Live data from Hacker News

The DNC data breach

blog.ngpvan.com

51–60 of 88 posts

Re: The DNC data breach

#51
post #46
post #40

Earlier quoted context omitted.

I've been working on a project like this for some time now - and wresting with whether I want to go the community-based vs. closed source model. The problems listed below are pretty exact: huge data sets, lots of cleaning and normalizing, and the snail mail/cd problem is real. Additionally, I'd note that ~40% of the states [somehow] charge for the data...it takes six digits to get a snapshot of all 50 states - and ce…

If you open it up with addresses/phone/email-addresses, beware that the main users may be commercial marketers (i.e. junk mail senders), not campaigns. Also note that many states license the data with a restriction that it only be used for election purposes.

if I define open as, "your campaign would have to register and be verified"...then it abides by the state/fed rules for these datasets. I can't just throw the data on github.

Re: The DNC data breach

#52

I'm sure Sanders was just polling well, and this is the perfect opportunity for the DNC to pull the rug out under his campaign. NGP-VAN is crap hack software anyways.

When I need a reminder that I'm not like most people, I just need to look at how something in human psychology means that being the president / prime minister / dictator's son/brother/wife means that you get your turn as well.

Maybe it really is nothing more than "Oh, I've heard of pepsi, so I'd better buy a fucking ton of blue-labeled sugar water every week of my life", but there might be something else evolutionary about power and loyalty and reward.

Re: The DNC data breach

#53
post #29

Earlier quoted context omitted.

My understanding is that the DNC contracts with VAN to manage the voter files for all fifty states. It's a shared database, with candidates able to build up their own data on top. All the campaigns can see the underlying voter data, but they additions they make are private to the individual campaign. The Sanders campaign staffers realized they were able to see Clinton campaign data they should not have access to. Tha…

"The Sanders people didn't abuse the bug in any significant way" It isn't clear if this is true. "in fact they reported it" VAN has not stated the issue was reported by the Sanders campaign. The claims that the Sanders campaign had reported an earlier issue are refuted in the OP, which states they had reported issues with another vendor's software. It is possible the bug was abused: "The database logs created by NGP…

To clarify:

The Sanders campaign had in October reported an unrelated software issue in a non-VAN system.

They did not report THIS issue to the DNC or NGP VAN, but claim they were gathering information about the breach for the purposes of reporting. Based on my reading of the OP, the breach was discovered by NGP VAN employees.

Re: The DNC data breach

#54
post #47

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

Bad faith seems like a pretty nefarious claim. For all we know Hillary's campaign was accessing Sander's data this whole time. The breach went both ways.

Well the press release states: "Our team removed access to the affected data, and determined that only one campaign took actions that could possibly have led to it retaining data to which it should not have had access."

Re: The DNC data breach

#55
post #40

Earlier quoted context omitted.

Difficulty level in replicating this dataset from secretary of state rolls?

I've been working on a project like this for some time now - and wresting with whether I want to go the community-based vs. closed source model. The problems listed below are pretty exact: huge data sets, lots of cleaning and normalizing, and the snail mail/cd problem is real. Additionally, I'd note that ~40% of the states [somehow] charge for the data...it takes six digits to get a snapshot of all 50 states - and ce…

Would love to hear more and see if we can't collaborate on this. My email is seth AT amicushq DOT com.

Re: The DNC data breach

#56

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

For an alternative perspective:

"The database logs created by NGP VAN show that four accounts associated with the Sanders team took advantage of the Wednesday morning breach. Staffers conducted searches that would be especially advantageous to the campaign, including lists of its likeliest supporters in 10 early voting states, including Iowa and New Hampshire. Campaigns rent access to a master file of DNC voter information from the party, and update the files with their own data culled from field work and other investments. After one Sanders account gained access to the Clinton data, the audits show, that user began sharing permissions with other Sanders users. The staffers who secured access to the Clinton data included Uretsky and his deputy, Russell Drapkin. The two other usernames that viewed Clinton information were “talani" and "csmith_bernie," created by Uretsky's account after the breach began. The logs show that the Vermont senator’s team created at least 24 lists during the 40-minute breach, which started at 10:40 a.m., and saved those lists to their personal folders. The Sanders searches included New Hampshire lists related to likely voters, "HFA Turnout 60-100" and "HFA Support 50-100," that were conducted and saved by Uretsky. Drapkin's account searched for and saved lists including less likely Clinton voters, "HFA Support http://www.bloomberg.com/politics/articles/2015-12-18/sander...

Re: The DNC data breach

#57
post #29

Earlier quoted context omitted.

My understanding is that the DNC contracts with VAN to manage the voter files for all fifty states. It's a shared database, with candidates able to build up their own data on top. All the campaigns can see the underlying voter data, but they additions they make are private to the individual campaign. The Sanders campaign staffers realized they were able to see Clinton campaign data they should not have access to. Tha…

"The Sanders people didn't abuse the bug in any significant way" It isn't clear if this is true. "in fact they reported it" VAN has not stated the issue was reported by the Sanders campaign. The claims that the Sanders campaign had reported an earlier issue are refuted in the OP, which states they had reported issues with another vendor's software. It is possible the bug was abused: "The database logs created by NGP…

A fresh account, commenting on a new, extremely controversial issue should probably disclose affiliations before getting too embroiled in arguing interpretations and facts.

Re: The DNC data breach

#58
post #10

Earlier quoted context omitted.

Right? Bernie just got some endorsements (which he has been sorely lacking), and all of a sudden this company (the CEO of which is a public Clinton supporter) has a problem that affects the Sanders campaign but not the Clinton campaign, on word from the company that there was a bad actor in the Sanders campaign but not the Clinton campaign. Sure it's possible that the Sanders campaign did exploit this and the Clinton…

Having actually used NGP-VAN, I think it's far more likely that this was a bug, not a conspiracy. The VAN is a real clunker in many ways, so it's not surprising that a bug like this would appear; and public exposure of a conspiracy to sabotage Sanders would be so catastrophic to the Clinton campaign that I think it's highly unlikely that NGP-VAN would do it.

agreed. many of the systems running our campaigns are "clunkers".

Re: The DNC data breach

#59
post #40

Earlier quoted context omitted.

I've been working on a project like this for some time now - and wresting with whether I want to go the community-based vs. closed source model. The problems listed below are pretty exact: huge data sets, lots of cleaning and normalizing, and the snail mail/cd problem is real. Additionally, I'd note that ~40% of the states [somehow] charge for the data...it takes six digits to get a snapshot of all 50 states - and ce…

Would love to hear more and see if we can't collaborate on this. My email is seth AT amicushq DOT com.

i'll fire an email your way shortly. but yea, a conversation would be great.

Re: The DNC data breach

#60
post #28
post #25

Earlier quoted context omitted.

I think it is pretty unreasonable. As you note, there is no technical reason to deny the Bernie campaign access to their data. The Bernie campaign has fully indicated they want and are willing to cooperate with a third party investigation into the data breach, which would require investigating both campaigns, the DNC, and NPG VAN. Given they are already willing to share everything they know about the incident, there…

There is no technical reason, but that doesn't mean there is no reason. Sanders campaign may have violated rules. The DNC has thrown them in jail without bail in hopes that it gets things resolved quickly. I have no problem with that. If the DNC drags this process out that would be a very different story.

There is a reason we don't normally throw people into jail without bail...
Post reply on HN