Feeds

Pennsylvania officials bail after voter reg site springs a leak

Flaw exposes sensitive user data

The Power of One Infographic

Pennsylvania officials pulled the plug on a voter registration website after a user posted online instructions that showed the site was exposing sensitive information about people who used the service.

The flaw with the state's Voter Registration Application made it possible for anyone on the net to view registration forms that had been completed online. The forms contained a bevy of personal information, including the voter's name, date of birth, driver's license number and political party affiliation, ComputerWorld reports.

The revelation comes a month before the state holds a high-profile presidential primary that could determine who wins the nomination for the Democratic candidate for US President. Users who tried visiting the site on Wednesday got a message that it was not available.

A user with the handle mtg169 first disclosed the leak in on Digg. The post showed that it was possible to view the PDF applications of voters my modifying request parameter included in the URL of the voter registration site. Simply adding or subtracting numbers was all it took to view a different application.

"Valid IDs appear to be working from 50000 and up to 58500+," mtg169 wrote. "Very bad PA ... very very bad!" PA is the US postal abbreviation for Pennsylvania.

In a comment following the post, mtg169 added that IDs in the 20,000 range also exposed applications.

The breach represents a serious blow to the privacy of people who may have used the service. The instructions on Digg had been up for hours before the service was unplugged, and there's no telling how long miscreants had been using the flaw to take a peak at voters' personal details. ®

If you have a tip about the leakage of personal information, please contact your reporter here.

Maximizing your infrastructure through virtualization

More from The Register

next story
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
Sit back down, Julian Assange™, you're not going anywhere just yet
Swedish court refuses to withdraw arrest warrant
UK Parliament rubber-stamps EMERGENCY data grab 'n' keep bill
Just 49 MPs oppose Drip's rushed timetable
MPs wave through Blighty's 'EMERGENCY' surveillance laws
Only 49 politcos voted against DRIP bill
EU's top data cops to meet Google, Microsoft et al over 'right to be forgotten'
Plan to hammer out 'coherent' guidelines. Good luck chaps!
US judge: YES, cops or feds so can slurp an ENTIRE Gmail account
Crooks don't have folders labelled 'drug records', opines NY beak
Delaware pair nabbed for getting saucy atop Mexican eatery
Burrito meets soft taco in alleged rooftop romp outrage
LightSquared backer sues FCC over spectrum shindy
Why, we might as well have been buying AIR
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Mobile application security vulnerability report
The alarming realities regarding the sheer number of applications vulnerable to attack, and the most common and easily addressable vulnerability errors.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.