An Electronic Voting Firm Exposes 1.8M Chicagoans
upguard.com
upguard.com
As soon as I read the headline, I immediately thought "AWS misconfiguration". A few recent massive government-data breaches (by contractors) have fallen into that category:
June 2017: http://gizmodo.com/gop-data-firm-accidentally-leaks-personal...
May 2017: http://gizmodo.com/top-defense-contractor-left-sensitive-pen...
Note that all of these breach reports (including this Chicago one) come from Upguard, which seems to have a method for scanning/crawling public S3 buckets.
"No charge for the first 1 GB processed by the content classification engine After first GB, $5 per GB processed by the content classification engine"
...data that's already on their servers, to boot!
https://www.engadget.com/2017/07/12/verizon-partner-exposes-...
I'll probably spend some time this weekend making things look better and improving the documentation. I made it mostly as a PoC
A misconfigured AWS instance is always an issue. I'm not trying to downplay that. Only that this data being released to the public isn't anything new - the public already had access to it.
https://www.elections.il.gov/votinginformation/computerizedv...
> The files included names, addresses, dates of birth, the last four digits of many voters' Social Security numbers, driver's license and state ID numbers for the 1.8 million who are registered to vote in Chicago.
[0] http://www.chicagotribune.com/news/local/politics/ct-chicago...
- Name
- Street address
- Party affiliation
- Elections in which you did (or did not) vote
- Phone number
- Email address
[0] https://www.forbes.com/sites/metabrown/2015/12/28/voter-data...
https://www.ssa.gov/history/ssn/geocard.html
Anecdotally, while bored in math class we figured out that 10 or so of the guys in the class had one of two numbers for their first three.
Yet it does. Almost every single business/government service in America uses DoB + last 4 SSN to identify you. The two together make fraud trivial.
Before you answer, you may want to poke your answers into this site and have a look at the outcome: https://www.ssn-check.org/lookup/
Caveat: This tracks your issue date, not truly your birthdate. In the past couple of decades many/most babies get registered at birth, but if I stick my own (birth) data in there I actually get the wrong answer, because when I was born issuance wasn't automatic yet. But that will work for a lot of people.
How many services do all of use use that accept name/birthdate/SSN as identification? How many other services, like phone companies, claim not to but would still yield for someone who sounded earnest and knew all of that?
And what can the leak victims possibly do? TFA is great where you can get it, but it's not universal, and none of this information can be refreshed.
Hooray for the free market .. ?
The free market says they don't care. I've had my identity stolen from a data breach. Could I have sued? Yes. Could I have led a class action lawsuit? Yes.
Did I? No. Why? I'm fine now and just like billions of other humans, I'm lazy and simply just don't care enough.
Amazon sent out warning emails for owners of misconfigured boxes about 60 days ago. Why didn't the firm in question take action? I am an engineer and literally had to do that same task at work at that time. Easy as 2 clicks.
I've wondered before why the UK doesn't have e-voting, and after watching it is sort of seems obvious. With traditional voting, it can easily be changed on a small scale, but is very hard to do in a meaningful way. Whilst with e-voting, its almost just as much effort to change on a small scale as a bigger scale, with much fewer people being involved.
I particularly like the idea that the reason we use pencils is as a protection against somebody replacing pens with ones with invisible ink. Not sure if this is true though.
This is a trove.
We have to get away from this idea of having "secret" numbers that, if simply discovered, can cause so much damage.
That includes credit card numbers, SSN, etc.
But, if you're interested in building an alternative, then off the top of my head, I'd suggest that we've got the blockchain. We've all got omnipresent palm-sized computing devices. We've got 2FA schemes, and more. The tools are there for you to create a much more robust system than one that says "here are a handful of secret numbers. Don't let anyone else see them or else your life may be ruined".
"Something you know" isn't a great standard as the entirety of auth, but it'll probably stay common for practical reasons. But "something you know and can never change if breached" is absolutely idiotic, and there are plenty of good alternatives already in existence.
We could start by exacting real consequences for those who abuse SSNs.
I just looked around and only found 42 U.S. Code § 408, which offers a maximum penalty of five years (higher for Social Security workers or medical professionals engaged in fraud).
Also, the vast majority of the text concerns misuse of an SSN to defraud of mislead the government, particularly by claiming benefits. (8) does read "discloses, uses, or compels the disclosure of the social security number of any person in violation of the laws of the United States", but at a quick look I only see prosecutions where that was tied to benefit fraud.
I don't think 5 years is an insufficient sentence, and I think the urge to raise sentences as a deterred is usually counterproductive. But I do think there's room for progress here.
Most SSN abuse as identification appears to be prosecuted as simple identity theft, not SSN fraud. Adding the secondary charge specifically for SSN abuse might encourage thieves to rely on other, less permanent information like passwords.
More broadly, I'd rather see the government concede that SSNs have become a standard form of identification, and make the renewal process less heinous. Right now you have to show grievous hardship over an extended period, can't appeal a bad decision, and will still lose your credit history when the new one is issued. That's simply not a reasonable system for a number people are expected to give out so often.
So, enforcement is a lot easier said than done.
Putting on my tinfoil hat for a moment, I have this nagging feeling in my guy that these issues are a little too coincidental.
So how can we make sure all this data isn't used to tamper with voter rolls or uploaded to FB, etc. to create Custom Audiences based on voting history and district?
Here's Florida's relevant information:
http://dos.myflorida.com/elections/for-voters/voter-registra...
"Voter registration information is public record in Florida with a few exceptions. Information such as your social security number, driver’s license number, and the source of your voter registration application cannot be released or disclosed to the public under any circumstances. Your signature can be viewed, but not copied. Other information such as your name, address, date of birth, party affiliation, and when you voted is public information."