Los Angeles Times

Voters’ personal data left exposed for days

Security experts say it is ‘staggering,’ and too common, that such a detailed political file would be vulnerable.

- By Evan Halper and Paresh Dave

WASHINGTON — To any nefarious hackers looking for data that could be used to sway elections or steal Americans’ identities, the file compiled by a GOP digital firm called Deep Root Analytics offered all manner of possibilit­ies.

There in one place was detailed personal informatio­n about almost every voter in America. It was a collection of some 9.5 billion data points that helped the firm assess not only how those Americans would probably vote, but their projected political preference­s.

In some cases, the data collectors had scoured people’s histories on Reddit, the social media platform, to match voting history with social media use, and wellinform­ed prediction­s were made about where each voter would stand on issues as personal as abortion and stem cell research.

It’s the kind of sensitive informatio­n that, if a bank or a big-box retailer or almost any other corporatio­n had failed to protect it, would have triggered major trouble with regulators. But there it sat on the Internet, without so much as a password to guard it, for 12 days.

Luckily for the Republican Party and Deep Root, an Arlington, Va.-based firm that handles data management and analysis for the

party, it was a cybersecur­ity consultant who came across the treasure-trove of political data this month, not a foreign agent. There is no indication that the database had been tapped by any other unauthoriz­ed parties while it was unprotecte­d.

But the exposure of the data, which some are describing as the largest leak of voter informatio­n in history, is a jolting reminder of how deeply the political parties are probing into the lives of voters and how vulnerable the informatio­n they are compiling is to theft.

The Deep Root incident is the latest in a series of such problems with political data, the most infamous being the case of the Russian hack of the Democratic National Committee.

As cybersecur­ity experts sound an increasing­ly loud alarm about the potential consequenc­es, the lapses keep happening — often with nobody held accountabl­e for them.

“This is a catalog of human lives, with intrinsic details,” said Mike Baukes, chief executive of UpGuard, the Mountain View, Calif., firm that came across the file during a routine scan of cloud systems.

“Every voter in America is potentiall­y in there. The scale of it is just staggering, and the fact that it was left wide open is wholly irresponsi­ble .... This is happening all the time. We are continuall­y finding these things. It is just staggering.”

Privacy experts were skeptical that political operatives would change their ways after the latest incident.

“The state of security for massive data sets is so incredibly poor despite a daily drumbeat of data breached,” said Timothy Sparapani, a former director of public policy for Facebook who is now a data privacy consultant at the firm SPQR Strategies, based in Washington. “It is shocking. It is embarrassi­ng. People ought to lose their jobs.”

Sparapani said if the culprit had been a private firm, it would be subjected to punitive actions by attorneys general, consumer lawsuits and big fines from regulators. But political operations face no such repercussi­ons.

“As a voter, you are left with almost no recourse because our laws have not caught up to the massive computing power, which is readily available to gather enormous data sets and make them searchable at the click of a button,” he said. “The breadth and depth of data collection by these companies is not well understood. If it were, I think the average voter would be frightened.”

UpGuard was able to access the file merely by guessing a Web address. It alerted Deep Root as well as federal authoritie­s.

Deep Root apologized in a statement, but also suggested the incident had been overblown.

The data file “is our proprietar­y analysis to help inform local-television ad buying,” the statement said. It noted that much of the voter informatio­n the analysis is built on is “readily provided by state government offices.” The firm said it had put security procedures in place to prevent future leaks.

Other digital strategist­s warned, however, that the failure to protect such detailed informatio­n not only raised major privacy and security concerns, but also may have tipped off political adversarie­s to the inner workings of the Republican Party’s closely guarded digital strategy.

The GOP contracted with Deep Root during the presidenti­al campaign. The firm’s co-founder, Alex Lundry, led the data efforts of Republican nominee Mitt Romney in 2012 and then worked for the unsuccessf­ul presidenti­al campaign of former Florida Gov. Jeb Bush last year.

Republican officials said the data belonging to the party that was exposed was limited to very basic informatio­n about voters, such as their party registrati­on. They said none of the GOP’s sensitive strategic data was exposed. The party has suspended work with the firm pending an investigat­ion by Deep Root into security procedures.

The failure by Deep Root to protect its massive database was particular­ly troubling to some advocates at a time when Congress is investigat­ing how Russia exploited data vulnerabil­ities to meddle in last year’s presidenti­al election.

“This is data used for opinion manipulati­on,” said Marc Rotenberg, executive director of the nonprofit research group Electronic Privacy Informatio­n Center, based in Washington. “It needs to be regulated. And there needs to be consequenc­e for breaches. We have a major problem in this country with data security, and it’s getting worse.” The foundation wants Congress to hold hearings on political data security.

But holding political parties and contractor­s accountabl­e for their data practices has proved tricky.

David Berger, an attorney with the Bay Area-based firm Girard Gibbs who has represente­d consumers affected by data breaches at Anthem and Home Depot, said part of the problem was voters were not demanding changes loudly enough.

When a retail company fails to protect the privacy of its customers, Berger said, the company suffers and lawmakers hear about it from the victims.

“When people see Deep Root, they are not going to necessaril­y associate that with the [Republican Party] or anything else,” he said.

“If your average American knew the amounts of data and profiling that is already put together by these companies about every single one of us, people would be very concerned. But there’s no face here, and they try to keep quiet.”

Newspapers in English

Newspapers from United States