10 ms·
191M US Voters’ Personal Info Exposed by Misconfigured Database
- r0m4n0 11y agoI own a few services that rely on voterfile data we acquire from many sources and I am aware of quite a few others (so I feel like I need to chime in here haha). I suppose sources aren't going to disclose the actual resource or IP address until law enforcement tracks them down? I haven't been able to find any reports of anything specific. It may not be Nation Builder per se but it could be one of their many integration points maintained by third parties: http://nationbuilder.com/apps http://nationbuilder.com/apps
- kazazes 11y agoA well crafted shodan.io search given the already public information (approximate size, in the US, no password, etc.) should give you a good start. It's already been found once.
- exhilaration 11y agoSo here's a starting point: https://www.shodan.io/search?query=port%3A27017+country%3AUS+os%3Alinux https://www.shodan.io/search?query=port%3A27017+country%3AUS... I'm not sure how to search by database size though. But I'd estimate that 190 million voter records, at 1 kb each, would be a little under 2 GB if my math is right.
- kazazes 11y agoIt's not any of those. Are you sure it's running linux? Also, you're off by a few orders of magnitude. 191mm records * 1kb each is 191 gigabytes.
- exhilaration 11y agoI included Linux in the search based on this earlier comment: https://news.ycombinator.com/item?id=10802149 https://news.ycombinator.com/item?id=10802149
- cynwoody 11y agoHere is a MongoDB named voters† that claims to be 472166432768 bytes long (a little short of 2500 bytes per voter, if there are 191e6 voters). I'm not familiar with MongoDB and don't have the time to learn right now. But do check it out! †https://www.shodan.io/host/52.0.220.221 https://www.shodan.io/host/52.0.220.221
- exhilaration 11y agoYup, you found it. Confirmed: db.blackhole_nj.find({$and:[{"fname": "Christopher"},{"mname": "J"},{"lname": "Christie"}]}) The governor's DOB in the results matches what's in Wikipedia.
- jlgaddis 11y agoHaving never used MongoDB, I guess I should go searching for some code examples.
- josscar 11y agohow did you run that?
- exhilaration 11y agoAny MongoDB client, I used Robomongo at the time. But when I tried again the next day I could no longer connect.
- wwweMergescom 11y agoBe pleased to look for the source with you emerges.com@gmail.com
- deleted 11y ago[deleted]
- AlexCoventry 11y agoSo where is the database? If there's any legal or ethical problem with doing this using the Ohio Voter Registration files, I would like to know. I recently made an interface to it[1] to use when gathering ballot access petition signatures for Bernie Sanders in Ohio[2]. It's freely downloadable data, though[3], and the Board of Elections officials I shared it with weren't aghast at the idea. [1] http://gobernie.net/ http://gobernie.net/ Source code: https://github.com/coventry/voter_lookup https://github.com/coventry/voter_lookup [2] https://www.facebook.com/groups/929112173802716/ https://www.facebook.com/groups/929112173802716/ [3] http://www2.sos.state.oh.us/pls/voter/f?p=111:1:0::NO:RP:P1_TYPE:STATE http://www2.sos.state.oh.us/pls/voter/f?p=111:1:0::NO:RP:P1_...
- occsceo 11y agoMy team has these same questions, we are working on a unified voter db. Care to collab on thoughts? looks like thehill just picked up on this. my username at gmail
- wwweMergescom 11y agoBe pleased to look for the source with you emerges.com@gmail.com
- deleted 11y ago[deleted]
- ryanlol 11y agoNot sure what LE is doing here unless this is operated by an org in one of the states where it's illegal to publish this data. e.g a Florida company publishing California voter records in Florida can't possibly be committing a crime. I don't see why FBI would get involved either, since there doesn't seem to be any federal crimes happening here.
- wwweMergescom 11y agoLook at our more detailed compilation of statutes at http://www.emerges.com/assets/images/docs/Restricted-State-Voter-Use-Affidavits.pdf http://www.emerges.com/assets/images/docs/Restricted-State-V.... Note NationBuilder is wrong about permissible MS data useage. More critically, NationBuilder may erroneously be denying accountability. “Nation Builder is under no obligation to identify customers, and once the data has been obtained, they cannot control what happens to it,” Specifically look at the statues for MA and CA. Clearly and in writing voter list purchasers are required to get written pre-approval from the two respective states PRIOR to releasing the data. But what if NationBuilder did not sign the affidavit with the state, ie what if NationBuilder got the data from someone in the Democratic or Republican national or state parties? If either of the two major parties released the data without getting written pre-approval from the state, then they may all be in breach of contract and liable, NationBuilder included.
