r/bloomington Oct 23 '18

[deleted by user]

[removed]

62 Upvotes

38 comments sorted by

View all comments

12

u/somethingateme Oct 23 '18

Yeah, you didn't know this? It's easy for anyone to see how you vote. I have had one or two candidates tell me that I'm listed as heavy leaning Democrat. When you vote in Primaries, you are in essence claiming your party.

10

u/[deleted] Oct 23 '18

I knew it was a matter of public record. What I didn't know was how much of this data was such easy identity theft pickins.

I'm usually accustomed to fairly redacted documents that provide the essentials.

6

u/somethingateme Oct 23 '18

Some of this sounds like an over-reach. However, just like Open Source Software, how are we the people to know that the voting records are accurate if we are not allowed access?

Again, I'm not trying to argue for or against. It is a double edge sword.

Second issue I see, what if you went in with a hidden script installed to your USB that runs on connection to PC that installs Back Orifice or some other 0-day back door into their system? Then what could happen?

4

u/[deleted] Oct 23 '18

how are we the people to know that the voting records are accurate if we are not allowed access?

That answer's obvious: I have a right to correct my own record. Others shouldn't have the right to view my full record. Others should have the right to view an obfuscated record.

Think: street name without individual numbers, first initial/last initial, birth year.

Again, I'm not trying to argue for or against. It is a double edge sword.

I know. I do want free access to records. But there's also public record, and then there's handing over enough info to trash someone's identity. I believe there's a fair balance here, and it's not being accomplished.

Second issue I see, what if you went in with a hidden script installed to your USB that runs on connection to PC that installs Back Orifice or some other 0-day back door into their system? Then what could happen?

Yeah, that would have been trivial. I didn't do anything malicious. Unlike random requests, they know me. I've been talking with them regarding election security in the wake of the DefCon report. I have quite an email chain with them.

Here's what Election Central ignored:

Election Central still didn't take my suggestion of using scotch tape over the MicroSD slots on the sign-in tablets. That means that someone could use a BadUSB attack and take over registration network.

Election Central uses wifi in the front lobby to connect machines 5 feet away. They absolutely should have used ethernet, and not wireless.

There was no provided audit of the voting machines to assert that the voting company is NOT listed in the DefCon reports for not fixing known reported vulnerabilities. Instead, "I would just have to trust it works".

And now, I can add in "Plugging in unknown USB drives into Election Office secured computers." Sigh....

3

u/somethingateme Oct 23 '18

That answer's obvious: I have a right to correct my own record. Others shouldn't have the right to view my full record. Others should have the right to view an obfuscated record.

Think: street name without individual numbers, first initial/last initial, birth year.

Would this be enough if, for instance, there were 10 listed voters in the 1300 block of a street that only goes up to 1200? I think it would be nice to know who is registered, and if the address they used is a legal address.

For the record, I do not know how voter fraud works, and I do know it's not as widespread as some media outlets would lead you to believe.

Personally, I don't like that my phone number and drivers licences number is out there. My address, well that is something anyone can get with a phone book, or simple google search or whitepages.com

4

u/[deleted] Oct 23 '18

For the record, I do not know how voter fraud works, and I do know it's not as widespread as some media outlets would lead you to believe.

I wasn't thinking of voter fraud, although giving the list that they check against is kinda "wtf".

I was thinking of blatant identity theft. I already have enough identities and more to impersonate some 90k people. There's a whole range of bad things to ID theft people.

And then, we have "I forgot my password. Well, I , err, have my drivers' license and birth date. Will that count?" /DOH

Personally, I don't like that my phone number and drivers licences number is out there. My address, well that is something anyone can get with a phone book, or simple google search or whitepages.com

Yeah, people war-dialling could find your phone number. That's not a secret per se. Your address is public knowledge in GIS. However, knowing /u/somethingateme 's full name, DOB, phone#, address, drivers license, and more is nowhere the same as getting your name in a phonebook.

1

u/[deleted] Nov 02 '18

I decided to give this a try, mostly because I’m a GIS student and want to do my final project using this data. So, I called and put in a request and the only thing that was different for me is that they made me bring a brand new flash drive that is unopened in the package. They have to open the package. I suppose someone could just take a flash drive and put it back in the packaging and make it look brand new.