Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

FourScore

(9,704 posts)
Mon Mar 28, 2016, 12:41 PM Mar 2016

Anonymous has released a report pertaining to alleged hacking of the AZ election

(If interested, please help to keep this kicked for wider viewership. It is getting lots of recs, but dropping like a stone. I find it particularly important that voters in NY and CA be on the alert and check out their voter registration. Thank you.)

Pretty damning stuff. Somebody definitely hacked the election, although, unfortunately, no concrete proof. I believe a full FBI investigation needs to be instigated, and Bernie should sue the state of AZ.

https://anonymousinvestigationsblog.wordpress.com/2016/03/26/anonymous-report-was-arizonas-voter-registration-database-hacked/

An excerpt:

Concerned that we might only be hearing one side of the story, Anonymous has used our very best online research methods in an attempt to discover what the reach of this potentially rather substantial scandal may be. We searched deeply on multiple social media sites, using a wide variety of search terms. We looked into every news story we could reasonably find reporting on this phenomenon. We engaged directly with a few Republicans and Hillary Clinton supporters on Twitter. We tried various general Google searches. We were looking very closely at specific reports where individuals said either that they or someone they knew directly (a relative, friend, or person they were at the polls with) had experienced having their voter registration changed without their knowledge. Where we were able to have direct contact with Democrats making such claims, we asked whether they supported Sanders or Clinton. While these results are far from comprehensive (there are likely well over a thousand of these little reports out there), we have done our best to get an accurate sampling. As reported on Twitter, these are our results:

?w=840

SNIP

...Arizona’s Secretary of State website stores its data in SQL databases. Properly maintained (a big question given Arizona’s constant penny wise, pound foolish budgeting), SQL databases can be defended against hackers with a moderate or lesser skill level. But SQL databases in general have been known to have a particular, structural flaw for decades. SQL Injection, where random data is entered into a data entry field, can trigger an SQL database to give up most or all of its goods to an unauthorized user. SQL Injection is nearly always the first line of attack a hacker learns, and at its most basic level, it can literally be taught to a toddler . A Vice article from November is entitled “The History of SQL Injection, the Hack That Will Never Go Away.” It notes that SQL Injection repeatedly takes the number one spot in Open Web Application Security Project Foundation’s triennial report on threats that websites face...

SNIP

...At this point, it is clear that some of the cases, like Ms. Robertson’s, stem from ridiculous new procedures put in place by Arizona’s Secretary of State and Motor Vehicles Division. That said, other cases like Bianca’s, clearly do not fit that pattern, and the apparent overwhelming impact on Sanders supporters cannot be explained by a glitch that should have hit all parties and candidate supporters in roughly equal numbers.

The numbers in Pima County and Maricopa are particularly glaring. Reports of five-inch thick piles of provisional ballots and up to 2/3 of ballots in a particular voting location in Pima are quite suspicious. Numbers Anonymous is using internally to monitor election results across the country suggest that Sanders should have won student rich, and reliably progressive Pima county comfortably. The lack of polling stations alone in Maricopa County cannot explain how Phoenix, with a Democratic Mayor, could see Republicans show up at the polls on election day to the tune of around 80,000 voters, while Democrats cast a paltry 33,000 votes in Maricopa County on election day...

SNIP

...In that vein, we should note that there are now likewise dozens and dozens of reports of Sanders supporters in places like Pennsylvania and New York, with upcoming closed primaries, finding that their own registrations have been switched. One such report arrived in our inbox on Friday morning, the final day for new voter registrations in New York. The emailer told us that the website for New York was going up and down intermittently. We asked what link they were using. When we checked it, our Tor Browser informed us that the website was insecure, presenting an invalid encryption certificate.

link to Anonymous's AZ switched database:

https://docs.zoho.com/sheet/published.do?rid=b7lrg2140d3169d644b8082fea3207bbb73c5


These are glaring results.

