<div dir="auto">This is a very serious anomaly that must be addressed soonest possible. It begs the question, are we safe as data subjects? If a body like IEBC that is expected to be beyond reproach can have such open flaws...then we say that we are ready to go for elections huh?its a disappointment.</div><div class="gmail_extra"><br><div class="gmail_quote">On 29-Jun-2017 11:47 PM, "Mwendwa Kivuva via kictanet" <<a href="mailto:kictanet@lists.kictanet.or.ke">kictanet@lists.kictanet.or.ke</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Dear Listers,</div><div><br></div><div>Today I'm wearing my CISA hat.</div><div><br></div><div>IEBC has launched a voter verification tool both through sms, and web query at <a href="http://voterstatus.iebc.or.ke/voter" target="_blank">http://voterstatus.iebc.or.<wbr>ke/voter</a></div><div><br></div><div>If you are privacy conscious, and a little bit paranoid, you will realize that IEBC is doing badly with how they are exposing raw data of nearly 20 million Kenyans to the world. Anybody with basic programing skills can be able to harvest the raw data through an automated search. If you search any random number with the format of Kenya ID numbers, say hypothetically 12345678, you will realize you can pull up citizen's details, at least ID number, and name, and where they live.</div><div><br></div><div>Basic security tips would require the system to have a captcha to prevent automated harvest of the information, and also have a challenge questions like date of birth to supplement the ID number, therefore thwart any mischievous individuals from harvesting the rich data<br></div><div><br></div><div>Can IEBC correct the anomaly?</div><div><br></div><div>Attached is a sample demo screenshot. Of course there is the other thing of strange ID numbers finding their way into the voter register.</div><div><br></div><div><h4 style="margin:0px 0px 0.5rem;padding:0px;box-sizing:border-box;border:none;font-weight:400;font-family:"Open Sans Condensed",calibri_0xx,sans-serif;line-height:1.1;color:rgb(52,52,52);font-size:1.5rem;outline:0px">Voter Details for Id: 12345678</h4><table class="m_3799577072574419567gmail-detail-view m_3799577072574419567gmail-table m_3799577072574419567gmail-table-bordered m_3799577072574419567gmail-table-striped" id="m_3799577072574419567gmail-yw0" style="margin:0px;padding:0px;box-sizing:border-box;border:1px solid rgb(236,238,239);max-width:100%;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;width:1517.5px;border-radius:4px;color:rgb(52,52,52);font-family:"Open Sans Condensed",calibri_0xx,sans-serif;font-size:16px;outline:0px"><tbody style="margin:0px;padding:0px;box-sizing:border-box;border:none;outline:0px"><tr class="m_3799577072574419567gmail-odd" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background:0px 0px;outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:0px 1px 1px;border-top-style:initial;border-right-style:solid;border-bottom-style:solid;border-left-style:solid;border-top-color:initial;border-right-color:rgb(236,238,239);border-bottom-color:rgb(236,238,239);border-left-color:rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;background-color:rgb(249,249,249);border-top-left-radius:4px;outline:0px">Id / Passport Number</th><td style="padding:2px;box-sizing:border-box;border-width:0px 1px 1px;border-top-style:initial;border-right-style:solid;border-bottom-style:solid;border-left-style:solid;border-top-color:initial;border-right-color:rgb(236,238,239);border-bottom-color:rgb(236,238,239);border-left-color:rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;background-color:rgb(249,249,249);border-top-right-radius:4px;outline:0px">12345678</td></tr><tr class="m_3799577072574419567even" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background-color:rgb(251,252,253);outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;outline:0px">Primary Name</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;outline:0px">KIBET</td></tr><tr class="m_3799577072574419567gmail-odd" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background:0px 0px;outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;background-color:rgb(249,249,249);outline:0px">Secondary Name</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;background-color:rgb(249,249,249);outline:0px">KIRUI</td></tr><tr class="m_3799577072574419567even" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background-color:rgb(251,252,253);outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;outline:0px">Birth Date</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;outline:0px">01/01/1994</td></tr><tr class="m_3799577072574419567gmail-odd" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background:0px 0px;outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;background-color:rgb(249,249,249);outline:0px">Gender</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;background-color:rgb(249,249,249);outline:0px">M</td></tr><tr class="m_3799577072574419567even" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background-color:rgb(251,252,253);outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;outline:0px">Polling Station Code</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;outline:0px">101</td></tr><tr class="m_3799577072574419567gmail-odd" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background:0px 0px;outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;background-color:rgb(249,249,249);outline:0px">Polling Station</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;background-color:rgb(249,249,249);outline:0px">LELACH PRIMARY SCHOOL</td></tr><tr class="m_3799577072574419567even" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background-color:rgb(251,252,253);outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;outline:0px">County</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;outline:0px">KERICHO</td></tr><tr class="m_3799577072574419567gmail-odd" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background:0px 0px;outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;background-color:rgb(249,249,249);outline:0px">Contituency</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);vertical-align:middle;line-height:1.5;height:6px;background-color:rgb(249,249,249);outline:0px">BURETI</td></tr><tr class="m_3799577072574419567even" style="margin:0px;padding:0px;box-sizing:border-box;border:none;background-color:rgb(251,252,253);outline:0px"><th style="margin:0px;padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);text-align:right;vertical-align:middle;width:160px;line-height:1.5;border-bottom-left-radius:4px;outline:0px">Ward</th><td style="padding:2px;box-sizing:border-box;border-width:1px;border-style:solid;border-color:rgb(216,226,231) rgb(236,238,239) rgb(236,238,239);outline:0px;vertical-align:middle;line-height:1.5;height:6px;border-bottom-right-radius:4px">CHEPLANGET<br></td></tr></tbody></table><div><div class="m_3799577072574419567gmail_signature"><br></div><div class="m_3799577072574419567gmail_signature">______________________<br>Mwendwa Kivuva, Nairobi, Kenya<br><a href="http://twitter.com/lordmwesh" target="_blank">twitter.com/lordmwesh</a><br><br><br></div></div><div class="m_3799577072574419567gmail_signature"><br></div>
</div>
</div>
<br>______________________________<wbr>_________________<br>
kictanet mailing list<br>
<a href="mailto:kictanet@lists.kictanet.or.ke">kictanet@lists.kictanet.or.ke</a><br>
<a href="https://lists.kictanet.or.ke/mailman/listinfo/kictanet" rel="noreferrer" target="_blank">https://lists.kictanet.or.ke/<wbr>mailman/listinfo/kictanet</a><br>
Twitter: <a href="http://twitter.com/kictanet" rel="noreferrer" target="_blank">http://twitter.com/kictanet</a><br>
Facebook: <a href="https://www.facebook.com/KICTANet/" rel="noreferrer" target="_blank">https://www.facebook.com/<wbr>KICTANet/</a><br>
<br>
Unsubscribe or change your options at <a href="https://lists.kictanet.or.ke/mailman/options/kictanet/ronojinx%40gmail.com" rel="noreferrer" target="_blank">https://lists.kictanet.or.ke/<wbr>mailman/options/kictanet/<wbr>ronojinx%40gmail.com</a><br>
<br>
The Kenya ICT Action Network (KICTANet) is a multi-stakeholder platform for people and institutions interested and involved in ICT policy and regulation. The network aims to act as a catalyst for reform in the ICT sector in support of the national aim of ICT enabled growth and development.<br>
<br>
KICTANetiquette : Adhere to the same standards of acceptable behaviors online that you follow in real life: respect people's times and bandwidth, share knowledge, don't flame or abuse or personalize, respect privacy, do not spam, do not market your wares or qualifications.<br>
<br></blockquote></div></div>