Bernie Sanders Campaign Blocked From DNC Voter Info After Improper Access (washingtonpost.com)
PolygamousRanchKid writes with news that staffers for the Bernie Sanders campaign improperly viewed the voter data gathered by Hillary Clinton's campaign by exploiting a software error. "The discovery sparked alarm at the DNC, which promptly shut off the Sanders campaign's access to the strategically crucial list of likely Democratic voters. The DNC maintains the master list and rents it to national and state campaigns, which then add their own, proprietary information gathered by field workers and volunteers. Firewalls are supposed to prevent campaigns from viewing data gathered by their rivals." On Wednesday, while the software was being patched, it briefly opened access to all of the restricted voter data. The Sanders campaign fired the staffer responsible for viewing the data, Josh Uretsky. The campaign says their access was simply part of an investigation to determine their own exposure, and blames the vendor (and those who hired it) for improperly securing the data.
Should have scrubbed the data...you know...with a rag or something.
From what the news stories are saying, this firewall-dropping was happening repeatedly. So:
NGP-VAN, the company that stores this data, which is run by an old Clinton hand who worked for them in 1992, the company paid $34,000 by Ready For Hillary, was repeatedly dropping their firewall between the two major Dem campaigns, Clinton and Sanders.
A guy who’s now fired from the Sanders team observed this. They complained once and were given assurances by the company that it was a mistake and wouldn’t happen again. Then it happened again. The guy decided to gauge how deeply the Clinton campaign was able to read into the Sanders campaign, by experimenting to see how much of the Clinton data he could get. That’s a bad call but by information security standards it’s not unthinkable: it’d be called a white hat intrusion, seeing how much of the firewall was down by probing the other side and assuming your own data was revealed exactly the same way. It does matter, but you still have to fire the guy.
One thing we can be sure of is, anything open to ‘stealing’ on the Clinton side was just as open on the Sanders side, literally. It’s the same system and the same firewall, and if the firewall keeps mysteriously going down for no good reason you have to wonder what’s up and more relevantly what’s being made available to those on the other side of the firewall, which might explain why the firewall’s going down like that.
The Sanders people did NOT throw a fit the first time this happened. But this time, the Sanders guy got caught crossing the nonexistent firewall. We have no information at all on whether anybody from the Clinton side was doing the same thing. During that time there WAS NO firewall and the guy wasn’t hacking, he was browsing, as anybody on either side could have done during those windows.
I think that’s accurate so far. The behavior of the firewall is important, whether or not it’s suspicious as a planned exploit of the Sanders data run by Clinton people who are at the DNC and at NGP-VAN.
In response to the Sanders guy browsing over and seeing data (how do they know? Because HE TOLD THEM. The Sanders team were the ones reporting this, that’s part of the story), the DNC suspended access by the Sanders campaign to THEIR OWN DATA at a crucial time. In order to get access back, at least as of this morning, the requirement is for the Sanders campaign to prove it has destroyed all data that it didn’t necessarily even download (remember, Sanders guy claims he was exploring the Clinton system because it would mirror the vulnerability of the Sanders system, and he’s not IN the Clinton system to go and browse the Sanders side to see how much is revealed, but he was IN the Sanders side and could look at the Clinton side and reasonably conclude that his own side was equally compromised)
And social media is blowing the hell up, not unreasonably, because it’s a goddamn hatchet job combined with a kneecapping to yank access by the Bernie campaign to its OWN DATA because a guy from the Bernie campaign passively browsed through a firewall he didn’t himself disable, a firewall run by a company controlled by Clinton partisans which had been going down already for reasons unknown.
The DNC doesn't want Sanders to be their candidate any more than the leadership of the GOP desperately doesn't want Trump to be their candidate - cause they both are afraid it would cost them the election at the Presidential and Senate level (and House seats too). Expect the DNC to do anything it can PR wise to help the expected winner to win. JMHO...
Also, while yammering away about a guy and his exploit through a firewall he himself didn't shut down
The DNC are using this as an excuse to lock the Sanders campaign out of its OWN DATA until whenever.
That data is how we print up lists of voters, addresses, phone numbers, and how we record people's reactions and what they care about. It goes into an NGP-VAN server and will eventually be used by ALL the Dem candidates.
And for 'whatever reason', the Democratic National Committee has decided to tell NGP-VAN to lock the Bernie campaign out of its own data, when we are counting the days until the first primaries.
While arguing about the guy and how guilty he is of data intrusion, try to consider whether it's worth shutting down the whole campaign and locking them out of their computer systems until (unspecified impossible conditions here). Because this is looking like an intra-Democrat coup to coronate Hillary Clinton, and that really helps nobody.
This could easily be shooting the messenger. The fellow responsible for protecting the Sanders campaign's voter data discovered that the DNC's patch had left their voter information database wide open. He starts determining the extent of the problem, which leaves an audit trail. As a result, he gets tossed over the side. Compare this to the commercial world. When you let one of your business customers discover that you've left their trade secrets wide open to their competitors, what happens? I guarantee that the employee who discovered it does not get sacked.
Let's try a somewhat-analogous scenario as a thought exercise:
I find out that on my bank's website, I can easily see my neighbor's bank account by doing some obvious URL manipulation.
I immediately tell the bank that I'm worried about the security of my own account because I know that I could go into anyone else's.
The bank locks me, and only me, from accessing any bank accounts, including my own.
That response makes no sense. The only proper response would be to revoke ALL access to the bank's website until such time as the security hole can be confirmed fixed. Otherwise, the implied message is that you should NEVER tell the bank that they have a potential problem.
I just wonder whether this was actually a story of extreme incompetence or extreme corruption.
If it's not, why haven't they unlocked the Bernie data yet?
Pretty easy to look like a conspiracy to stop the Bern, when you 'suspend' the campaign and lock the guy out of his own data files. Do you think Hillary Clinton would have been locked out of access to her campaign's data files?
The real question is, for how long. It's an important time, just weeks before the first primaries, and every day counts. This is one day that Bernie's people can't work on getting out the vote, because their systems are down.
Well, not down: they're just not allowed to have them. Because it's totally democratic to handicap one entire campaign for a day or days or who knows HOW long, while allowing the other campaign to carry on canvassing.
I smell a double agent.
The Powers That Be have stacked the deck against Bernie in every way imaginable. DNC chairman is a former Clinton campaign manager. They cut the number of primary debates because they learned from focus groups that the more people see and learn about Hillary, less they like her, while the opposite was true for Bernie -- his favorability went up the more people learned about him.
Not only that, the few remaining debates have been scheduled to attracted as little viewership as possible (Saturday and Sunday nights, opposite major sporting events, Xmas shopping season, etc)
This latest flap is just a curt reminder for Bernie that he's just here as a prop and that he needs to know his place.
[I have no interest in voting for a socialist as President. Just not my politics. Also there is also NO WAY I'd vote for Hillary Clinton. NO WAY. But...]
After all the political snafus and screw-ups that the Democrats have been involved with in the past 30 years, one thing is clear: NO ONE ever gets fired. Ever.
So, if Bernie Sanders helmed a campaign that FIRED someone--I humbly submit that if you're trying to decide between the two, and don't want more of the same from this f'd up political system--Bernie should DEFINITELY get your vote.
Scott
"Hokey religions and ancient weapons are no match for a good blaster at your side, kid."