Capitol View®

Fallout

Striking all previous and subbing Scheck's story.

GOP peers into voters' data with CD

* * *

[image]

Talking with Mark Drake at the Republican Party this morning, it's probably going to say that it was always the company's intention to secure the data at the time the CD was released. That the CD that was provided to the media at Monday's news conference was a BETA version and the "security" will be installed -- and was intended to be installed -- before the program will be sent out.

The Party hopes to get the CDs from the vendor on Friday and hopes to mail them out on Friday.

Here's what happened as has been explained to me by the folks who took the program apart.

CH Consulting used a program called DotNetNuke at the Internet data repository for their survey results. But they neglected to secure their DotNetNuke site. We don't think this was intentional, especially since the entire mailing list with the assigned codes was posted.

As for securing the CD, I haven't seen the final copy yet, but the security problem we found wasn't on the CD, it was the server.

The Republican Party is not happy with me and I understand their frustration. I also understand the frustration of the people who wanted -- desperately -- to get the destination IP and I understand it sounded last night like I was saying "ha, ha, I know something you don't."

I accept that and there's nothing I can do about it except to point out I don't think CH Consulting needed to be put out of business today by denial-of-service attacks. Nor can I legitimately talk about the importance of protecting data, and then give you the address of where you can get it.

As bad a day as the Republican Party and CH Consulting may (or may not) be having today, believe me, it could have been a lot worse. Any nefarious individual could have mined the information.

Some of the blogs I read last night seemed to suggest that when you answer a question, you should know that information is being sent somewhere. And when you go to a Web site and click SUBMIT, I think that's reasonable.

But this is a Flash presentation about a political issue featuring cool video. And in Flash, interactivity is accomplished with the presentation. If you, for example, were to answer that you are a "sometimes Republican," there's actually every expectation by the user that this could lead to a somewhat, shall we say, softer video than if you had selected another choice. So saying "people should just know" their answers are being sent isn't necessarily true.

And in that case, all of that could be eliminated as a concern, just by telling them in the first place. The subject didn't come up at Monday's news conference for a simple reason: nobody asked.

We don't yet know what the "final CD" is going to have on it or what the wording is going to be to make clear to the participant what and how the data is being used. The Republican Party spokesman said he would "look into it."

Sometimes the best response is "whoops." And move on.

Here let me show you. You know how I said the server had the questions the presentation asked and we could've changed them. It's true the questions are on the server, but they're in the Flash document as text too. So I was wrong about that. Whoops.

(Update 1:04 p.m.) Here's the packaging. Methinks this will boil down to a question of what "interactivity" means.

(Update 1:15 p.m.) GOP says this is draft.

[image]

[image]

[image]

[image]

[image]