Attacks/Breaches

2/8/2017
09:32 AM
50%
50%

Dutch Voter Guide Website Leak Highlights Privacy Concerns

StemWijzer fixes vulnerabilities after researcher discovers website is secretly maintaining voter-preference record.

A data leak from StemWijzer, a Dutch voter guide website, has raised questions about its intentions and whether it is quietly conducting popularity polls and infringing upon voters' privacy, Reuters reports. Security researcher Loran Kloeze discovered that a record of voters' preference was being maintained by the site, which could potentially influence trends ahead of the March 15 elections in the Netherlands.

Anita de Jong of website designer ProDemos said vulnerabilities pointed out by Kloeze had been resolved and clarified the intention was not to offer voting advice but only to educate voters.

StemWijzer requires a site visitor to answer 30 questions and then tells him which political party matches his views the best. The leaked data currently places Labour Party in the second place after Party for Freedom even though opinion polls do not reflect this.

Countries going to the polls this year are working overtime to address cybersecurity concerns, following multiple hacking incidents during the US presidential election last year.

For the full story, read Reuters.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12242
PUBLISHED: 2018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
CVE-2018-12243
PUBLISHED: 2018-09-19
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths i...
CVE-2018-14792
PUBLISHED: 2018-09-19
WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project files.
CVE-2018-16607
PUBLISHED: 2018-09-19
Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.
CVE-2018-16785
PUBLISHED: 2018-09-19
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell