Live data from Hacker News

The DNC data breach

blog.ngpvan.com

41–50 of 88 posts

Re: The DNC data breach

#41
post #40

Earlier quoted context omitted.

Difficulty level in replicating this dataset from secretary of state rolls?

I've been working on a project like this for some time now - and wresting with whether I want to go the community-based vs. closed source model. The problems listed below are pretty exact: huge data sets, lots of cleaning and normalizing, and the snail mail/cd problem is real. Additionally, I'd note that ~40% of the states [somehow] charge for the data...it takes six digits to get a snapshot of all 50 states - and ce…

> A part of me [now] wants to open source this because of the DNC's actions.

Was my thought exactly. Aggregate, then open.

Re: The DNC data breach

#42
post #29

Earlier quoted context omitted.

Difficulty level in replicating this dataset from secretary of state rolls?

My understanding is that the DNC contracts with VAN to manage the voter files for all fifty states. It's a shared database, with candidates able to build up their own data on top. All the campaigns can see the underlying voter data, but they additions they make are private to the individual campaign. The Sanders campaign staffers realized they were able to see Clinton campaign data they should not have access to. Tha…

"The Sanders people didn't abuse the bug in any significant way"

It isn't clear if this is true.

"in fact they reported it"

VAN has not stated the issue was reported by the Sanders campaign. The claims that the Sanders campaign had reported an earlier issue are refuted in the OP, which states they had reported issues with another vendor's software.

It is possible the bug was abused:

"The database logs created by NGP VAN show that four accounts associated with the Sanders team took advantage of the Wednesday morning breach. Staffers conducted searches that would be especially advantageous to the campaign, including lists of its likeliest supporters in 10 early voting states, including Iowa and New Hampshire. Campaigns rent access to a master file of DNC voter information from the party, and update the files with their own data culled from field work and other investments. After one Sanders account gained access to the Clinton data, the audits show, that user began sharing permissions with other Sanders users. The staffers who secured access to the Clinton data included Uretsky and his deputy, Russell Drapkin. The two other usernames that viewed Clinton information were “talani" and "csmith_bernie," created by Uretsky's account after the breach began. The logs show that the Vermont senator’s team created at least 24 lists during the 40-minute breach, which started at 10:40 a.m., and saved those lists to their personal folders. The Sanders searches included New Hampshire lists related to likely voters, "HFA Turnout 60-100" and "HFA Support 50-100," that were conducted and saved by Uretsky. Drapkin's account searched for and saved lists including less likely Clinton voters, "HFA Support http://www.bloomberg.com/politics/articles/2015-12-18/sander...

Re: The DNC data breach

#43
post #37

Earlier quoted context omitted.

Wow, that interview is incredibly hostile.

How so? It seemed completely fair to me - yes, he pushed the staffer a bit but would there have been a point to the interview if he hadn't? I'm not quite sure if I believe the Sanders campaign story, but that seems independent from the quality of the interview; even if you do, it shouldn't be a bad thing to ask more questions of individuals involved.

Push him on it, sure. After the 5th time of accusing him of stealing the data it felt a bit more like badgering the same point.

I think there are certainly some parallels as mentioned by the parent of the what constitutes a understanding of a breach vs ethics of accessing a system.

Re: The DNC data breach

#44
post #26

Earlier quoted context omitted.

Not technically difficult but incredibly tedious. First, you have to go out and collect it from all 50 Secretaries of State, and in come cases county officials. Some states send you the data on a CD (no joke). You then have to clean the data, which is often not in great shape, and then normalize it. Even then, you only have a snapshot, because the states typically don't keep historical data. What this means is that y…

Except it wasn't just a list of voters. It also included "client scores". That means the Sanders campaign had access to modelling information regarding the Clinton campaign's list. It is pretty valuable knowing how the other campaign values and/or targets specific voters and that is something that obviously can't be found from public info.

aristole and ngpvan "scoring" isn't a game changer. Losing access to their existing work is what matters.

Re: The DNC data breach

#45
post #31
post #29

Earlier quoted context omitted.

My understanding is that the DNC contracts with VAN to manage the voter files for all fifty states. It's a shared database, with candidates able to build up their own data on top. All the campaigns can see the underlying voter data, but they additions they make are private to the individual campaign. The Sanders campaign staffers realized they were able to see Clinton campaign data they should not have access to. Tha…

>The Sanders people didn't abuse the bug in any significant way, in fact they reported it. That is pure conjecture and I'm not even sure the Sanders campaign would agree with you considering they have fired a staffer over this.

My read on this is that very few people involved in the conversation have a very good understanding of technology and gp's speculation matches my own understanding.

Re: The DNC data breach

#46
post #40

Earlier quoted context omitted.

Difficulty level in replicating this dataset from secretary of state rolls?

I've been working on a project like this for some time now - and wresting with whether I want to go the community-based vs. closed source model. The problems listed below are pretty exact: huge data sets, lots of cleaning and normalizing, and the snail mail/cd problem is real. Additionally, I'd note that ~40% of the states [somehow] charge for the data...it takes six digits to get a snapshot of all 50 states - and ce…

If you open it up with addresses/phone/email-addresses, beware that the main users may be commercial marketers (i.e. junk mail senders), not campaigns. Also note that many states license the data with a restriction that it only be used for election purposes.

Re: The DNC data breach

#47

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

Bad faith seems like a pretty nefarious claim. For all we know Hillary's campaign was accessing Sander's data this whole time. The breach went both ways.

Re: The DNC data breach

#48

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

The Sanders campaign did not report the recent issue to the DNC or NGP VAN.

The Sanders campaign had reported a different issue with a different vendor's software in the past.

Re: The DNC data breach

#49
post #37

Earlier quoted context omitted.

Wow, that interview is incredibly hostile.

How so? It seemed completely fair to me - yes, he pushed the staffer a bit but would there have been a point to the interview if he hadn't? I'm not quite sure if I believe the Sanders campaign story, but that seems independent from the quality of the interview; even if you do, it shouldn't be a bad thing to ask more questions of individuals involved.

I'm not quite sure if I believe the Sanders campaign story

Well, if they didn't report, then we'd have more reason to doubt, no? Self-reporting deserves benefit of the doubt.

edit: Never mind my comment, now more clear on the situation.

Re: The DNC data breach

#50

A bug of that nature, completely bypassing all permissions, made it past testing (I presume they test). Whatever happened afterward is noise to me. How the hell do you let that happen? Hardly getting any blame is a neat trick. I wish I had that luxury.

Close enough for government work.

See also: "goto fail;"

Post reply on HN