Can also follow on twitter here: https://twitter.com/HiveComm/with_replies

EDIT: This was their initial release on March 26:

:large
48 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Anonymous has released a report pertaining to alleged hacking of the AZ election (Original Post) FourScore Mar 2016 OP
This needs to be front page news, and there should be a new primary run in Arizona peacebird Mar 2016 #1
everyone repeat after me, "there will never be a primary do-over" TheDormouse Mar 2016 #9
Why is the Democratic Party so undemocratic? DamnYankeeInHouston Mar 2016 #2
Looks to me like there is massive election tampering/fraud going on throughout the country. Snotcicles Mar 2016 #3
K&R CharlotteVale Mar 2016 #4
Which candidate does this tactic benefit the most? Dont call me Shirley Mar 2016 #5
Which candidate does it ALWAYS benefit. bvar22 Apr 2016 #47
Yup, just a coinkydink... Dont call me Shirley Apr 2016 #48
kicking for CA and NY voters!!! n/t FourScore Mar 2016 #6
K&R nt avebury Mar 2016 #7
Kick. n/t lumberjack_jeff Mar 2016 #8
K and R for visibility bbgrunt Mar 2016 #10
K/R for signal boost. VulgarPoet Mar 2016 #11
lol, every state is either a Bernie win or a Clinton consiracy to steal the vote geek tragedy Mar 2016 #12
Sad. You can't possibly think this is okay. FourScore Mar 2016 #13
Heh, I've noticed the same thing. It turns out Bernie has actually won every state! nt BreakfastClub Mar 2016 #31
kick Viva_La_Revolution Mar 2016 #14
K & R Duppers Mar 2016 #15
CA Voter PCPrincess Mar 2016 #16
In my town, I called the county elections board to verify. I'm in NY. FourScore Mar 2016 #18
You can check online noamnety Mar 2016 #20
CA here too Chezboo Mar 2016 #25
I could take this way more seriously if... hootinholler Mar 2016 #17
Please explain for those of us who are not as tech savvy as you. n/t FourScore Mar 2016 #19
Well, how much time you got? hootinholler Mar 2016 #21
so far they are just collecting public reports questionseverything Mar 2016 #24
K&R Paka Mar 2016 #22
K&R amborin Mar 2016 #23
#ReVoteArizona AzDar Mar 2016 #26
K&R! Pastiche423 Mar 2016 #27
K&R pugetres Mar 2016 #28
This is not credible! fun n serious Mar 2016 #29
They don't know anything....don't read it! The MSM is the best source for this type of thing, n/t blueintelligentsia Mar 2016 #30
K & R KT2000 Mar 2016 #32
1. anyone can post something like that. Does it benefit republicans to divide our party? shadowandblossom Mar 2016 #33
looks like 'someone' puts up fake websites for registration, voting info? then takes them down fast. Sunlei Mar 2016 #34
There's just a lot of suppositions from someone at Anonymous who thinks he's a statistician. randome Mar 2016 #35
doesn't take rocket scientist to find a 100,000 fewer democratic votes alarming questionseverything Mar 2016 #37
KnR Myrina Mar 2016 #36
Kicked. Thanks. mariawr Mar 2016 #38
I wouldn't put too much stock in anything "Anonymous" puts out. "They" also BreakfastClub Mar 2016 #39
Billions for hi tech surveillance felix_numinous Mar 2016 #40
check your voter registration and grab a screenshot hopemountain Mar 2016 #41
Kick Zira Apr 2016 #42
KnR! Dont call me Shirley Apr 2016 #43
Kick... peacebird Apr 2016 #44
Kick azmom Apr 2016 #45
kick aspirant Apr 2016 #46

TheDormouse

(1,168 posts)
9. everyone repeat after me, "there will never be a primary do-over"
Mon Mar 28, 2016, 02:14 PM
Mar 2016

We Americans constantly criticize other countries for their fraudulent, rigged, and failed elections.
We turn a blind eye to our own.
see Bush v Gore

DamnYankeeInHouston

(1,365 posts)
2. Why is the Democratic Party so undemocratic?
Mon Mar 28, 2016, 12:52 PM
Mar 2016

Hillary will sacrifice our party and our form of government to get elected. This stuff would never be noticed in the past. Hooray for the Internet.

 

Snotcicles

(9,089 posts)
3. Looks to me like there is massive election tampering/fraud going on throughout the country.
Mon Mar 28, 2016, 12:54 PM
Mar 2016

And it looks like it can be done from anywhere into many of these systems.

