9 ms·
How a Political Engineering Firm Exposed Their Code Base
- deleted 9y ago[deleted]
- craftyguy 9y agoThis is basically just some screenshots of a private gitlab instance? It would be trivial to fabricate this story.. Did he post the files publicly?
- peterhadlaw 9y agoIf this is true, what are the ramifications for unauthorized computer access? Update: looks like the registration link was still listed / open, but my question still stands
- Moogs 9y agoAccording to the first article, the code was hosted with a custom version of Gitlab, with the register link still functioning. Once an account was created all the repos were public. If that's true, then it's a public site being accessed through features of the site.
- peterhadlaw 9y agoI'm sure it also depends on if the site was intended to be accessed "publicly" or not. Let's say, visually, all registration links were removed, but (as someone with internal knowledge of GitLab here did) could "breach" into the registration page.
- Varcht 9y agoIsn't it typically “breaking or entering”, not “breaking and entering”?
- shiado 9y agoThis is the most interesting question. The company is based in Canada so supposedly Canadian laws would apply but I suppose it depends on where the Gitlab instance is hosted. Also the author cannot argue that they were bug hunting in good faith as an ethical security researcher would cease activity after breaching the repository and report their findings. If American laws apply the CFAA is extremely selectively enforced but if I was the author of this I would be extremely fucking concerned about going up against the Trump entourage.
- michaeljbishop 9y agoInteresting followup by Seth Abramson. https://twitter.com/SethAbramson/status/978329921192906752 https://twitter.com/SethAbramson/status/978329921192906752
- CobrastanJorji 9y agoThanks for that; that was a much more comprehensible summary.
- draw_down 9y agoThis is why I have trouble believing much will come of this, besides all the other petty corruption and dishonesty we've seen which has had essentially no effect. It's a real bummer.
- tptacek 9y agoSeth Abramson sure is someone to talk about poor journalism and analysis. Really: HN doesn't need to be the first to break out stories like this. If someone important has been found here, someone will cover it seriously outside of tweets. HN should start penalizing tweet stories.
- ExactoKnight 9y agoWhy would HN penalize tweet links!? Hacker news is a perfect place for stories that intersect technical and journalistic expertise to be explored more in depth with a focus on truth. In journalism tweets are how evidence of a story evolves. Taking away twitter linking from journalistic minded HN users would be like taking away the ability for a coder to link to github...
- FLUX-YOU 9y agoHe discounts the importance of figuring out how modern election data shops work (and what tools they use/build) with regards to elections, which may be important for us to fight these firms down the road and build laws against unscrupulous data collection. The mechanical details definitely matter here, and that can be found by looking at source code. I don't necessarily agree that gizmodo should have led with tying this open repository of code to AIQ/SCL/CA to Bannon/Trump/Russia. Finding the tools and explaining what they do was more important given this was found today. It's not like they can't write follow-up articles which explain the larger issues.
- danjoc 9y ago"There is no serious person out there who would suggest somehow that you could even rig America's elections" --Barrack Obama https://www.youtube.com/watch?v=y7F7eRM1oiU https://www.youtube.com/watch?v=y7F7eRM1oiU
- eli 9y agoHe's right. There was no voter fraud. People really did vote for Donald Trump. Voters may have been distracted with leaked emails or lied to by "fake news" but the votes were real. The election wasn't "rigged."
- cuckcuckspruce 9y agoThe Democratic primary, ironically, appears to have been rigged against Bernie Sanders though.
- YurtleTheTurtle 9y agoAnd I'm sure you will provide ample evidence of this "vote rigging."
- fwdpropaganda 9y agoAre you being sarcastic, or are you not familiar with the leaked DNC e-mails where they discuss this?
- soared 9y agoActual write up: https://www.upguard.com/breaches/aggregate-iq-part-one https://www.upguard.com/breaches/aggregate-iq-part-one Important to note this leak only (as of now) ever mentions ted cruz - nothing to do with Trump's campaign beside some handwavy connections between this marketing agency and cambridge analytica. Bannon is also literally never mentioned in the write up.
