App used by Netanyahu’s Likud leaks Israel’s entire voter registry - Israel Election 2020 - Haaretz.com
The Likud has uploaded the full register of Israeli voters to an application, causing the leak of personal data on 6,453,254 citizens. The information includes the full names, identity card numbers, addresses and gender of every single eligible voter in Israel, as well as the phone numbers and other personal details of some of them.
Israeli political parties receive personal details of voters before the elections and commit to protecting their privacy, as well as not to reproduce the registry, not to provide it to a third party, and to permanently erase all the information once the election is over.
The voter registry was uploaded by Likud to the Elector app, which is used by the party to manage Election Day. The firm that developed the application, Feed-b, commented that the vulnerability was a “one-off incident that was immediately dealt with," and that security measures have since been boosted.
The Likud has yet to respond to a request for comment.
According to information obtained by Haaretz, as well as Noam Rotem and Ido Kenan of the Cybercyber podcast, a vulnerability in the application allowed for anyone to easily download the entire voter registry. The only known leak of a similar magnitude occurred in 2006, when an Interior Ministry employee stole the population registry and distributed it illegally.
Haaretz received an anonymous tip about the security lapse, allowing anyone to obtain the leaked information in its entirety without using sophisticated tools. Right-clicking on the Elector app’s home page and choosing “view source” revealed the original code of the internet page. The code revealed all the usernames and passwords of system admins, allowing one to log in and download the registry.
The anonymous tipper also provided Haaretz with personal details of powerful people in Israel. It is unknown how many people gained access to the data and downloaded it. However, the application has users in various countries abroad, among them the United States, China, Russia and Moldova.
Dans le paquet, il y aurait les données de personnalités importantes, y compris dans le domaine de la sécurité... #israël