Live data from Hacker News

The DNC data breach

blog.ngpvan.com

61–70 of 88 posts

Re: The DNC data breach

#61
post #29

Earlier quoted context omitted.

My understanding is that the DNC contracts with VAN to manage the voter files for all fifty states. It's a shared database, with candidates able to build up their own data on top. All the campaigns can see the underlying voter data, but they additions they make are private to the individual campaign. The Sanders campaign staffers realized they were able to see Clinton campaign data they should not have access to. Tha…

"The Sanders people didn't abuse the bug in any significant way" It isn't clear if this is true. "in fact they reported it" VAN has not stated the issue was reported by the Sanders campaign. The claims that the Sanders campaign had reported an earlier issue are refuted in the OP, which states they had reported issues with another vendor's software. It is possible the bug was abused: "The database logs created by NGP…

Hmm, that's much more specific, and seems to go beyond simply establishing that there's a permissions problem and they can see data they shouldn't. I still think cutting off the Sanders campaign from all their data, even after the bug was fixed, is over the top. Perhaps the staffers did act inappropriately or aggressively, but deal with them, and let the campaign continue with its daily business.

Re: The DNC data breach

#62
post #28
post #25

Earlier quoted context omitted.

I think it is pretty unreasonable. As you note, there is no technical reason to deny the Bernie campaign access to their data. The Bernie campaign has fully indicated they want and are willing to cooperate with a third party investigation into the data breach, which would require investigating both campaigns, the DNC, and NPG VAN. Given they are already willing to share everything they know about the incident, there…

There is no technical reason, but that doesn't mean there is no reason. Sanders campaign may have violated rules. The DNC has thrown them in jail without bail in hopes that it gets things resolved quickly. I have no problem with that. If the DNC drags this process out that would be a very different story.

Seems pretty unreasonable to me. It's pretty obvious that the DNC would not have taken access away from Clinton if the situation were reversed.

Re: The DNC data breach

#63
post #59

Earlier quoted context omitted.

Would love to hear more and see if we can't collaborate on this. My email is seth AT amicushq DOT com.

i'll fire an email your way shortly. but yea, a conversation would be great.

I've also wanted to get involved in a open voterfile project like yours for a very long time. I'd love to connect as well. My email's my username at gmail, if you're interested.

Re: The DNC data breach

#64

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

For an alternative perspective: "The database logs created by NGP VAN show that four accounts associated with the Sanders team took advantage of the Wednesday morning breach. Staffers conducted searches that would be especially advantageous to the campaign, including lists of its likeliest supporters in 10 early voting states, including Iowa and New Hampshire. Campaigns rent access to a master file of DNC voter infor…

"Saving the list" entails creating a copy of the list on the VAN servers (technically, creating an SQL query). It does not mean copying any of the data locally where it could be kept.

It demonstrates the ability of the Sanders campaign to access the Clinton data without actually having the ability to use it once the breach was sealed, which, like the previous breach, it would inevitably be.

It's like making a copy of the personnel files left in the mailroom and sticking them in your mailbox. Lets you demonstrate they got left out in case VAN tries to say the breach wasn't serious.

Re: The DNC data breach

#65
Interesting that Hillary would protest unauthorized access of data when she was running that email server that was not authorized, and arguably was holding much more important information than a voter database.

Re: The DNC data breach

#66
post #6

If you believe the Sanders camp, this sounds a lot like the Instagram bug bounty issue [1] that appeared on HN recently. Someone from the Sanders campaign identified a bug and to prove their was an issue grabbed private data that they should have never had the ability to access. That is questionable ethically whether they looked at the data or not. The DNC also can't immediately tell if it is the truth or if the data…

Every time something like this happens, non-technical people don't know how to respond to it. Just look at the DNC Chairwoman's response[0],

"That is just like if you walked into someone's home when the door was unlocked and took things that don't belong to you in order to use them for your own benefit."

Essentially, "gray-hat" hacking isn't always seen as a friendly warning to the vulnerable as much as it might be an attack. One has to wonder, if one could draw a physical parallel between a trespassing and gray-hat style hack, if you did enter someones house, take their gold watch from their bedroom, then walk down to you sitting at your breakfast table and tap you on the shoulder, and then say, "Hey bro, your door was open, and you didn't even secure your jewelry in a safe with a key in case someone did break in. I did this to demonstrate your house's vulnerabilities, you should be grateful! May be even give me a little something for my troubles..."

Of course, the parallel might not be fair, since one can't draw a parallel between a private house and a server with a public facing access point to sensitive material, so the closest proxy I can think of is a bank. Still, a similar parable can be drawn here: You rob a bank without tripping alarms and hand the manager $30000 of stolen money, and claim you did it to warn him/er of issues with the vault's security. In that case, it's plausible to assume s/he might not be that receptive.

I think it's great that penetration testers and people of the like are very willing to do the hard work of finding holes in security systems--and not use it for nefarious purposes, but actually disclose it to companies so that they can holster their systems--but how exactly is the hacked party supposed to take it?

[0]http://www.cnn.com/2015/12/18/politics/bernie-sanders-campai...

Re: The DNC data breach

#67

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

That's interesting, thanks for adding that explanation for us not in the space. What I'm surprised about is that the campaigns are willing to let this data be stored in the cloud on shared systems. I would have expected all proprietary data to be stored locally by each campaign on private in-house servers, probably with periodic data dumps of updates from the data provider.

Why?

Why put forth the expense of obtaining (purchase or rent) hardware and staff to maintain that hardware? Additionally, why put forth the time and expense to write or compose a CRM-like software solution that integrates with voter data, what sounds like a dialer/call center, and "big data" tools (Spark, Hadoop, Tableau, SSIS/SSRS) that probably needs a good 6 months lead time before the candidate even announces a run for office? Also, why would every potential candidate do this every 4 years?

Sounds like a perfect choice for a hosted solution that can be iterated on outside of the election cycle.

Re: The DNC data breach

#68
post #57

Earlier quoted context omitted.

"The Sanders people didn't abuse the bug in any significant way" It isn't clear if this is true. "in fact they reported it" VAN has not stated the issue was reported by the Sanders campaign. The claims that the Sanders campaign had reported an earlier issue are refuted in the OP, which states they had reported issues with another vendor's software. It is possible the bug was abused: "The database logs created by NGP…

A fresh account, commenting on a new, extremely controversial issue should probably disclose affiliations before getting too embroiled in arguing interpretations and facts.

...and if they don't have any affiliations?

Re: The DNC data breach

#69
post #22

A significant problem with 'dynasties' is that you start to get perceived, if not real conflicts of interest above and beyond governance itself. As was pointed out in this reddit thread [1],The CEO of NPG VAN (Stu Trevelyan) is a strong supporter of Hillary Clinton and worked on the 1992 Clinton-Gore "War Room," and then in the Clinton White House [2]. [1] https://www.reddit.com/r/technology/comments/3xbt3w/bernie_s.…

It's irrelevant who the NPGVAN CEO supports: The decision to cut off the Sanders campaign was made by the DNC, not him.

Re: The DNC data breach

#70

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

That's interesting, thanks for adding that explanation for us not in the space. What I'm surprised about is that the campaigns are willing to let this data be stored in the cloud on shared systems. I would have expected all proprietary data to be stored locally by each campaign on private in-house servers, probably with periodic data dumps of updates from the data provider.

How many businesses use Google for email and document storage and run their entire system on AWS?

Private in-house servers are very expensive to set up and maintain. Nearly everyone stores vital personal information on someone else's servers.

Post reply on HN