Personal info of 93M Mexicans exposed on AWS
databreaches.net
databreaches.net
http://www.diariodemexico.com.mx/inemexico-encuentra-quien-f...
The government isn't publishing details, but the article gives the impression that it was some Mexican political party acting out of line who should not have uploaded this data to US servers. It appears that each party receives a copy of electoral registrations.
¿Qué chingados? I didn't know every party got a copy of all voter registrations. This seems grossly undemocratic.
For contested elections, party inspectors will note active voters who haven't voted yet and report, which generates phone calls or even volunteers dropping by to drive voters to the polls.
IMO, transparency is required for democracy.
In Mexico, this isn't transparency, as only the political parties get a copy. This is surveillance, probably used for more effective targetted campaigning, which has historically been used for buying votes.
I'm not sure I will ever renew my Mexican voter registration.
If it isn't provided by the state, Political parties buy lots of information based on the voter rolls. They know alot.
The data leaked is enough to gain access to almost a hundred million people's account on any web-service or, as some other comment pointed out, in Mexico's case even to real-life services like banking.
[1] The United States are not the norm. You might live there, but that makes you a minority of the world population. There are some nations that actually value democracy and privacy, not just on paper.
I agree that the database should be made public for all citizens, as it currently stands, only parties registered for elections get a copy, and no doubt use it for their campaigns. This puts people outside of the party system in a disadvantage against the parties, particularly relevant for things like citizen initiatives.
What are you going to use for ID if you don't have a credencial?
To be fair, driver license is also good enough for most cases.
It's not a direct democracy.. other than state referendums, people generally do not have an opportunity to _actually_ vote on issues.
https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
(The url is the whole story).
Keep in mind also that your voting ID card in Mexico is your primary identification, similar to driver licenses in the U.S. The data from this breach can allow someone to create a pretty good fake of any voting card, which may be used to impersonate people for: banking operations, government processes (that don´t require the CURP, our equivalent of a SSN) and yes, also during elections. Voter fraud might not be much of a problem in the U.S. in reality, but in Mexico it definitely is.
Err, the US database contains address as well.
I remember when i used to run politics and elections products, we were basically the only company in the US to explicitly request they not give us names or anything we did not need (we were building street segment to voting location mapping)
My point is that what works on the U.S. and what is considered sensitive information in the U.S. might not match what is sensitive in other societies. My mailing address and phone number are relatively public while in the U.S., but back in Mexico I would never do it that way.
Here's one of the 50 websites where you can see every American citizen registered to vote... includes their DOB, Address, Voter ID etc...
and while you're there check out the removal request policy page - it's quite humorous.
EDIT: If you are wondering how the website obtained data specifically for Oklahoma please see https://www.ok.gov/elections/Candidate_Info/Voter_List/index...
I found it childish and unprofessional, just like the reply letters TPB wrote in response to DMCA requests.
Ladies and gentlemen, this is why we can't have nice things (as a species).
Isn't voting meant to be a private thing?
Isn't this a great example why it's bad that this data is open.
In Mexico, perhaps volunteers are dropping by to drive voters to/from the polls. With guns.
Ditch the party system, and maybe it gets better - I think it would.
I don't get what purpose does it serve?
Also, the note says that the info is on "Amazon's sales portal" WTF?
But they don't know the authorities know who did it.
... which, of course, was the original point.
Right, which explains they they were reluctant to put it in the news i.e. "... but they won't say because they don't want to alert the guilty party before the investigation is over."
So it doesn't seem completely illogical why they'd do it as gp post suggests.
And anyway the whole registering to vote thing is undemocratic. You have valid citizen id - you show and vote, and that is it. In Europe where everyone has government issued id card the system works fine.
If states were at all serious about voter verification through ID, they'd make every non-constitutionally guaranteed service require a photo ID. Then when it gets back to SCOTUS they could readily report that every resident in their state already has a photo ID.
This seems to be a misconfigured MongoDB server hosted in AWS but details are scarce.
Personally, with the vast swaths of PII data being leaked, I am interested in whether there is a global database of these people yet. Not for nefarious purposes, mind you, but for global legal representation not limited to voting.
> MongoDB server..
unheard of
I definitely am all for doing the right thing and I might make a best effort in the same situation, but that's pretty gutsy. My overdeveloped sense of paranoia would tell me that contacting these agencies would put me on all sorts of lists I wouldn't want to be on. Who knows how easy it is for "There is a data breach" could become "I have your data, meet my demands".
