6 ms·
The DNC data breach
- digitalzombie 11y agoThat bug seems to be setting back Bernie Sanders, which sucks. The media going to have a field day with this.
- justinzollars 11y agoI'm sure Sanders was just polling well, and this is the perfect opportunity for the DNC to pull the rug out under his campaign. NGP-VAN is crap hack software anyways.
- diyorgasms 11y agoRight? Bernie just got some endorsements (which he has been sorely lacking), and all of a sudden this company (the CEO of which is a public Clinton supporter) has a problem that affects the Sanders campaign but not the Clinton campaign, on word from the company that there was a bad actor in the Sanders campaign but not the Clinton campaign. Sure it's possible that the Sanders campaign did exploit this and the Clinton campaign did not. But I'm skeptical as hell given the political allegiances of the company's leadership.
- morninj 11y agoHaving actually used NGP-VAN, I think it's far more likely that this was a bug, not a conspiracy. The VAN is a real clunker in many ways, so it's not surprising that a bug like this would appear; and public exposure of a conspiracy to sabotage Sanders would be so catastrophic to the Clinton campaign that I think it's highly unlikely that NGP-VAN would do it.
- toomuchtodo 11y agoI don't think NGP-VAN is involved. I believe the DNC is using this "crisis" (never let one go to waste, am I right?) in order to discredit Sanders' campaign (as the DNC is cozy with the Clintons).
- vvanders 11y agoYeah, that seems to be a reasonable conclusion here(esp since Sanders campaign reported a similar breach in other software but we don't see the DNC acting the same).
- diyorgasms 11y agoOh having used enough "enterprise" software in my day, I have very few doubts that this was a bug. I only have doubts that Sanders' campaign would have discovered this while the Clinton campaign did not. Both have presumably talented people working for them, it strikes me as unlikely that both sides were not a party to malfeasance. As such, it would not surprise me if the company leadership were covering for the Clinton campaign.
- scarmig 11y agoAs someone who has had... shall we say, intimate interactions with NGP-VAN's code base, the idea being floated by some Sanders supporters that this is a DNC conspiracy and not a bug is hilarious.
- toomuchtodo 11y agoSo its Sanders' campaign's fault NGP-VAN's code is shit and released information it shouldn't? EDIT: Why isn't the DNC taking punitive actions against NGP-VAN? Ahh! Of course. Because they're a tight knit "provider" which is essentially the political tech vendor of the DNC.
- brown9-2 11y agoIf so then this would be a non-event right?
- pool 11y agoWhen I need a reminder that I'm not like most people, I just need to look at how something in human psychology means that being the president / prime minister / dictator's son/brother/wife means that you get your turn as well. Maybe it really is nothing more than "Oh, I've heard of pepsi, so I'd better buy a fucking ton of blue-labeled sugar water every week of my life", but there might be something else evolutionary about power and loyalty and reward.
- deleted 11y ago[deleted]
- slg 11y agoIf you believe the Sanders camp, this sounds a lot like the Instagram bug bounty issue [1] that appeared on HN recently. Someone from the Sanders campaign identified a bug and to prove their was an issue grabbed private data that they should have never had the ability to access. That is questionable ethically whether they looked at the data or not. The DNC also can't immediately tell if it is the truth or if the data was taken maliciously. Given that, I don't think it is unreasonable to temporarily shut out the Sander campaign until it was fixed. Although if I was in charge, I would shut out all campaigns until the matter is fully investigated. It isn't fair to disable one campaign if there was nothing malicious happening. (Never mind, see edit) EDIT: Actually on seconding reading the Sander's lockout was not for security reasons and was only done by the DNC in awaiting full details from the campaign. In that instance it wouldn't make sense to suspend any other campaign's access. They are punishing the Sanders campaign in hopes that it causes a quick confession of the exact details of what data the campaign accessed and retained. I still don't think that response is as unreasonable as some Sander supporters are alleging. [1] - https://news.ycombinator.com/item?id=10754194 https://news.ycombinator.com/item?id=10754194
- Zikes 11y agoBecause of the audit, they were quickly able to identify who was accessing data they shouldn't have been able to access. Presumably the temporary lockout is not to prevent further data breaches, as that bug was already fixed, but to minimize the potential damage of the data breach they did identify.
- smadge 11y agoI think it is pretty unreasonable. As you note, there is no technical reason to deny the Bernie campaign access to their data. The Bernie campaign has fully indicated they want and are willing to cooperate with a third party investigation into the data breach, which would require investigating both campaigns, the DNC, and NPG VAN. Given they are already willing to share everything they know about the incident, there is absolute no legitimate reason for the DNC to intentionally sabotage the campaign.