- codeulike 9y agoThe Guardian has an article here https://www.theguardian.com/uk-news/2018/mar/24/aggregateiq-data-firm-link-raises-leave-group-questions https://www.theguardian.com/uk-news/2018/mar/24/aggregateiq-... about the links between AIQ and Cambridge Analytica. AIQ were used by the Brexit 'Vote Leave' group which is why the Guardian were looking at them.
- sctb 9y agoThanks, we’ve updated the link from https://twitter.com/VickerySec/status/978314282097033216 https://twitter.com/VickerySec/status/978314282097033216.
- TAForObvReasons 9y ago> using a custom version of popular code repository Gitlab, located at the web address gitlab.aggregateiq.com. Entering the URL, Gitlab prompts the user to register to see the contents - a free process which simply requires supplying an email address. Once registered, contents of the dozens of separate code repositories operated on the AggregateIQ Gitlab subdomain are entirely downloadable. Is this (anyone can register with an email address) the default mode for a self-hosted gitlab deployment?
- JetSpiegel 9y agoYou can always blacklist or whitelist certain email domains. You will want to make all your repositories private, which makes you whitelist all access.
- adamiscool8 9y agoThis looks like a tool for tracking voter canvassing, hardly a smoking gun of anything? The selective publication and inflammatory language makes me less likely to believe this is of any importance, other than tut-tutting at the server insecurity. The disinformation and jumping to conclusions in the comments of that tweet thread is extraordinary.
- zzzeek 9y agothe issue would be if it were provided by a foreign entity without compensation so that it is essentially a campaign donation, or if a foreign entity is found to be in a strategic role for a US campaign, which violates US election law. See http://abcnews.go.com/Politics/exclusive-cambridge-analytica-accused-violating-us-election-laws/story?id=54010145 http://abcnews.go.com/Politics/exclusive-cambridge-analytica... for a story today breaking on this.
- adamiscool8 9y agoAs I understand it, these aren't foreign apps gifted to a US campaign, this is software from a subcontractor of Cambridge Analytica? Whether CA CEO Nix as a foreign national played a key strategic role is a different, perhaps thornier, issue.
- zzzeek 9y agoThere's a lot more about the kinds of legal trouble this software implies in the EU here: https://gizmodo.com/aggregateiq-created-cambridge-analyticas-election-softw-1824026565 https://gizmodo.com/aggregateiq-created-cambridge-analyticas... this has a lot to do with Brexit.
- adamiscool8 9y agoSure, but the thrust of this data release wasn't exactly "perhaps there was improper coordination of marketing funds between Brexit campaign groups". Frankly, I'm just amazed at the amount of effort that continues to go into locating a smoking gun and a technical devious explanation for Trump/Brexit success beyond "a lot of people really are unhappy with the status quo".
- deleted 9y ago[deleted]
- spdustin 9y agoBased on this tweet†, it seems that Chris downloaded the repos and put them online, encrypted using some of his personal information as a sort of "dead man's switch". † https://twitter.com/VickerySec/status/978056901677146112 https://twitter.com/VickerySec/status/978056901677146112
- deleted 9y ago[deleted]
- aalleavitch 9y agoI'm not sure I understand the point of this. He wants us to open the file but he wants it to be annoying?
- sterlind 9y agoFor posterity: <14-character non-dictionary word>+<My current CA DL number>+<Streetname of my residence during 1st grade> Schema: aaaaaaaaaaaaaa+Annnnnnn+Aaaa Aaaaaaa (a=lower alpha, A=upper alpha, n=numeric) md5 those 36-characters. Hash is the passphrase Driver's license numbers are likely sequential, so the keyspace is likely guessable, or recoverable from credit data breaches. Street name is an easier find, from public records. Since we know that non-dictionary word is 14-characters, and assuming English, entropy should much less than 26^14. anyone willing to give it a spin?