- a2tech 11y agoWhats amazing is that there seems to be no way to contact anyone to take down this database-its just sitting there happily serving up data to anyone that asks. No contact info, no way to track down the owners. Almost makes you think knocking it offline would be worthwhile just so someone will take a look at it.
- dvcc 11y agoUsing census info for age distributions, this most likely amounts to every registered voter. The site also seems to be having a rough time with the traffic. Here is the cached page: http://webcache.googleusercontent.com/search?q=cache:BXSmNL6bUa4J:www.databreaches.net/191-million-voters-personal-info-exposed-by-misconfigured-database/+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:BXSmNL6...
- Afforess 11y agoAs far as I can tell, the only "breach" here is revealing what candidates or parties voters chose. The voter registries are public in nearly all states. I've used public voter registries to look up addresses, even when I only had a name. Information such as a personal address, phone number, etc have always been trivial to look up.
- krisdol 11y agoI don't disagree with the general notion of your comment, but in > As far as I can tell, the only "breach" here is revealing what candidates or parties voters chose Why put "breach" in double-quotes? That's a very serious privacy concern if voters did not want this information to be public.
- JadeNB 11y ago> Why put "breach" in double-quotes? That's a very serious privacy concern if voters did not want this information to be public. I think that this is a very important point. It doesn't matter how important it is to you that my information is public; the seriousness of its exposure depends on how important it is to me. (I am using 'you' and 'me' here not to argue with you specifically—in fact I agree with you!—but rather as generic pronouns.)
- eli 11y agoIt's not a breach because nothing was exposed that wasn't already public. Public voter rolls are one way we prevent fraud.
- JadeNB 11y agoYour replies in this thread suggest that you take the public nature of voting registration lists to be axiomatic, but it is not; as the article discusses (and as I quoted at https://news.ycombinator.com/item?id=10801570 https://news.ycombinator.com/item?id=10801570 ), there are (more or less strict) laws regarding confidentiality of voter registration lists in some states, some of whose voters are affected by this breach.
- jwcrux 11y agoSeeing the "_id" : ObjectId() fields indicates to me that this is likely a mongodb instance that was available to everyone. There's been a lot of talk about these recently[1] that I'm surprised this didn't come up sooner. [1] https://blog.shodan.io/its-still-the-data-stupid/ https://blog.shodan.io/its-still-the-data-stupid/
- xPaw 11y agoYeah, the screenshot is using MongoVUE.
- deleted 11y ago[deleted]
- cjoh 11y agoWhile it's poor form to have a leaky database, this information is largely public and dirt cheap. You can buy a whole state's worth of data for a couple hundred bucks or a few cents a name. That includes whether or not you're registered to vote in any specific primary. Doesn't look like who you voted for is disclosed -- I'm not sure that this data even exists. I suspect in most states, you go in to vote, your name is crossed off a list, you're assigned a hash, and that hash votes, and there's no database of "John Smith voted for Jane Doe."
- eternalban 11y agoDoesn't DieBold determine who voted for whom? /s
- golergka 11y ago> I suspect in most states, you go in to vote, your name is crossed off a list, you're assigned a hash I don't know about US, but I once knew a programmer who worked on russian voting system. I honestly don't think that he was qualified enough to know what "hash" is.
- pavel_lishin 11y agoGiven that it's a Russian voting system, I'm not sure that this is unintentional.
- golergka 11y agoStupidity, not malice. In my observer experience, the higher the official, the less interested he was in falsifications; it was the lowest ranks that wanted to prove that their areas are loyal with any means necessary, while the higher-ups wanted to avoid the embarrassment and didn't worry much about the outcome, since population's loyalty is pretty sincere, thanks to the propaganda machine.
- hackuser 11y ago> since population's loyalty is pretty sincere, thanks to the propaganda machine Or is that we believe the population is loyal, because of the propaganda machine's affect on us?
- cbsmith 11y ago"Could it be one of their non-hosted clients leaking the database? Maybe. Could it be that someone hacked one of their clients and stored a copy of the database at this IP address? Maybe. Could it be that an employee of a client decided to make themselves a copy for their own purposes? Maybe. The possibilities are numerous. We really don’t know and DataBreaches.net declines to speculate." Umm... you just speculated.
- NittLion78 11y agoThey refuse to speculate if one of the speculations is superior to other speculations. Thus, if all speculations are still on the board to be further speculated upon, one cannot speculate further. My head hurts.
