Live data from Hacker News

Millions of UK voters’ data accessible in cyber-attack

theguardian.com

21–30 of 41 posts

Re: Millions of UK voters’ data accessible in cyber-attack

#21
Thus providing an example of why we should stick with our pencil and paper, manually counted voting system, and not computerise it.

Most of the info lost is already publicly available (if one is willing to visit libraries in each electoral ward), so could be collated. Despite that, the manual process of the polls means that it is very difficult to corrupt, and even more so to corrupt without being detected.

In a completely electronic system, it would be so much easier to cheat, and get away with it. It would also be difficult to convince folks that the systems are robust.

In that sense Estonia is 'brave'.

Re: Millions of UK voters’ data accessible in cyber-attack

#22
post #21

Thus providing an example of why we should stick with our pencil and paper, manually counted voting system, and not computerise it. Most of the info lost is already publicly available (if one is willing to visit libraries in each electoral ward), so could be collated. Despite that, the manual process of the polls means that it is very difficult to corrupt, and even more so to corrupt without being detected. In a comp…

I believe the word is “courageous”, minister.

That’s the beauty of turning up and putting an x on a piece of paper. You can of course slip in the occasional fraudulent vote (pretend to be someone who isn’t going to vote). You can register a false person in the address. It’s quite easy to swing dozens of votes across the country, with an increasing risk of being caught

But the effort it takes would be better spent getting the vote out for your candidate. You can pretend to be your neighbour once or twice, but if you turn up at the voting station several times you’re going to be noticed.

Better to offer a lift to your identified voters to make sure they legitimately vote for you even though it’s raining.

Re: Millions of UK voters’ data accessible in cyber-attack

#23
post #2

While the data contained in the electoral registers is limited, and much of it is already in the public domain What is not generally in the public domain is the National Insurance number, mandatory on electoral registration since 2015, very useful for impersonation purposes. I wonder if they got those?

I tried to take myself off it using the webpage, I couldnt remove myself only change my name. Dont see the point of being on it, I wont be voting ever again!

Leave the country for however long it takes to lose the vote, then upon returning simply forget to register?

Ireland is close, and would probably suffice.

I've a vague memory of it being 7 years, but on checking it seems to be 15.

Re: Millions of UK voters’ data accessible in cyber-attack

#24
post #18

Earlier quoted context omitted.

Nah, they would just pay a fine and keep on doing business. At least in the US.

It's the same in EU. Google and Facebook got fined a couple of times and they just don't care.

The phrase you’re looking for is “slap on the wrist”.

A fine is a fee you pay for wrongdoing that makes you think twice next time.

Re: Millions of UK voters’ data accessible in cyber-attack

#25
post #2

While the data contained in the electoral registers is limited, and much of it is already in the public domain What is not generally in the public domain is the National Insurance number, mandatory on electoral registration since 2015, very useful for impersonation purposes. I wonder if they got those?

[deleted]

Re: Millions of UK voters’ data accessible in cyber-attack

#26
To me the report seems very vague as to whether the details were exposed by accident or as the result of an attack. Like, the organisation is trying to make it _sound_ like it was the result of an attack, but they seem to know very little about it so that makes me suspicious.

Re: Millions of UK voters’ data accessible in cyber-attack

#27
From the article:

> McNally [Chief Executive] said: “We regret that sufficient protections were not in place to prevent this cyber-attack. Since identifying it, we have taken significant steps with the support of specialists to improve the security, resilience and reliability of our IT systems.

Finding out nearly 2 years after a breach is really poor considering the potential for phishing given someone full name and address.

The Electoral Commission should really be pressed to give a proper post mortem and not get away with "sufficient protections" and "significant steps".

Re: Millions of UK voters’ data accessible in cyber-attack

#28
post #21

Thus providing an example of why we should stick with our pencil and paper, manually counted voting system, and not computerise it. Most of the info lost is already publicly available (if one is willing to visit libraries in each electoral ward), so could be collated. Despite that, the manual process of the polls means that it is very difficult to corrupt, and even more so to corrupt without being detected. In a comp…

I believe the word is “courageous”, minister. That’s the beauty of turning up and putting an x on a piece of paper. You can of course slip in the occasional fraudulent vote (pretend to be someone who isn’t going to vote). You can register a false person in the address. It’s quite easy to swing dozens of votes across the country, with an increasing risk of being caught But the effort it takes would be better spent get…

> It’s quite easy to swing dozens of votes across the country,

the best liars believe what they say

Re: Millions of UK voters’ data accessible in cyber-attack

#29
post #21

Thus providing an example of why we should stick with our pencil and paper, manually counted voting system, and not computerise it. Most of the info lost is already publicly available (if one is willing to visit libraries in each electoral ward), so could be collated. Despite that, the manual process of the polls means that it is very difficult to corrupt, and even more so to corrupt without being detected. In a comp…

I believe the word is “courageous”, minister. That’s the beauty of turning up and putting an x on a piece of paper. You can of course slip in the occasional fraudulent vote (pretend to be someone who isn’t going to vote). You can register a false person in the address. It’s quite easy to swing dozens of votes across the country, with an increasing risk of being caught But the effort it takes would be better spent get…

Wonderful to see a Yes, Minister reference on HN
Post reply on HN