Live data from Hacker News

The DNC data breach

blog.ngpvan.com

71–80 of 88 posts

Re: The DNC data breach

#71
post #59

Earlier quoted context omitted.

Would love to hear more and see if we can't collaborate on this. My email is seth AT amicushq DOT com.

i'll fire an email your way shortly. but yea, a conversation would be great.

Not to pollute the thread, but I'm also really interested in this, I've worked at both the Clinton campaign and NGP VAN and it seems like a very worthwhile pursuit. If you're adding people, my email is in my profile.

Re: The DNC data breach

#72
Are there any grey-hat things that can be done keep campaign-parity in the mean time? Strictly hypothetically, I'd throw all of my technical skills at this problem if there was a clear path to a solution.

Re: The DNC data breach

#73
post #18

Earlier quoted context omitted.

Here's an interview the Sanders campaign staffer who was fired gave explaining just what you describe: http://www.msnbc.com/thomas-roberts/watch/fired-sanders-camp...

Wow, that interview is incredibly hostile.

He is trying to pretend that they accessed the data for noble reasons and not taking advantage of the breach while it lasted when that obviously seems to be the case. They did something wrong but the problem here is that the DNC's response is heavy handed and unfair.

If this guy wants to help the campaign (which he obviously still do) he should stop giving more interviews.

Re: The DNC data breach

#74
post #51
post #46

Earlier quoted context omitted.

If you open it up with addresses/phone/email-addresses, beware that the main users may be commercial marketers (i.e. junk mail senders), not campaigns. Also note that many states license the data with a restriction that it only be used for election purposes.

if I define open as, "your campaign would have to register and be verified"...then it abides by the state/fed rules for these datasets. I can't just throw the data on github.

Can you comment on this a bit?

It's not obvious to me how open access to this data would be intrinsicly bad, but I suppose that relies on the assumption that it's equally available to all parties (which may not (definitely not?)) be the case.

any pointers to the statuatory/regulatory guidelines would be appreciated.

Re: The DNC data breach

#75
post #14
post #10

Earlier quoted context omitted.

Having actually used NGP-VAN, I think it's far more likely that this was a bug, not a conspiracy. The VAN is a real clunker in many ways, so it's not surprising that a bug like this would appear; and public exposure of a conspiracy to sabotage Sanders would be so catastrophic to the Clinton campaign that I think it's highly unlikely that NGP-VAN would do it.

As someone who has had... shall we say, intimate interactions with NGP-VAN's code base, the idea being floated by some Sanders supporters that this is a DNC conspiracy and not a bug is hilarious.

Who would be better positioned to stage a trap coalesced with a bug for the Sanders campaign than individuals within a company with a track record for bugs?

It sounds like the data director of the Sanders campaign was the only member who could initially access Clinton data--would this not go both ways?

If such extreme bugs were the norm, why would the DNC continue to use such a vendor? The entire platform the DNC depends upon is hindered each time such a bug happens, so it makes no sense from an organizational perspective.

Conspiracy is a strong word, but it seems a bit naive to look at this as either "is a bug" or "isn't a bug".

Re: The DNC data breach

#76
post #51

Earlier quoted context omitted.

if I define open as, "your campaign would have to register and be verified"...then it abides by the state/fed rules for these datasets. I can't just throw the data on github.

Can you comment on this a bit? It's not obvious to me how open access to this data would be intrinsicly bad, but I suppose that relies on the assumption that it's equally available to all parties (which may not (definitely not?)) be the case. any pointers to the statuatory/regulatory guidelines would be appreciated.

Here's a good list:

http://nationbuilder.com/voterdata

Re: The DNC data breach

#77

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

Difficulty level in replicating this dataset from secretary of state rolls?

Very. Expensive, and many states have legal restrictions on what you can use it for and who can get it.

Nationbuilder, a sorta-competitor to NGP, has put together a national voter file and it's reasonably priced. https://elections.nationbuilder.com/about/faq

The DNC/NGP voter file, however, is significantly enhanced - for one, it's got a lot of phone numbers, which most states don't include in their lists. There's a lot of other survey and consumer data associated.

For a national voter file that's good enough to use for say a City Council race anywhere in the country, where all you want to know is "who is likely to vote in this non-presidential election", it's doable but very expensive. For anything serious, it's pretty much outside of capabilities of anyone but the parties and some of the very big SuperPACs/very big orgs.

Re: The DNC data breach

#78

For those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in…

For an alternative perspective: "The database logs created by NGP VAN show that four accounts associated with the Sanders team took advantage of the Wednesday morning breach. Staffers conducted searches that would be especially advantageous to the campaign, including lists of its likeliest supporters in 10 early voting states, including Iowa and New Hampshire. Campaigns rent access to a master file of DNC voter infor…

"Despite audit logs, Weaver said at the news conference that NGP VAN has told the campaign that no Clinton data was printed or downloaded."

The phrasing here strikes me as somewhat vague. Are they implying that Weaver's statements are in conflict with the audit logs, or are they (somewhat ineffectively) implying that "saving lists" merely equates to bookmarking a certain query?

NGP stated:

"So for voters that a user already had access to, that user was able to search by and view (but not export or save or act on) some attributes that came from another campaign."

What exactly do they mean by "view", let alone "act on"? If someone was truly dedicated to extracting data through their browser, are the terms truly mutually exclusive?

Re: The DNC data breach

#79
Josh Uretsky and Russell Drapkin copied voter lists [1]. Did they intend to keep and misuse the lists that they copied? If they knew they were being audited, it's unlikely they intended to misused the data and get away with it. Uretsky has experience as a programmer [2]. He might be telling the truth and was only documenting and determining the severity of the issue. On the other hand 20 voter lists is a bit extensive for a proof of concept.

[1] - http://www.bloomberg.com/politics/articles/2015-12-18/sander...

[2] - http://heavy.com/news/2015/12/josh-uretsky-bernie-sanders-ca...

edit: added source

Re: The DNC data breach

#80
post #6

If you believe the Sanders camp, this sounds a lot like the Instagram bug bounty issue [1] that appeared on HN recently. Someone from the Sanders campaign identified a bug and to prove their was an issue grabbed private data that they should have never had the ability to access. That is questionable ethically whether they looked at the data or not. The DNC also can't immediately tell if it is the truth or if the data…

Every time something like this happens, non-technical people don't know how to respond to it. Just look at the DNC Chairwoman's response[0], "That is just like if you walked into someone's home when the door was unlocked and took things that don't belong to you in order to use them for your own benefit." Essentially, "gray-hat" hacking isn't always seen as a friendly warning to the vulnerable as much as it might be a…

can't edit, but my "you's" got switched up in my story about breaking into someone's house.
Post reply on HN