- slg 11y ago
- sethbannon 11y agoFor those that are not familiar with the space, campaigns typically use voter contact software to record the results of the conversations they have with potential voters on the phones, at the doors, and over the Internet. In this case, the voter contact software that both the Hillary and Sanders campaigns were using, NGP VAN, had a bug which allowed both campaigns to access each other's private, proprietary data (in this case, I believe, modeling data). The Data Director on the Sanders campaign discovered the error and (he claims) was verifying and documenting the bug, which was then reported to the Democratic National Committee (DNC) and NGP VAN. The DNC claims these actions were not in good faith, and as a reaction cut the Sanders campaign off from the system. This is a BIG deal for a campaign, so close to the first elections. Campaigns rely on that data to inform nearly everything they do, and rely on access to such tools to conduct their voter outreach program. Being cut off from the system is crippling for a campaign, likely why the Sanders campaign so quickly sued to get its access reinstated [1]. [1] - http://www.politico.com/story/2015/12/sanders-campaign-threatens-to-sue-dnc-216942 http://www.politico.com/story/2015/12/sanders-campaign-threa... edit: typos
- toomuchtodo 11y agoDifficulty level in replicating this dataset from secretary of state rolls?
- dragonwriter 11y agoAs I understand it, the data set contains proprietary information from the campaigns using it, so it is impossible to reconstruct it from any public source, or really any source unless the campaign has retained separate copies of all the data (which is probably impractical.)
- sethbannon 11y agoNot technically difficult but incredibly tedious. First, you have to go out and collect it from all 50 Secretaries of State, and in come cases county officials. Some states send you the data on a CD (no joke). You then have to clean the data, which is often not in great shape, and then normalize it. Even then, you only have a snapshot, because the states typically don't keep historical data. What this means is that your dataset won't be as good as someone who's been collecting this data for years, and thereby knows things you won't like where someone used to live, how often they voted there, who recently dropped off the registered voter rolls, etc. In this case, even this data wouldn't be enough, because the Sanders team had made likely hundreds of thousands of contacts with voters, and recorded what issues they cared about and who they planned to vote for. This data, which they personally collected, is now inaccessible to them. edit: expounded
- toufka 11y agoA significant problem with 'dynasties' is that you start to get perceived, if not real conflicts of interest above and beyond governance itself. As was pointed out in this reddit thread [1],The CEO of NPG VAN (Stu Trevelyan) is a strong supporter of Hillary Clinton and worked on the 1992 Clinton-Gore "War Room," and then in the Clinton White House [2]. [1] https://www.reddit.com/r/technology/comments/3xbt3w/bernie_sanders_campaign_is_disciplined_for/ https://www.reddit.com/r/technology/comments/3xbt3w/bernie_s... [2] https://personaldemocracy.com/stu-trevelyan https://personaldemocracy.com/stu-trevelyan
- dragonwriter 11y agoEven without dynasties, its not at all uncommon (in fact, its rather routine) for either party committee chairs or firms serving parties or campaigns to have close ties to one or more of the candidates.
- joshdick 11y agoIt's irrelevant who the NPGVAN CEO supports: The decision to cut off the Sanders campaign was made by the DNC, not him.
- thieving_magpie 11y agoA bug of that nature, completely bypassing all permissions, made it past testing (I presume they test). Whatever happened afterward is noise to me. How the hell do you let that happen? Hardly getting any blame is a neat trick. I wish I had that luxury.
- sneak 11y agoClose enough for government work. See also: "goto fail;"
- n0us 11y agoInteresting that Hillary would protest unauthorized access of data when she was running that email server that was not authorized, and arguably was holding much more important information than a voter database.
- rockshassa 11y agoAre there any grey-hat things that can be done keep campaign-parity in the mean time? Strictly hypothetically, I'd throw all of my technical skills at this problem if there was a clear path to a solution.
- smadge 11y agoJosh Uretsky and Russell Drapkin copied voter lists [1]. Did they intend to keep and misuse the lists that they copied? If they knew they were being audited, it's unlikely they intended to misused the data and get away with it. Uretsky has experience as a programmer [2]. He might be telling the truth and was only documenting and determining the severity of the issue. On the other hand 20 voter lists is a bit extensive for a proof of concept. [1] - http://www.bloomberg.com/politics/articles/2015-12-18/sanders-campaign-fires-data-director-after-breach-of-clinton-files http://www.bloomberg.com/politics/articles/2015-12-18/sander... [2] - http://heavy.com/news/2015/12/josh-uretsky-bernie-sanders-campaign-national-data-director-fired-photos-bio-age-who-improperly-accessed-clinton-data-democratic-dnc-system-access/ http://heavy.com/news/2015/12/josh-uretsky-bernie-sanders-ca... edit: added source