

Same with Nice Systems' leak of Verizon customers' data:

https://www.engadget.com/2017/07/12/verizon-partner-exposes-...

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#38
post #27

Earlier quoted context omitted.

Last four of social is so abused it shouldn't count, and date of birth is in nearly every company's loyalty database. That leaves drivers license and state ID number as the leaked data. I'm honestly not sure how important or secure those are.

They are a requirement if you were wanting to fraudulently open a bank account in someone else's name.

Need a whole SSN for that no?

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#39
post #20

Earlier quoted context omitted.

And they're certainly not the only one. Last 4 of SSN is a very common authentication question.

Which is inane. We have to get away from this idea of having "secret" numbers that, if simply discovered, can cause so much damage. That includes credit card numbers, SSN, etc.

what alternative do you have in mind ?

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#40
post #26
post #2

Source blog post (and free of CNN's obnoxious autoplay video): https://www.upguard.com/breaches/cloud-leak-chicago-voters As soon as I read the headline, I immediately thought "AWS misconfiguration". A few recent massive government-data breaches (by contractors) have fallen into that category: June 2017: http://gizmodo.com/gop-data-firm-accidentally-leaks-personal... May 2017: http://gizmodo.com/top-defense-contracto…

Amazon just launched a service to help scan, categorize, and protect data https://aws.amazon.com/macie/

Don't you have to pay for that?
Post reply on HN