13 Comments
User's avatar
DataRepublican's avatar

I know we disagree on a great deal politically, but I think we share the same concern here: protecting people’s personal data. I do not want to see anyone’s PII exposed, regardless of affiliation.

I’ve reported on several cybersecurity incidents involving activist organizations: all were fundamental failures in access control and data protection. In StopICE's case, Sherman Austin publicly denied that any breach had occurred. As a result, many affected users never rotated their passwords despite an exposure affecting roughly 100,000 accounts.

Unfortunately, this kind of security posture is not unusual among activist-operated platforms today.

DataRepublican's avatar

One correction: I did not scrape either website. By the time I reported the UndoTrump.org vulnerability, it had already been largely patched. The sources I spoke with were highly conscious of the exposure of PII, and the fact that these data dumps have not been broadly leaked should reflect that.

Scott Petty's avatar

Thank you for the clarification, we have updated the article to reflect your correction. Also, regarding your previous comment, I completely agree and said pretty much the same thing to Kyle during the interview. I try to avoid many of the more partisan aspects of modern politics, it’s all a bit too tribal for my tastes. I do feel that our ability to disagree on such things, civilly, while finding common ground in others is one of the things that makes our country great. I appreciate you taking the time to respond.

DragonflySiouxsie's avatar

FUCK ICE!

karemm's avatar

I was one of the people who foolishly gave my information. I am not a computer person. I dont know how to protect myself, so I will not give my information out again.

I Have Friends Everywhere's avatar

Thank you for covering this issue. This data breach obviously needs to be taken seriously. It’s a reminder to activists that they need to be careful with sharing their personal info. And it’s a reminder that organizations collecting such info need to have infrastructure in place to secure it before collecting it. (And only collect as much info as necessary to accomplish the specific goals of the organization.) That infrastructure includes facilities, hardware, software, and—critically—training for everyone within the collecting organization.

But I also think it’s important to report accurate information as to the nature and scope of the breach, and what’s being done to mitigate potential harm. To do that you need to interview the people behind GTFOIce.org, in addition to outside IT security experts. From your reporting it doesn’t appear you’ve done that. Modern reporting etiquette requires that you seek comment from people / organizations you write about too. I hope you’ll include their perspective in your future reporting on this. It would give your readers a better sense of the nature and scope of the breach, and what’s being done to mitigate potential harm.

We should not be trying to spread unnecessary fear among people advocating for ICE accountability, as that would having a chilling effect on the movement. But accurate assessments of risks like data breaches are important.

Hagerstown Rapid Response's avatar

1.) What statement did they issue us?

2.) And outside of an email they sent users on Saturday, we’re unaware of any statement they have made publicly or privately. But if you know of one, please let us know.

3.) On Monday, we had a meeting scheduled with their cofounder, Xander Schultz, literally to discuss their handling and use of data. Sadly, he abruptly canceled it 20 mins before it was to begin with no explanation.

I Have Friends Everywhere's avatar

My apologies, the person who told me about the statement must’ve been mistaken about the timing of its release, since you didn’t receive it, and I’m not seeing it online. Hopefully they’ll release it soon. I deleted the reference to it in my prior comment to avoid confusing others.

Hagerstown Rapid Response's avatar

So…they still haven’t addressed this. Thoughts? Also, who told you they would put out a statement?

I Have Friends Everywhere's avatar

Noticed that, and the site is still down. Unfortunately I don’t have any additional info about it that I can share at this time.

Me speculating: they may be waiting for hired help (IT experts, lawyers, etc.) to finish assessing what happened, and what needs to be done to fix it, before issuing a statement or otherwise engaging with the press about it. A nonprofit I used to work at experienced a data breach while I was there, and they had to hire outside help to figure that stuff out before taking next steps. It can take time.

You may want to research how long such processes typically take for situations like this, and seek interviews from IT security, legal and PR professionals with experience dealing with breaches like this. To get a better sense of what might be going on and how long it might take.

And I would continue seeking comment from GTFOIce and other orgs / people behind it that you reference ahead of publishing any new articles about it. (See Google’s AI summary for “no surprise rule in journalism”.)

They’ll have to explain what’s going on at some point in order to mitigate brand and legal risk from the breach.

Hagerstown Rapid Response's avatar

We will not be waiting for them before we post. Nearly, 18,000 people may have had their personally identifiable information over to the FBI and DHS. We have sought comment numerous times and they have intentionally been evasive to us and journalists trying to get a response.

The individuals and organizations behind this website need to be doing everything in their power to be helping the people who were harmed and they have not done this.

I Have Friends Everywhere's avatar

I agree with you. I’m not saying you should not post until they respond. But give them 24-48 hours to respond to a summary of the assertions you’re planning to make, and framing for them. Give them a deadline. If they don’t respond by the deadline, just state they didn’t respond to a request for comment. If they do respond, include their response in your article. It serves as a check against factual errors and helps critical reporting appear less biased. And it can help cover your butt in case of a libel suit. My wife is a journalist, hence my familiarity with it.

InfiniteEMF's avatar

I feell like half the inattention to security could likely be attributed to developers heady political hubris. Something like having the notion they're so damned righteous in their cause they don't have to care. Fellow travelers will excuse their carelessness basis the gravity of the cause, and the momentum of their imagined success will carry them far enough, fast enough to outdistance even Karma itself.

Not EVER a good bet.

Can't help the schadenfreude.