Feeds

Pennsylvania officials bail after voter reg site springs a leak

Flaw exposes sensitive user data

New hybrid storage solutions

Pennsylvania officials pulled the plug on a voter registration website after a user posted online instructions that showed the site was exposing sensitive information about people who used the service.

The flaw with the state's Voter Registration Application made it possible for anyone on the net to view registration forms that had been completed online. The forms contained a bevy of personal information, including the voter's name, date of birth, driver's license number and political party affiliation, ComputerWorld reports.

The revelation comes a month before the state holds a high-profile presidential primary that could determine who wins the nomination for the Democratic candidate for US President. Users who tried visiting the site on Wednesday got a message that it was not available.

A user with the handle mtg169 first disclosed the leak in on Digg. The post showed that it was possible to view the PDF applications of voters my modifying request parameter included in the URL of the voter registration site. Simply adding or subtracting numbers was all it took to view a different application.

"Valid IDs appear to be working from 50000 and up to 58500+," mtg169 wrote. "Very bad PA ... very very bad!" PA is the US postal abbreviation for Pennsylvania.

In a comment following the post, mtg169 added that IDs in the 20,000 range also exposed applications.

The breach represents a serious blow to the privacy of people who may have used the service. The instructions on Digg had been up for hours before the service was unplugged, and there's no telling how long miscreants had been using the flaw to take a peak at voters' personal details. ®

If you have a tip about the leakage of personal information, please contact your reporter here.

Providing a secure and efficient Helpdesk

More from The Register

next story
Net neutrality protestors slam the brakes on their OWN websites
Sites link up to protest slow lanes by bogging down pages
Found inside ISIS terror chap's laptop: CELINE DION tunes
REPORT: Stash of terrorist material found in Syria Dell box
Uber alles-holes, claims lawsuit: Taxi biz sued by blind passengers
Sueball claims blind passengers ditched, guide dogs abused
Drag queens: Oh, don't be so bitchy, Facebook! Let us use our stage names
Handbags at dawn over free content ad network's ID policy
Italy's High Court orders HP to refund punter for putting Windows on PC
Top beaks slam bundled OS as 'commercial policy of forced distribution'
Show us your Five-Eyes SECRETS says Privacy International
Refusal to disclose GCHQ canteen menus and prices triggers Euro Human Rights Court action
Heavy VPN users are probably pirates, says BBC
And ISPs should nab 'em on our behalf
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.