Fake 'Russian Hack' Of Public Michigan Voter Rolls Gets Absurdly Overhyped On The Interwebs
from the good-old-fashioned-freak-out dept
On Tuesday morning a story began making the rounds indicating that Russian hackers had somehow managed to hack into Michigan's election systems, gaining access to a treasure trove of voter data. Russian newspaper Kommersant was quick to proclaim that nearly every voter in Michigan -- and a number of voters in additional states -- had had their personal information compromised. The report was quickly parroted by other outlets including the Riga-based online newspaper Meduza, which insisted that the breach was simply massive:
"Russian hackers have leaked the personal data of nearly every voter in Michigan (7.6 million of the state’s 7.8 million voters), as well as the information of another million voters in Arkansas, Connecticut, North Carolina, and Florida, according to the newspaper Kommersant. The data recently appeared on a Darknet forum, posted by a user nicknamed “Gorka9.” The information was current as of March 2020 and a source at the security firm “InfoWatch” confirmed to Kommersant that the data is authentic.
For each American voter targeted in the leak, the following information is now available: full name, date of birth, sex, date of registration, home address, zip code, email address, voter ID number, and polling station number."
The reports also insisted that hackers were then exploiting the U.S. Rewards for Justice Program to get paid for bringing the hack to the attention of the U.S. government. From there, the story quickly ballooned across Twitter, thanks in part to journalists:
The problem? This data was already either widely available, or available via a basic Freedom of Information Act (FOIA) request. Much like the recent hysteria over TikTok (in which many people act as if banning the app prohibits China from accessing U.S. user data that's available pretty much everywhere thanks to our crap privacy and security standards), people that actually study or report on infosec for a living were then forced to try and do damage control by adding useful context. That context being that the ease in which anybody could obtain this data means it doesn't actually hold much value:
This sort of data is generally very available and not of much value.
From 2016, when people were hyped about back then: Voter Records Get Hacked a Lot, And You Can Just Buy Them Anyway https://t.co/HQ6ncfUvai
Election security coverage can be really dumbhttps://t.co/E4h6CNFL8d
— Joseph Cox (@josephfcox) September 1, 2020
The disconnect between those that cover infosec for a living, and those who engage in security or privacy tourism on Twitter was a bit jarring:
Michigan's voter records were not hacked. A Michigan voters file was posted on the site "raidforums" by user Gorka9. The file itself, available at https://t.co/og5TRC2mbo, contains only publicly available information from Michigan's qualified voter file. Thread: pic.twitter.com/tGVdxbVjzk
— Jack Cable (@jackhcable) September 1, 2020
The one truly interesting bit, that the U.S. tip line was being exploited to pay hackers for directing them to publicly accessible data, is far more interesting and will require additional reporting. Meanwhile, the Michigan Department of State was forced to issue a statement noting it was never hacked, and urging internet users to exercise a little better judgement in terms of what they choose to hyperventilate over:
— Michigan Department of State (@MichSoS) September 1, 2020
All told, just another day on the internet. Granted, our non-transparent and dodgy election security systems in many states still pose a genuine threat to U.S. security. A threat that's not being fully addressed due to the fact we seem to have idiotically made basic election security a partisan issue. But freaking out over inflated claims of hacks that never happened sure as hell isn't helping to fix that problem.
Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.
Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.
While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.
–The Techdirt Team
Filed Under: fact checking, hacks, journalism, michigan, russia, voter rolls
Reader Comments
Subscribe: RSS
View by: Time | Thread
Voter rolls
In general, voter rolls have always been available to campaigns for campaigning purposes.
https://www.ncsl.org/research/elections-and-campaigns/access-to-and-use-of-voter-registration-lists .aspx
[ link to this | view in chronology ]
Call me Captain Obvious but...
I'm pretty sure fixing the problem was never the intent.
[ link to this | view in chronology ]
Welcome to Florida
Here's Florida's voter rolls, last 8 years including the latest. Available to anyone. I'm in there somewhere.
https://flvoters.com/downloads.html
[ link to this | view in chronology ]
Re: Welcome to Florida
YOU ARE SOOOOOOOO REPORTED.
[ link to this | view in chronology ]
Re: Welcome to Florida
Damn it, you hacked Florida's voter rolls? What a horrible thing to do.
Of course, with "hacking" I'm using the new US definition of the word which apparently means "Read it off a government-issued publication".
[ link to this | view in chronology ]
Real reason
Dammit, 5G strikes again!
[ link to this | view in chronology ]
So this is what "hacking" means now?
I guess that means I'm currently hacking this Techdirt page...
[ link to this | view in chronology ]
Disinformation Abounds
Just gonna leave this here:
Julia Ioffe is a Russian-born American journalist who covers national security and foreign policy topics for GQ. Her articles have appeared in The Washington Post, The New York Times, The New Yorker, Foreign Policy, Forbes, Bloomberg Businessweek, The New Republic, Politico, and The Atlantic.
She should have known better.
[ link to this | view in chronology ]
What wonderous times we live in, that having a dedicated email address just to deal with misinformation is a thing.
[ link to this | view in chronology ]