191M US Voters’ Personal Info Exposed by Misconfigured Database
databreaches.net
databreaches.net
There have actually been some interesting social science experiments to shame people into voting more often by using their turnout record http://www.usatoday.com/story/news/politics/2014/10/30/inter...
Note in particular, "Placing on the internet so anyone can find out where anyone else lives" is not exactly an approved use in locations like California and Hawaii. Which is why there are going to be consequences once the database owner is tracked down.
What's your thinking behind that?
I think law enforcement agencies should be able to wiretap suspects of crimes to listen to their phone calls, subject to judicial oversight. I do not think they should have unrestricted, unlogged access to a database of recordings of every phone call ever made by every citizen.
Same line of thinking IMO. There's a difference between an individual identifying themselves and signing a usage agreement before requesting public records from an individual county, versus dumping online a public database that lets you query the personal details of 191 million people. The same data is available, but the extra hoops you have to jump through change the potential for abuse.
With respect to the law enforcement example, the access there is to non-public data. That seems like an essential difference to me, but perhaps you're citing this situation in preparation for your third paragraph.
In your third paragraph, I think I'm seeing a dilemma. I don't understand how jumping through the hoops changes the potential for abuse.
Let's say 30 people go to the county records office and get the data. They all sign an agreement of some kind. 30 people now have (presumably) exactly the same data set. One of the 30 violates the agreement and publishes it anonymously on the Internet. The data is now "in the wild" and any potential for abuse that it held is now up for grabs.
I recognize that I may be missing something, but if I am, I'm not able to see it. I might need more coffee. ;-)
With respect to the public data though, this is an issue which we've been wrestling with (and largely punting on) since various public records became readily available in electronic form. The fact is that, in the US, there's quite a bit of public information available about individuals. Much of this information (think home sales, past addresses, any court records) is public for historically sound reasons. However, there is a huge difference between scouring dusty town, county, and state records at considerable cost of time and money and making a few quick queries on the Internet, possibly paying a nominal fee if you really want to go deep.
But, to your point, we effectively implement privacy through obscurity/bureaucracy to shield ostensibly public information that we don't feel comfortable about anyone having access to it. But it probably works about as well as security through obscurity.
HAVA improved the situation, but 50+ separate systems leads to data quality issues. Which then trigger alarms. False positives are "voter fraud". False negatives are "caging" and "purging".
Made worse by the requirement that only eligible (active & inactive) voters appear in each database. Versus a master list of everyone with an eligibility flag, backed by an audit log.
The optimal solution is automatic, universal voter registration, maintained by each jurisdiction and hosted by the feds (perhaps http://eac.gov). Which is exactly what both parties are doing in-house. Then we can put a stop to the recurring food fight every election cycle.
Thanks for listening. My work on this issue has made me grumpy.
I've been working on legislation information systems, as best able, to help future persons like myself be more effective. (Tools I wish we had when I got started.)
Thanks for asking. From your profile's links, it looks like we'd be allies.
Doesn't look like who you voted for is disclosed -- I'm not sure that this data even exists. I suspect in most states, you go in to vote, your name is crossed off a list, you're assigned a hash, and that hash votes, and there's no database of "John Smith voted for Jane Doe."
I don't know about US, but I once knew a programmer who worked on russian voting system.
I honestly don't think that he was qualified enough to know what "hash" is.
In my observer experience, the higher the official, the less interested he was in falsifications; it was the lowest ranks that wanted to prove that their areas are loyal with any means necessary, while the higher-ups wanted to avoid the embarrassment and didn't worry much about the outcome, since population's loyalty is pretty sincere, thanks to the propaganda machine.
Or is that we believe the population is loyal, because of the propaganda machine's affect on us?
"Evil government oppressing discontent population" is a nice trope, but the reality is more grim.
I don't think I will in this case. How do you know? I have yet to see any reliable data supporting it, and many dictators have claimed overwhelming public support with polls and elections to match.
I'm not sure how anyone could reliably poll Russian citizens. Who would dare say something negative about Putin? How do you know you can trust the interviewer? How could you rely on anyone keeping your opinion secret from the intelligence services? How much risk are you willing to take for something as trivial as answering a survey? What polling service would dare publish a negative result for Putin?
