2016 Postmortem
In reply to the discussion: DISGRACEFUL: DNC Compromises Clinton Campaign Data, Then Blames/punishes Bernie Sanders [View all]0rganism
(25,346 posts)there's another layer to this story.
either the DNC's database is unsecured by poor design or implementation, or because an admin created a vulnerable/honeypot scenario for... reasons.
if it's the former, i would assume improper data access multiple times by multiple campaigns as much by accident as malfeasance. the DNC needs to bust ass to scope the problem and fix it, rather than levying punishments and accusations.
my general rule is "don't attribute to malice that which can be explained adequately by stupidity", which favors a flawed design hypothesis. however, the speed at which this particular breach was revealed, specifically in this primary, suggests that either the DNC's database was recently redesigned (poorly), or there was an intentional (temporary?) reconfiguration that allowed improper access which remained closely monitored. the service provider claims this vulnerability was during a brief interval due to software patching -- this is a verifiable claim, as any patching activity on a production system will be carefully logged and the consequences of any particular patch across a particular schema should be repeatable. it should be fairly easy to establish if said patch would be sufficient to disable user and/or role restrictions to view campaign data. for the production databases i've worked with, any such patching is a HUGE deal, accompanied by a service shutdown and preliminary user noticfication (pref. 48h in advance), requiring verification before returning to use. i'd be curious to know what kind of "hot patch" the DBAs thought was appropriate to apply on a Wednesday without closing off external access.
this will become an interesting story from a tech perspective after the hype dies off and follow-up investigations begin to reveal underlying causes. from a political perspective, this story will be long dead by then.
Edit history
Recommendations
0 members have recommended this reply (displayed in chronological order):