If some awful, unfortunate thing does happen on their watch I honestly hope the first thing they do is get the hell out of the way so professionals can handle the situation.
> Yeah, but that's theater performed by low-wage employees.
The status of the people who act out these policies is much less important than who is setting these policies. And it's not low-wage employees who are setting these policies, it's high level bureaucrats, the same bureaucrats who will be in charge of your fate should you report wrongdoing to them.Picking up the phone and calling random departments is how you get in trouble. All it takes is one person to scream "hacker", which is not unlike yelling "fire" in a crowded building, and you've got yourself in hot water even when trying to do the right thing.
If there was a number to report security issues of this sort, or an email address if they're that savvy, it would go a long way towards encouraging people to report serious issues.
[1] http://krebsonsecurity.com/2015/12/13-million-mackeeper-user...
[2] https://www.linkedin.com/pulse/mackeeper-chris-vickery-launc...
It's completely nuts. I always give fake or incomplete information to everyone, private or public (and you must give info for practically anything here). If it's absolutely necessary to give real info, then I never update it.
This is generally a problem I've come across multiple times. Small hosters are usually quicker to respond ( or they don't at all), and then actually try and handle malicious hosts on their networks.
The large ones like Amazon or CloudFlare (especially CloudFlare) have a semi-automated process, where the impression I get is that I am talking to a really stupid bot. Or when I get through to a human, that they are so overworked that they aren't able to comprehend the sentences that write to them in plain english, so nothing get's resolved. Or they just forward my info to their customers, which in many cases is a real security risk.
[0] http://www.dailydot.com/politics/amazon-mexican-voting-recor...
From this and many other leaks and breaches from companies, governments & institutions one could deduce security is imperfect & digitally massively so.
Identity theft is rampant; Biometrics are irrevocable - yet the solution is used by most people everyday.
Cryptography solves both the problem of identity and privacy simultaneously.
It is establishable as persona via chains of trust, e.g. PGP signing.
Apart from societal control there seems no good reason not to adopt a system whereby everyone is issued a private and public key - which signs every email, bank instruction, comminucation & vote.
Akin to good practice being to store only password hashes so only the individual posses the secret.
Ones identity would be ones own responsibility and huge leaks like this would reveal nothing but a list of public keys obtainable by crawling the web.
One can imagine a dystopian future nation where individuals must fight to protect their basic fundamental rights from state level adverseries operating outside the law - punchline is the worst threat is their own government.
Ever since Gibson the best science fiction is set in the present.
Privacy and key loss are two reasons that come to mind.
Key loss would require re-issue - under the present system that uses real details or a biometric these cannot be revoked so cryptography seems better.
The current system the UK uses is a Nation Insurance Number, which is just a key in a government database but once issued it is not revokable either.
Solutions like a back up reissue key, or quorum of those who signed you key verify it is lost and then it can be resissued, or an trusted official like ones lawyer - or you have to take some ID to a post office.
It may be inconvenient but less inconvenient than identity theft today.
As for privacy this is solved by crytography too, so I don't follow your first point.
If I wanted to message you privately, I encrypt the message with your public key and then you and only you can read it - just like PGP today.
Of course this hypothetical system unbackdoored cryptography would be fully legal so we could have keys just for privacy between us / or verification.
A bank could issue a key per account, the key ensures your banking cannot be eavesdropped and ensures the identity for this account.
While I think it's a good idea for services that already required official documents (governmental services, bank accounts, certain utility contracts), I fear that once the system is actually used by most people - right now it's still mostly ignored - more and more services that were once somewhat anonymous will start requiring the card, since the barrier is much lower than having to send an authenticated photocopy.
This allows anonymous accounts that are also verifiable.
National ID databases or Government Overreach can be enacted using an insecure system like Social Security Number as a database key, already.
Certain private elements of ones file, such as credit card, or medical records, could be kept encrypted until the citizen grants a temporary access token.
If one discovers a security issue or data breach, it is best to either do nothing, or at most raise the issue very anonymously.
I find this the most interesting. I thought of a voting system where every citizen gets a unique voting key. It obviously would be a huge mistake to vote directly with such a key. Signing your voting decision makes a lot more sense. This way only the government and you know the key.
I wonder what will happen now, looks like they will have to reissue 93M codes.
These numbers are typically abused in mass fraud for government monetary/physical goods assistance programs.