5. Social Engineering
Social engineering, in the context of
information security, refers to psychological
manipulation of people into performing
actions or divulging confidential information.
6. Background
• On 12/15/2018 I graduated from Washington State University (Pullman).
• On 12/21/2018 I moved from Pullman to the Great Seattle area.
• On 12/24/2018 I changed my address online, but the system also ask me to change my voter
address that is how I know MyVote exist.
• On 12/24/2018 I realized the voter information can be manipulated by a attacker.
• On 12/25/2018 I contacted Secretary of State (SOS) of Washington.
• On 12/26/2018 I got a useless email in reply.
• On 12/27/2018 I published my article on my Linkedin account to warn others remove their date
of birth from their social media account.
7. Steps of Attacking
1. Find a victim from Facebook.
2. Add the victim as friend.
3. Check/find out victim’s date of birth.
4. Use MyVote to get victim’s true address.
5. Use ***Search to get all victim’s information
including victim’s relatives’ information.
6. Repeat step 1.
16. SOS Email
Hello,
Thank you for contacting our office. Certain voter registration data is public and can’t be withheld from public request.
Private information like your phone number, driver’s license number, Social Security number, etc. is not public and
therefore not disclosed, but your name, address, date of birth, gender, etc. is public. If anyone contacts our office or a
County Auditor’s Office and requests voter registration information, we are required by RCW 29A.08.710 to provide that
information. The only exception to public disclosure is voters enrolled in the Address Confidentiality Program (RCW
29A.08.710). RCW 29A.08.740 does restrict what requesters can do with voter registration information and misuse of
voter registration information is a class C felony.
Everything that appears on MyVote is public information under state law.
I hope this answers your questions!
Selena Faller
Office Assistant
Washington State Elections | Office of the Secretary of State
(360) 902-4180 | www.vote.wa.gov
17. My Question
So my question is:
"If everyone can follow the law,
why we still need a password?"
18. Solutions
• Add a ReCAPTCHA at front page.
• Add a request form to verify the requester’s
information.
• Taking down all reserve social engineering website
like ***Search.