Live data from Hacker News

An Electronic Voting Firm Exposes 1.8M Chicagoans

upguard.com

61–70 of 76 posts

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#62

Earlier quoted context omitted.

"Improper use of this card and/or number by the number holder or any other person is punishable by fine, imprisonment or both." We could start by exacting real consequences for those who abuse SSNs.

Currently it's between 48 months and 27 years (see federal sentencing guidelines) if caught. What sort of real consequences would you like to see? I don't think making the numbers above bigger would make that much of a difference.

Sorry, could you source that?

I just looked around and only found 42 U.S. Code § 408, which offers a maximum penalty of five years (higher for Social Security workers or medical professionals engaged in fraud).

Also, the vast majority of the text concerns misuse of an SSN to defraud of mislead the government, particularly by claiming benefits. (8) does read "discloses, uses, or compels the disclosure of the social security number of any person in violation of the laws of the United States", but at a quick look I only see prosecutions where that was tied to benefit fraud.

I don't think 5 years is an insufficient sentence, and I think the urge to raise sentences as a deterred is usually counterproductive. But I do think there's room for progress here.

Most SSN abuse as identification appears to be prosecuted as simple identity theft, not SSN fraud. Adding the secondary charge specifically for SSN abuse might encourage thieves to rely on other, less permanent information like passwords.

More broadly, I'd rather see the government concede that SSNs have become a standard form of identification, and make the renewal process less heinous. Right now you have to show grievous hardship over an extended period, can't appeal a bad decision, and will still lose your credit history when the new one is issued. That's simply not a reasonable system for a number people are expected to give out so often.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#63
How far fetched would it be for this data to make it's way into Cambridge Analtyica-type targeting for future election advertising?

Putting on my tinfoil hat for a moment, I have this nagging feeling in my guy that these issues are a little too coincidental.

So how can we make sure all this data isn't used to tamper with voter rolls or uploaded to FB, etc. to create Custom Audiences based on voting history and district?

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#64

How far fetched would it be for this data to make it's way into Cambridge Analtyica-type targeting for future election advertising? Putting on my tinfoil hat for a moment, I have this nagging feeling in my guy that these issues are a little too coincidental. So how can we make sure all this data isn't used to tamper with voter rolls or uploaded to FB, etc. to create Custom Audiences based on voting history and distri…

AFAIK, the latter use-case is currently done all the time. Much of the data can be obtained legally, and is public data. Political campaigns are most definitely using all the data they have on you, including public data/legally-obtainable information such as voter turnout history/registration/party affiliation, street address, etc. to do targeting advertising already.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#65

How far fetched would it be for this data to make it's way into Cambridge Analtyica-type targeting for future election advertising? Putting on my tinfoil hat for a moment, I have this nagging feeling in my guy that these issues are a little too coincidental. So how can we make sure all this data isn't used to tamper with voter rolls or uploaded to FB, etc. to create Custom Audiences based on voting history and distri…

I can tell you that campaigns have much of this information already, often provided directly by the state as public information. The idea that campaigns don't already "create Custom Audiences based on voting history and district" is laughable at best. Communications are often targeted in exactly this way.

Here's Florida's relevant information:

http://dos.myflorida.com/elections/for-voters/voter-registra...

"Voter registration information is public record in Florida with a few exceptions. Information such as your social security number, driver’s license number, and the source of your voter registration application cannot be released or disclosed to the public under any circumstances. Your signature can be viewed, but not copied. Other information such as your name, address, date of birth, party affiliation, and when you voted is public information."

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#66

Earlier quoted context omitted.

Considering this was Chris Vickery, my money is on it being an unsecured Mongo instance on AWS. He's spent the last 2+ years consistently probing for Mongo instances (mostly via Shodan) and then ransoming the owners if he can find them.

This is a false and defamatory. I (Chris Vickery) have never ransomed any data. I have protected the private data of hundreds of millions. Post some evidence or retract your comment.

I never said "you" (assuming it's really you, new account and all) ransomed the "data" specifically, but I do know of two instances where you threatened companies to go to their customers and/or the FTC unless they met your specific demands.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#67
Slightly off-topic, but a great video on why Electronic Voting could be a bad idea: https://www.youtube.com/watch?v=w3_0x6oaDmI

I've wondered before why the UK doesn't have e-voting, and after watching it is sort of seems obvious. With traditional voting, it can easily be changed on a small scale, but is very hard to do in a meaningful way. Whilst with e-voting, its almost just as much effort to change on a small scale as a bigger scale, with much fewer people being involved.

I particularly like the idea that the reason we use pencils is as a protection against somebody replacing pens with ones with invisible ink. Not sure if this is true though.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#68
post #34

Earlier quoted context omitted.

Last four of social is so abused it shouldn't count, and date of birth is in nearly every company's loyalty database. That leaves drivers license and state ID number as the leaked data. I'm honestly not sure how important or secure those are.

Illinois is one of the states where driver's license numbers are computed from all the other information: http://www.highprogrammer.com/alan/numbers/dl_us_shared.html

wow. I had no idea about this, but it correctly calculated my DL number.

Re: An Electronic Voting Firm Exposes 1.8M Chicagoans

#69

How far fetched would it be for this data to make it's way into Cambridge Analtyica-type targeting for future election advertising? Putting on my tinfoil hat for a moment, I have this nagging feeling in my guy that these issues are a little too coincidental. So how can we make sure all this data isn't used to tamper with voter rolls or uploaded to FB, etc. to create Custom Audiences based on voting history and distri…

I can tell you that campaigns have much of this information already, often provided directly by the state as public information. The idea that campaigns don't already "create Custom Audiences based on voting history and district" is laughable at best. Communications are often targeted in exactly this way. Here's Florida's relevant information: http://dos.myflorida.com/elections/for-voters/voter-registra... "Voter reg…

Most of this info is public, but not who you voted for, or your email address.
Post reply on HN