- cbsmith 11y agoYou win the rationalization of the day award: two aspirins. ;-)
- eli 11y agoThis is public voter data that anyone can get from their county office or secretary of state's office. It's not being "exposed" because voter files and party registrations were never secret.
- NN88 11y agoBut eliminating the jumps you go through to get that info isn't a good thing either
- jes 11y agoAre you saying that accessing public data should be possible, but require a willingness to jump through hoops? What's your thinking behind that?
- deleted 11y ago[deleted]
- dangrossman 11y agoI'm not the person you asked, but to play devil's advocate... I think law enforcement agencies should be able to wiretap suspects of crimes to listen to their phone calls, subject to judicial oversight. I do not think they should have unrestricted, unlogged access to a database of recordings of every phone call ever made by every citizen. Same line of thinking IMO. There's a difference between an individual identifying themselves and signing a usage agreement before requesting public records from an individual county, versus dumping online a public database that lets you query the personal details of 191 million people. The same data is available, but the extra hoops you have to jump through change the potential for abuse.
- jes 11y agoI appreciate your thoughtful comment. With respect to the law enforcement example, the access there is to non-public data. That seems like an essential difference to me, but perhaps you're citing this situation in preparation for your third paragraph. In your third paragraph, I think I'm seeing a dilemma. I don't understand how jumping through the hoops changes the potential for abuse. Let's say 30 people go to the county records office and get the data. They all sign an agreement of some kind. 30 people now have (presumably) exactly the same data set. One of the 30 violates the agreement and publishes it anonymously on the Internet. The data is now "in the wild" and any potential for abuse that it held is now up for grabs. I recognize that I may be missing something, but if I am, I'm not able to see it. I might need more coffee. ;-)
- deleted 11y ago[deleted]
- jstalin 11y agoEarlier this year I spent $25 for a FOIA request for my state's entire voter database. This isn't exactly private information.
- whoopdedo 11y agoWhat benefit does revealing registrations provide? How would the public interest be harmed by shielding names, addresses, and phone numbers from disclosure? A lot of comments here saying "so what it's public record." But not a lot of asking if it should be. Something being the status quo doesn't make it right.
- kristofferR 11y agoIt seems like this is a MongoDB database. Scanning the US IP ranges for Linux hosts (as mentioned in the article) with port 27017 open with ZMap and then running a script that connects to the open database and saves the size of the database in a file would be a good place to start for those who want to find it.
- hendzen 11y agoAlso a good way to go to jail. Please think long and hard before accessing random computers on the internet. The fact that they are unprotected is unfortunate but irrelevant.
- r0m4n0 11y agoWhile you might appear to be overly cautious, I'm going to agree with you. Better to not be wrapped up in the witch hunt especially once we know authorities are investigating
- netcraft 11y agoim interested in the legality argument against this - if it is illegal how do sites like this operate? https://www.shodan.io/search?query=port%3A27017+country%3AUS+os%3Alinux&language=en# https://www.shodan.io/search?query=port%3A27017+country%3AUS... or even https://scans.io/ https://scans.io/ which uses something like https://zmap.io/ https://zmap.io/ Not saying you're wrong, wondering where the line is if there is one.
- hendzen 11y agoPort scans (what Shodan does) are in a grey area. Actually using the port scan data to connect to a networked service and exfiltrate data is definitely illegal.
- jstalin 11y agoUndoubtedly, the torrent will be available in a matter of hours. Let someone else do the dirty work.
- DrSayre 11y agoKentucky has it where you can find your party by using your name and birthday. It also shows your home address. If you're wondering John Calipari is an Independent while Rick Pitino is a Democrat. What's interesting is that it shows Cal's address but Pinito only shows U of L. https://vrsws.sos.ky.gov/VIC/ https://vrsws.sos.ky.gov/VIC/
- d43594 11y agoWould be interesting to validate the voting record in elections according to the DB against the outcome.
- balgan 11y agoWe actually found a ton of this stuff couple of months ago http://blog.binaryedge.io/2015/08/10/data-technologies-and-security-part-1/ http://blog.binaryedge.io/2015/08/10/data-technologies-and-s...
- dyoon 11y ago1) this information is mostly public information, it contains information about party affiliations and participation in elections but doesn't contain details about votes. 2) it looks like the data came from nationbuilder, which spent around 2-3 years building/compiling a voter registration database that's more accessible to the public than other proprietary solutions
- dyoon 11y agohttp://nationbuilder.com/voter_file http://nationbuilder.com/voter_file