Live data from Hacker News

Millions of UK voters’ data accessible in cyber-attack

theguardian.com

11–20 of 41 posts

Re: Millions of UK voters’ data accessible in cyber-attack

#11
post #2

While the data contained in the electoral registers is limited, and much of it is already in the public domain What is not generally in the public domain is the National Insurance number, mandatory on electoral registration since 2015, very useful for impersonation purposes. I wonder if they got those?

While officially they serve a similar purpose, NI numbers aren't used like SSNs are for identification, so the impersonation impact is more limited than an equivalent leak of US SSNs would be.

To prevent identity fraud, keep your National Insurance number safe. Do not share it with anyone who does not need it.

HMG

https://www.gov.uk/national-insurance/your-national-insuranc...

Re: Millions of UK voters’ data accessible in cyber-attack

#13
post #6

Earlier quoted context omitted.

> It is a criminal offence to not register. Afaik that is not correct. It is a criminal offence to refuse to complete the registration form or to give false information. But if you're not asked ro register then no offence is committed.

I stand corrected, they are generally rather persistent in asking though ...

Which is rather amusing, as my partner, a Chinese national, is regularly hounded to register, despite not being eligible to do so (and in fact, would be committing an offense if she tried).

Re: Millions of UK voters’ data accessible in cyber-attack

#14
> These registers include the name and address of anyone in the UK who was registered to vote between 2014 and 2022

So the headline may as well read “ALL UK voter’s data since 2014 leaked”

I’m angry about this. Our technology strategy in this country is completely backwards.

Re: Millions of UK voters’ data accessible in cyber-attack

#15

This is the same government demanding a back door into encryption of messaging devices. If the UK govt operated in the private sector, they would have been fired several times over

Nah, they would just pay a fine and keep on doing business. At least in the US.

Re: Millions of UK voters’ data accessible in cyber-attack

#16
post #11

Earlier quoted context omitted.

While officially they serve a similar purpose, NI numbers aren't used like SSNs are for identification, so the impersonation impact is more limited than an equivalent leak of US SSNs would be.

To prevent identity fraud, keep your National Insurance number safe. Do not share it with anyone who does not need it. HMG https://www.gov.uk/national-insurance/your-national-insuranc...

Clearly fraudsters need it.

Typical late stage Tory victim blaming coms.

Re: Millions of UK voters’ data accessible in cyber-attack

#17
post #2

While the data contained in the electoral registers is limited, and much of it is already in the public domain What is not generally in the public domain is the National Insurance number, mandatory on electoral registration since 2015, very useful for impersonation purposes. I wonder if they got those?

While officially they serve a similar purpose, NI numbers aren't used like SSNs are for identification, so the impersonation impact is more limited than an equivalent leak of US SSNs would be.

NI is more about the right to work.

That said I'm sure it'll be a factor in credit card applications.

Re: Millions of UK voters’ data accessible in cyber-attack

#18

This is the same government demanding a back door into encryption of messaging devices. If the UK govt operated in the private sector, they would have been fired several times over

Nah, they would just pay a fine and keep on doing business. At least in the US.

It's the same in EU. Google and Facebook got fined a couple of times and they just don't care.

Re: Millions of UK voters’ data accessible in cyber-attack

#19

Earlier quoted context omitted.

> It is a criminal offence to not register. Afaik that is not correct. It is a criminal offence to refuse to complete the registration form or to give false information. But if you're not asked ro register then no offence is committed.

Apparently you must register to vote. You can opt out of the extended register. [1] Not being on the electoral register is a huge pain too. It affects your credit quite significantly. [1] https://www.manchester.gov.uk/info/500328/voting/6470/regist...

I'm registered to vote, but because I don't live at my last UK address since leaving the country over 10 years ago, I can confirm: it's a factor in a bad credit rating.

Re: Millions of UK voters’ data accessible in cyber-attack

#20
post #2

While the data contained in the electoral registers is limited, and much of it is already in the public domain What is not generally in the public domain is the National Insurance number, mandatory on electoral registration since 2015, very useful for impersonation purposes. I wonder if they got those?

This is another good case for security-by-minimisation. I struggle to see why NI numbers were required on the electoral register — particularly when democracy in the UK had been functioning for over a century without them. The best way to ensure valuable data doesn’t leak into the public realm is to minimise the amount of unnecessary data collection.

Best way here would have been to only collect the information at the constituency level. Why is there even a need for a national database? If you're concerned about fraud then periodically cross-check hashed NI numbers or something like that.
Post reply on HN