You know why I despise the western anti-establishment activists who are afraid of US and Europe turning into totalitarian regimes? Because they have a very naive image of what totalitarian state is and how it starts. Today's Russia didn't start in former KGB or in government offices; it started in Stalin-loving hutjob papers. It started with ideology, and that ideology filled a vacuum that the cleptocratic elites desperately needed.
If you fear for your country's future, know that a self-serving capitalist asshole is not nearly as dangerous as a sincere actuvist who really wants to make the world a better place.
Where is this data sold?
Among many others.
The data itself is mostly free public records, but it's worth paying to get all 50 states in one place
There are companies that add a bit of value by collecting the data and spiffing up the formatting a bit, then burning it to a CD/DVD for you. When I ran for city council of Redmond, WA, I went 15 minutes down the road to a place in Bellevue and just picked up the CD. It gives name, address, and whether or not one voted in each of the last X elections. SELECT * FROM voters WHERE "voter voted in 50% of elections" to get bang for the walking-door-to-door buck, throw that into MapPoint (tells you how long ago it was), and print out the walking sheets.
We then implemented electronic voting machines with voter-verifiable paper tapes that allow to you see your votes and could, if absolutely necessary, be used to do a manual recount using paper records. These tapes were on the same type of paper used for other receipts, but were fed from one reel to another and stored in a locked box on the machine.
During the first election these machines were used, I went with another poll watcher to the precinct where a politician who was so set on how secure and wonderful the machines were and kept my own log - which of the five machines people used as they signed in.
So, at the end, I had my log (line 73 to machine 5, line 74 to machine 1, etc), the nice sequential sign-in sheet that matched easily to the easy-to-read printed poll book, and the paper tapes (required to be open to inspection).
We were able to match votes to people for all but seven of the votes (the last seven, actually, and we had a good idea who matched with which). The politician flipped his shit when I was able to demonstrably prove he voted for someone other than his party's candidate for governor.
The poll procedures were changed the next election cycle. The paper tapes were not allowed to be produced and the poll workers used a tick mark instead of a number in the poll books. The machines remain in use.
So you are the person that killed democracy? Given that voting is a "trade secret" and the code will never be inspected do you think the abolishment of a paper trail is a good idea?
Umm... you just speculated.
My head hurts.
If there's any legal or ethical problem with doing this using the Ohio Voter Registration files, I would like to know. I recently made an interface to it[1] to use when gathering ballot access petition signatures for Bernie Sanders in Ohio[2]. It's freely downloadable data, though[3], and the Board of Elections officials I shared it with weren't aghast at the idea.
[1] http://gobernie.net/ Source code: https://github.com/coventry/voter_lookup
[2] https://www.facebook.com/groups/929112173802716/
[3] http://www2.sos.state.oh.us/pls/voter/f?p=111:1:0::NO:RP:P1_...
There's been a lot of talk about these recently[1] that I'm surprised this didn't come up sooner.
It may not be Nation Builder per se but it could be one of their many integration points maintained by third parties:
I'm not sure how to search by database size though. But I'd estimate that 190 million voter records, at 1 kb each, would be a little under 2 GB if my math is right.
I'm not familiar with MongoDB and don't have the time to learn right now. But do check it out!
Confirmed: db.blackhole_nj.find({$and:[{"fname": "Christopher"},{"mname": "J"},{"lname": "Christie"}]})
The governor's DOB in the results matches what's in Wikipedia.
The site also seems to be having a rough time with the traffic. Here is the cached page: http://webcache.googleusercontent.com/search?q=cache:BXSmNL6...
A lot of comments here saying "so what it's public record." But not a lot of asking if it should be. Something being the status quo doesn't make it right.
Scanning the US IP ranges for Linux hosts (as mentioned in the article) with port 27017 open with ZMap and then running a script that connects to the open database and saves the size of the database in a file would be a good place to start for those who want to find it.
https://www.shodan.io/search?query=port%3A27017+country%3AUS...
or even https://scans.io/ which uses something like https://zmap.io/
Not saying you're wrong, wondering where the line is if there is one.
More critically, NationBuilder may erroneously be denying accountability.
“Nation Builder is under no obligation to identify customers, and once the data has been obtained, they cannot control what happens to it,”
Specifically look at the statues for MA and CA. Clearly and in writing voter list purchasers are required to get written pre-approval from the two respective states PRIOR to releasing the data. But what if NationBuilder did not sign the affidavit with the state, ie what if NationBuilder got the data from someone in the Democratic or Republican national or state parties?