Dont call me Shirley

(10,998 posts)
48. Yup, just a coinkydink...
Thu Apr 21, 2016, 08:16 PM
Apr 2016


The accusations of CT or "incompetence" or "it was just an honest mistake" by the other side are something to behold.
 

geek tragedy

(68,868 posts)
12. lol, every state is either a Bernie win or a Clinton consiracy to steal the vote
Mon Mar 28, 2016, 03:36 PM
Mar 2016

Some people think about politics like it's a professional wrestling match--the bad guys only win if they cheat.

lol

PCPrincess

(68 posts)
16. CA Voter
Mon Mar 28, 2016, 05:29 PM
Mar 2016

I have recommended my first post! I've lurked for a long while, joined to finally leave my opinion a little while back after leaving HuffPo sometime back due to forced use of Facebook.

This needs to be seen. Although, does anyone know what steps are taken to check one's current registration in CA?

FourScore

(9,704 posts)
18. In my town, I called the county elections board to verify. I'm in NY.
Mon Mar 28, 2016, 06:10 PM
Mar 2016

Just google "voter registration" and the name of your town. The info should come up with who to call.

Welcome to DU, PCPrincess!!! I feel honored that my post was your first recommend!



Chezboo

(230 posts)
25. CA here too
Tue Mar 29, 2016, 01:41 AM
Mar 2016

It can be done with a phone call. We're being told to keep checking the status too, with all the fraud that's happening around the country. Many Sanders voters in NY are finding out too late their status has been changed and they are being told they can't vote in the primary.


Check Status of Your Voter Registration
http://www.sos.ca.gov/elections/registration-status/


hootinholler

(26,449 posts)
17. I could take this way more seriously if...
Mon Mar 28, 2016, 05:51 PM
Mar 2016

The person writing it didn't screw the pooch on the technical stuff.

hootinholler

(26,449 posts)
21. Well, how much time you got?
Mon Mar 28, 2016, 07:35 PM
Mar 2016

I'll try to be succinct and not very technical to give you a 30,000 foot level view of some of the problems I see in the article.

Let's start by admitting that I didn't visit the link and when I replied I was going by your excerpt, and the intuitive red flags I felt when I read it. That said, given the context, it's not as bad as I thought, but I still have problems with it. If in fact there was a successful SQL injection then it is a given that there are also serious problems with the AZ systems in that it is such a fundamental and well known and easily defended attack, it should never occur as we say, in the wild.


Hacked? Arizona’s SQL Vulnerability

Anonymous asked three of our veteran hackers, of varying skill levels, to scan Arizona’s Secretary of State website for vulnerabilities, while insisting that nothing illegal be done along the way. One hacker had health related issues that prevented her or him from doing a vulnerability scan. Another hacker was quite busy, but made two or three attempts. In each case, the IP associated with their vulnerability scan was immediately blocked by the website. One of Anonymous’ best hackers, however, discovered a massive vulnerability in less than a minute that we feel is nearly impossible to defend against a skilled and determined attacker.


UGH, that last sentence. Who wrote this, her Boyfriend or his girlfriend or any other way you want to combine them? The attack that succeeded is a fundamental in defense against the dark arts. Nothing was mentioned as to what access was gained and etc. What was this massive vulnerability? What access was obtained from it?


Arizona’s Secretary of State website stores its data in SQL databases. Properly maintained (a big question given Arizona’s constant penny wise, pound foolish budgeting), SQL databases can be defended against hackers with a moderate or lesser skill level. But SQL databases in general have been known to have a particular, structural flaw for decades. SQL Injection, where random data is entered into a data entry field, can trigger an SQL database to give up most or all of its goods to an unauthorized user. SQL Injection is nearly always the first line of attack a hacker learns, and at its most basic level, it can literally be taught to a toddler . A Vice article from November is entitled “The History of SQL Injection, the Hack That Will Never Go Away.” It notes that SQL Injection repeatedly takes the number one spot in Open Web Application Security Project Foundation’s triennial report on threats that websites face.


What a surprise! The Az database is SQL compliant. SQL is a standard that specifies what functionality must be available and provides a standards based Structured Query Language (SQL) which is used to obtain data from a compliant database.

The claim: "random data is entered into a data entry field, can trigger an SQL database to give up most or all of its goods is bogus on its face. Random data isn't used in a SQL injection, rather a SQL clause or command is used. This couldn't be farther from being random data. To work it has to be crafted.

Even if you are successful in making the injection there remains the problems in obtaining the query results. Attempts at SQL injection end in many different ways depending on the systems involved and I really can't say much more without more specifics. I will note that per the above excerpts one of their "best hackers" brought to bear a technique they claim "can literally be taught to a toddler" which I sort of have to stop for a minute and snicker at.