- ExactoKnight 9y agoChris lived in BC, so this would be what his driver's license looked like: http://www.metronews.ca/news/vancouver/2013/02/15/new-b-c-identity-card-combining-msp-number-and-drivers-licence-now-available.html http://www.metronews.ca/news/vancouver/2013/02/15/new-b-c-id... It's an 8 digit number. The keyspace for the streets would be a list of every street in Greater Victoria.
- doomjunky 9y ago"non-dictionary" is 14-characters long
- michaelmcmillan 9y ago
- snowwrestler 9y agoThe description of "Mamba-Jamba" sounds similar to what Harper Reed's team built for Obama's campaign in 2012. In terms of illegality, there would only be a problem if AggregateIQ was not properly compensated for their work by the U.S. political campaigns--i.e. if AggregateIQ improperly provided value to the campaign as "in kind" donations of work. If the campaigns paid AggregateIQ for their work, there's nothing illegal or even improper. Campaigns are allowed to purchase products or services from foreign sources.
- codeulike 9y agoWhat about if 'a foreign entity is found to be in a strategic role for a US campaign'?
- jnbiche 9y ago> Campaigns are allowed to purchase products or services from foreign sources. It's not quite so simple. It's true that US campaigns can purchase products and services from foreign vendors, but only to the extent that those services do not include any management or strategic decision-making services. So you could hire a Canadian firm to make data visualizations for you, but the firm could not tell the US campaign, "we recommend you target group x" based on that visualization. But I agree, based on what is described here, there may be nothing here. Very much unlike certain Cambridge Analytica activities across the pond.
- fortean 9y agoVery informative! Thank you!!!
- chillingeffect 9y agoI'm not picking on or defending anyone, I'm just weary of the last years' worth of articles that keep claiming "smoking guns." Can anyone explain how this is illegal or damning? It appears the biggest reveal is some database/statistical tools. Do they do anything illegal? Is it illegal to outsource a project, especially to an ally like Canada? It seems they were developed as the result of an outsourced project, but does that count for anything? We knew CA was hired to help them win the election. I don't understand how that itself is wrong, legally either.
- ggg9990 9y agoI don't see evidence here of anything more than the application of techniques long-used by advertisers like General Motors and Unilever to the political arena. It may be odious, and may make the world a worse place, but it is not particularly unusual, unexpected, or illegal as far as I know.
- StanislavPetrov 9y agoIf all the "breaking news" about the tactics used by the Trump team in last year's election were limited strictly to "new" tactics used by the Trump crowd, the volume of "news" released would shrink to a tiny fraction of what it is now. Unfortunately, as always, the problem lies with the ignorance of the American people. Its easy to portray underhanded and/or illegal tactics as being somehow unique to the Trump crowd when most people are entirely ignorant about how our political system works (and has worked) for decades. The fact is that campaigns on every level - local, state, and federal - have used data mining techniques, social media platforms, algorithms, and data of all sorts (both foreign and domestic) to influence everyone that possibly could in every way possible. Shining a bright light on any corner of our putrid political system (as is being done in the case of the Trump crowd) will uncover a host of shady, disreputable and/or illegal acts. It doesn't matter what corner you shine the light on or what party you choose to focus on. As someone who didn't vote for Trump, and doesn't support him, that's one of the (many) things I find so disheartening about this entire process. Pretending that Trump is somehow a unique problem that needs to be solved rather just another corrupt politician is to whitewash the rest of the crooks running our government. It isn't an accident that Trump is being portrayed as a unique menace. The levers of power in our government (and their minions in media) are very careful to paint the picture of this being an aberration. They are playing on the myth of "American exceptionalism". That's where the whole Russian-conspiracy nonsense plays in, because naturally, the American people would never vote to reject the establishment in favor of a despicable con-man like Trump unless they were influenced or fooled by evil Russians! If we can just get rid of Trump (and the free and open internet that allowed the evil Russians to influence us), then we can return to the wonderful status quo of the "Liberal Western Order" AKA monopolar US global hegemony, that is great for everyone!
- ExactoKnight 9y agoWhere can we download the codebase. Seriously interested in seeing it.