Personal info of 6M Israelis leaked after Likud uploads voter info
jpost.com
jpost.com
The gist is that, amazingly, the url "/get-admin-users" would return a list of all admin users with their plaintext passwords... And that this url appeared in the html source of the site's landing page.
[0] https://internet-israel.com/%d7%97%d7%93%d7%a9%d7%95%d7%aa-%...
- passwords in plaintext, check - deliver that list without protection, check - put a hint to this route into the landing page, check
Wow!
Stupidity may be a great cover for uncoordinated malice leading to widespread negligence. A bit like “chaos monkey” but by those who’d like to rearrange the pieces.
Whether they are a "corrupt cowboy" or "cost-efficient genius" mostly depends on whether the project is a success, and that depends on luck.
Relevant comment I wrote on how to solve that:
Of all of the crazy in this story, this is possibly the most worrying bit - journalists can’t do journalism without facing prosecution.
That's exactly what a scientist is? At least if they're using the scientific method to learn about the world.
As an example, i was extremely surprised when an israeli airline company sent me my existing password in clear text via mail. For a country that's at the forefront of fighting terrorism and always assessing airplanes security, it seemed like an incredible mistake.
More than a decade, no patent numbers yet.
Israeli public sector tech: crook
Outside the IDF, which is merely incompetent and overstaffed, this is mostly on purpose. The reigning Israeli government for the past ~10 years have been corrupt neoliberals of the most stereotypical kind.
This leads to a situation where apps and websites facing the local market are usually sub par, apart from the rare case where a good start-up uses it as a dogfood playground for new tech.
> The firm that developed the application, Feed-b, commented that the vulnerability was a “one-off incident that was immediately dealt with"
Yeah... after a screw-up of that magnitude you don't even need a second vulnerability.
Although I should be, I am not actually surprised by the lack of security in a political parties application.
What I don't understand is why the interior ministry is providing political parties with the entire voter registry, which includes PII. I never gave my consent for this. It probably explains why I am getting spam SMS's from different parties on a daily basis(which is extremely annoying), but worse than that, soon we will all be forced to join the biometric database and I have zero confidence in the ability of the interior ministry to protect that.
Personally I am no fan of GDPR, but I am starting to see why it's necessary.
Israel may have a similar law but I don't speak Hebrew and I suspect any searches I do for this will get buried by the news of the leak, so I don't think I'll be successful in finding it.
In this case the information included first name, last name, ID number, phone number, address and parents names
Voting record in this case means which elections you voted in, not who you voted for.
It is explicitly illegal to use these records to send advertisements, but who knows how well that works
Apparently, the parties voted themselves the right to that data when the election cycle starts (6 months or so before the actual elections, or something like that), under the promise that "they will keep it safe, and delete it afterwards, and only use it themselves". Needless to say, it has leaked out to marketers/private-investigators/bittorrent in basically every election cycle so far.
Am not a fan either (but likely for different reasons), but would this be solved by Israel adopting GDPR? I'd assume they already have data privacy laws in place, and this still happens. I also don't think that it's a question of increased fines - those just become part of the business plan.
Israel could probably do with something like the GDPR or CCPA.
But they did, because reasons. It would be nice if they committed their extralegal activities with more care so they create less collateral damage, sure, but the issue is that people/companies/institutions who don't care about law ... don't care about the law.
> At a minimum it would guarantee legal consequences for those companies that are not protecting PII
I understand the sentiment, and I wish that was true. Alas, my experience is that it is not.
edit: made it clear it was only on a per-ward basis.
UKIP would be allowed a copy for free, being a registered political party. Those entitled to a copy for money are limited, rather than just "anyone who pays five grand". OTOH, the open, edited register is more widely available, but it has been possible to remove yourself from that and has been for some years. https://ico.org.uk/your-data-matters/electoral-register/
So no, you can't buy a copy of your local ward, but every few years you can spend a small amount of money and do a little paperwork to get a copy.
More specifically - did you ever give your consent for everybody's biometric data to start being collected as well? They went ahead with this despite the pilot having established there are security concerns and despite public outcry against it.
I should inform other readers about the icing on the cake as well: The Minister of the Interior is a convicted criminal - Arye Der'i - who served time for corruption in this exact position. He is also currently under criminal investigation for corrupt dealings involving embezzlement of charitable organization funds in favor of some real-estate purchases. He was also implicated in the "Bar'-On-Hebron" affair during his last trial, where he was trying to get a convenient attorney general appointed in exchange for agreeing on the army withdrawing from occupied Palestinian city Al-Khaleel/Hebron. He wasn't indicted on that one because he had supposedly "quit politics" and was in jail when the investigation concluded.
I find it's sometimes an illuminating point of view, to see these sorts of egregious failures from the point of view that there is a range of possible outcomes of any effort, from complete entropic chaos to a perfect expression of the intent and specifications.
Efforts like these simply fail to approach the ideal closely enough to avoid the costs of the inherent chaos.
I don't think so much about trying to herd people toward the light of perfect code and process. I do think about ways to mitigate the cost of the chaos.
And then occasionally I get this vision of people who fail to consider the effects of breaches getting doxxed themselves, but that also seems vindictive, and as Tim Ferriss rightly pointed out just this week, can involve permanent damage to others.
We humans are a tough bunch to sort out.
EDIT: "Last week, Prime Minister Benjamin Netanyahu called on Likud supporters to download the application in order to help draft more supporters and voters."
Personally I would have said that is normal, legitimate processing; and any definition of "data leak" that included that would be so broad as to be meaningless.
Of course, the leak of the full register by a negligently designed website is another matter...
Having said that - we need to differentiate between the intended use of the "Elector" app, which is individual record search, and the ability to obtain all records. The latter is due to a bug, and that's the leak. As for the former, I'm not sure exactly about its legality in the first place; perhaps others can comment on this.