NoSQL or non-SQL databases have been around since the 1960’s, gained popularity beginning in 1998 in the initial move to greater web security, and are used by banks, major social media sites, and web giants like Google and Amazon to process and protect big data.


This has absolutely nothing to do with the issue at hand. I'll leave the fact checks here as an exercise for the interested reader. Let's just say I consider this claim to be very dubious. Especially in the big data field which I have a bit of experience in.


Anonymous may release an addendum to this report at a later time outlining specific SQL related vulnerabilities for the Arizona Secretary of State’s voter related websites.


I look forward to the specifics of this amazing feat of crackerdom. It certainly wasn't a hack.

 

fun n serious

(4,451 posts)
29. This is not credible!
Tue Mar 29, 2016, 02:16 AM
Mar 2016

Go to the twitter link and take a HARD look at the people saying this crap. They're all fake PAID trolls. Go look for yourself. So Obvious.

shadowandblossom

(718 posts)
33. 1. anyone can post something like that. Does it benefit republicans to divide our party?
Tue Mar 29, 2016, 03:42 AM
Mar 2016

2. how would they know who they are voting for in advance? I'm registered. There is no paperwork on who I'm voting for.

3. why have the republicans who have been working against Clinton, suddenly decided locally to support her? You see Sanders as the stronger candidate, maybe that's correct, I don't think so, but don't know, but as for republicans, they see Clinton that way. They don't want to deal with her. Why are they suddenly supporting her in this theory? How does that serve them. Please think critically.

I'm not trying to criticize you but it's worthless to jump on every explanation that favors your desires. Looking for the simplest explanation will get you better results. Please practice basic common sense before conspiracy theory, and look at what's going on locally first. There's adequate explanation there.

Sunlei

(22,651 posts)
34. looks like 'someone' puts up fake websites for registration, voting info? then takes them down fast.
Tue Mar 29, 2016, 09:00 AM
Mar 2016

fake website only needs to be up for a short time to be effective.

 

randome

(34,845 posts)
35. There's just a lot of suppositions from someone at Anonymous who thinks he's a statistician.
Tue Mar 29, 2016, 09:06 AM
Mar 2016

An SQL injection explanation and 'invalid encryption certificates' sounds like a normal day at the office, really. They didn't find anything and until someone does, it's safe to assume that the GOP fucked everything up with their usual fealty to screwing over voters.
[hr][font color="blue"][center]No squirrels were harmed in the making of this post. Yet.[/center][/font][hr]

questionseverything

(9,654 posts)
37. doesn't take rocket scientist to find a 100,000 fewer democratic votes alarming
Tue Mar 29, 2016, 11:25 AM
Mar 2016

The numbers in Pima County and Maricopa are particularly glaring. Reports of five-inch thick piles of provisional ballots and up to 2/3 of ballots in a particular voting location in Pima are quite suspicious. Numbers Anonymous is using internally to monitor election results across the country suggest that Sanders should have won student rich, and reliably progressive Pima county comfortably. The lack of polling stations alone in Maricopa County cannot explain how Phoenix, with a Democratic Mayor, could see Republicans show up at the polls on election day to the tune of around 80,000 voters, while Democrats cast a paltry 33,000 votes in Maricopa County on election day.

While Early Voting is increasing in Arizona with each election, we are rather skeptical of the idea that Maricopa had nearly 100,000 fewer Democrats voting in-person over against 2008’s primary between Clinton and Obama.

felix_numinous

(5,198 posts)
40. Billions for hi tech surveillance
Tue Mar 29, 2016, 12:45 PM
Mar 2016

and weapons manufacturing, and we get these monkey business black boxes to vote with.

A standardized system with paper receipts is possible. It needs to be set up to assure democracy if we don't want to continue being a banana republic.

hopemountain

(3,919 posts)
41. check your voter registration and grab a screenshot
Thu Mar 31, 2016, 02:12 AM
Mar 2016

or printout. according to "claudia" in the article, her registration was correct the day before the primary - but when she got to the polling site, her designated party had been changed.

according to anonymous, the online voter registration checker is vulnerable to hacking. the voter info is provided by the states as required by law as "public information" - but the site allows one to change the registration or cancel it.

Latest Discussions»Retired Forums»2016 Postmortem»Anonymous has released a ...