Alexander

4.1K posts

Alexander banner
Alexander

Alexander

@Alecxace

literally me screaming in the void.

Katılım Eylül 2013
321 Takip Edilen212 Takipçiler
Alexander
Alexander@Alecxace·
Being an adult sometimes sucks
English
0
0
1
19
Alexander
Alexander@Alecxace·
@VancePoitier @omoteurax @somemore_b Or that American cars record your driving data and sends it to insurance companies or the feds. Or that America never stopped bulk collecting all electronic communications coming insane out of the Bahamas.
English
0
0
0
12
Vance 🇧🇸🇧🇷
Vance 🇧🇸🇧🇷@VancePoitier·
I scraped some of the Bahamas voter roll in 14 minutes. Then I mapped every single one of them as best as possible. 6,452 names. Voter IDs. Dates of birth. Home constituencies. 676 API calls. Zero rate limiting. Zero authentication beyond a public key sitting in the page source. This isn't a hack. There's no exploit. No credentials were stolen. No systems were compromised. The Bahamas government voter lookup tool has a 2-character minimum search, no rate limiting, and a CORS wildcard (*), meaning anyone, from any website on earth, can query it programmatically and pull data cross-origin without restriction. I wrote a script that iterated every 2-letter prefix from "aa" to "zz." That's it. 14 minutes later I had the full roll. What came back per voter: full legal name, voter registration number (used as government-issued ID), year of birth, constituency, polling division, and advance poll status. 8 PII fields per person, served up to anyone with a browser console and basic fetch knowledge. So I built something to make the implications impossible to ignore. Using constituency and polling division data alone, no addresses, no GPS, no phone records, I triangulated each voter's approximate physical location to within ~1-4km using a GEOSINT (Geographic Open Source Intelligence) visualization. Every dot on the map is a real person, placed within a polygon near their real neighborhood, derived entirely from "public" civic data. Here's what an adversary would see when they connect the dots: - Voter IDs are used for identity verification purposes, that's an identity fraud vector. - Constituency + polling division = neighborhood-level geolocation without ever needing an address. - Full name + year of birth + location = a social engineering playbook that practically writes itself. - Advance poll registration = a confirmed physical location on a specific, known date This isn't about The Bahamas specifically. Treating voter data as "public record" without considering what happens when public + structured + queryable + unprotected = weaponizable at scale. The fix is embarrassingly simple: • Increase the search minimum to 4+ characters • Add rate limiting (even 10 requests/minute would have stopped this) • Remove the CORS wildcard • Require authentication for bulk-capable queries None of this is hard. None of this is expensive. It just has to actually be done. ⚠️ This project is strictly for educational and awareness purposes. No data was used maliciously. The tool was built to demonstrate the real-world intelligence implications of exposed PII in civic systems so that the people responsible for protecting it understand the urgency. If you work in election security, government IT, or data protection policy, this can be used with information like info stealers or malware that works together with information from the darknet for even further purposes like social engineering, this is just a very small example of what could evolve into something like a threat before it becomes a headline. @ValaLegz @SansNevis @phreakydev @secmxx #CyberSecurity #OSINT #GEOSINT #ElectionSecurity #DataPrivacy #InfoSec
English
13
44
131
8.2K
Alexander
Alexander@Alecxace·
What an odd time for this story to drop. This is not the 1st, 2nd or 3rd time something like this dropped in the final days of an election. The Fox podcast comes to mind. I’m not taking a position, just pointing out that Something is odd. miamiherald.com/news/nation-wo…
English
1
1
7
920
Alexander
Alexander@Alecxace·
We say this only to then obediently follow the Washington consensus and pretend it’s a novel idea our leaders came up with. A country that prostitutes itself for FDI in USD is bound by the rules set by Washington. To argue otherwise is pure fantasy.
Denzel 🇧🇸🇭🇹@dembazell

We shouldn’t base the success of our country by the ratings of foreign/western entities like moody’s. They’re corrupt to the point of hilarity if they weren’t so dangerous. Western-powers’ approval of our economy does not equal a successful economy for our citizens.

English
0
0
4
186
Alexander
Alexander@Alecxace·
A lot of people listen to Lincoln Bain’s livestreams. The amount of random people playing his videos out loud… This will be a fascinating election.
English
0
0
1
72
Alexander
Alexander@Alecxace·
@RemedyLovegood @imastrc242 Not taking sides but let’s not forget when Loretta Butler-Turner burst off Andre Rollins head IN the HOA after he made a remark.
English
1
0
0
42
Alexander
Alexander@Alecxace·
@NyaWinter_ The jurors list is now partially censored. So it’s fine. It used to be published with home addresses of the entire list.
English
1
0
4
308
Tastemaker 🇭🇹🇻🇪🇸🇩🇨🇩🇵🇸
Can we expect anything else when our Government has been held at ransom by cyber hackers 😭 and almost extorted for $300,000, I believe? No preparation, no thinking about cyber security, but VOTE for progress. Abysmally poor oversight. This is our standard, shoddy work.
GIF
Alexander@Alecxace

Ok bad news. You really can scrape the entire database and download the entire thing. Everything is stored in plain text. No idea who’s responsible for this, but they didn’t give a single fk.

English
1
1
3
237
Alexander
Alexander@Alecxace·
@MeyerHaruko Reminds me of when they would publish the name, phone number and address of the jury list
English
0
0
7
1.1K
Haruko Meyer
Haruko Meyer@MeyerHaruko·
@Alecxace Yeah I said the same thing earlier Exact dob general location and full government name is info scammers would kill for
English
1
0
7
1.6K