If either of the two major parties released the data without getting written pre-approval from the state, then they may all be in breach of contract and liable, NationBuilder included.
e.g a Florida company publishing California voter records in Florida can't possibly be committing a crime.
I don't see why FBI would get involved either, since there doesn't seem to be any federal crimes happening here.
Almost makes you think knocking it offline would be worthwhile just so someone will take a look at it.
> As far as I can tell, the only "breach" here is revealing what candidates or parties voters chose
Why put "breach" in double-quotes? That's a very serious privacy concern if voters did not want this information to be public.
I think that this is a very important point. It doesn't matter how important it is to you that my information is public; the seriousness of its exposure depends on how important it is to me. (I am using 'you' and 'me' here not to argue with you specifically—in fact I agree with you!—but rather as generic pronouns.)
I assure you there are already databases of every registered voter in America. You're not allowed to do certain things with some of the data, but its always been available.
That's an interesting and subtle point, to which I don't know how to respond fairly. My information on these laws comes solely from the article, which says:
> In California, information on voter registration cards is considered confidential, and subject to many restrictions to access and use ….
"[S]ubject to many restrictions" links to https://www.lavote.net/Documents/purchase-order-for-voter-el.... I suppose that you could argue that these restrictions do not prevent you (assuming you are a US person) from accessing the data, but I think that the data are far from being public, which is what I understood you to be saying.
edit: I pieced together information from other comments and noticed that who one voted for is not available, even through this breach. That's great. My comment here was addressing the breach as it was presented in this comment thread.
> revealing what candidates or parties voters chose
This did not happen.> This did not happen.
The list of fields at http://www.databreaches.net/wp-content/uploads/DataFields.jp... does include 'party', although I suppose that information is only as confidential as the voter registration anyway.
EDIT: The replies indicate that my last sentence was unclear. Contrary to what it seemed to say, it meant that, since the voter registration isn't confidential, neither is the party information (except that sometimes the voter registration is confidential, as discussed in the article and my 'uncle' comment (https://news.ycombinator.com/item?id=10801570 )). Maybe I should have phrased it, equivalently but more clearly, as "that information is as public as the voter registration anyway".
The point of my comment was just that it is not true that "voters' parties weren't revealed", which I took to be part of dfc's comment (https://news.ycombinator.com/item?id=10801543 ).
Campaigns will also use it to target their literature; you might send one mailer to the members of your own party ("X is a totally loyal party member, here's seven things he did to support our core party values!"), another mailer to the opposition party ("X is not a total baby eater, here's five ways he crossed party lines to support things you probably care about!"), and a spattering of other mailers to the third-parties to emphasize support for their particular interests.
The weirder thing to me is that these databases also include birthdays. You could send birthday cards to everyone.
The list of fields shown is not complete, as they clearly state. They may have a reason known only to them, don't ask me what it is, for holding back information on fields they did not show.
.. thereby destroying the integrity of the secret ballot, enabling vote-selling, intimidation, etc.
The article specifically mentions this:
> While the majority of states make their voter registration lists available as a matter of public record and do not restrict use, some states restrict use. For example, South Dakota requires the requestor of voter registration data to sign a statement …. In California, information on voter registration cards is considered confidential, and subject to many restrictions to access and use …. And in Hawaii, voter registration information may only be used for elections and by the government.
It is implied that the victims include voters from these three states (and explicitly stated that they include voters from California), so it is a genuine data breach in that sense.
> As far as I can tell, the only "breach" here is revealing what candidates or parties voters chose.
Also, as other commenters have mentioned, the list of fields at http://www.databreaches.net/wp-content/uploads/DataFields.jp... does include your party (which I think is information as public as the voting record anyway), but does not seem to include your specific vote.
That said, both RNC and DNC databases track who you are likely to have voted for in each race, but that's just a guess. It's a secret ballot. Nobody knows who you voted for.
For a Get Out the Vote operation it's very valuable to know how consistently people have voted in the past. If you look like a supporter but you vote inconsistently, I might call and ask if you need a ride to the polls. If you already vote every time, I'll allocate resources elsewhere, or ask you to donate/volunteer.
This is why Wikipedia founder Jimmy Wales (and presumably other victims of stalking or DV) does not vote.
Isn't this supposed to be anonymous? Is it just the affiliation declared when registering for voting, or the actual vote itself?