I would cast my drop-in-the-ocean vote if it didnā€™t require needlessly reckless disclosures. The question is- which states offer more privacy than others? These are some of the issues:

publication of residential address

Itā€™s obviously fair enough that you must disclose your residential address to the election authority so you get the correct ballot. But then the address is public. WTF? Iā€™m baffled that the voter turnout isnā€™t lower.

Exceptionally, Alaska enables voters to also supply a mailing address along with their residential address. In those cases, the residential address is not made public. But still an injustice as PO Boxes are not gratis so privacy has a needless cost.

Some states give the mailing address option exclusively to battered spouses. So if you are a victim of domestic abuse, you can go through a process by which you receive an address for the public voting records that differs from your residential address. Only victims of domestic abuse get privacy that should be given to everyone.

publication of political party affiliation

You are blocked from voting in primary elections unless you register a party affiliation, in which case you can only vote in the primary election of that party. A green party voter cannot vote in the democrat primary despite the parties being similar. The party you register in is public. So e.g. your neighbors, your boss, and your prospective future boss can snoop into your political leanings.

AFAIK, this is the same for all states.

publication of your voting activity (which is used for shaming)

Whether you voted or not is public. If you register to vote but do not vote, itā€™s noticed. There is a shaming tactic whereby postcards are sent saying ā€œyour neighbors the Johnsons at 123 Main St. voted early ā€“ will you do your civic duty too? Note that the McKinneys at 125 Main St. have not voted; perhaps you can remind them?ā€ They of course do this in an automated way, so non-voters know their neighbors are receiving postcards that say they did not partake in their civic duty.

forced disclosure to Cloudflare

These states force all voter registrations through Cloudflare:

  • Arizona
  • Florida
  • Georgia
  • Hawaii
  • Idaho
  • New York
  • Ohio
  • Rhode Island
  • Washington

Thatā€™s not just public info, but everything you submit with your registration including sensitive info like DL# and/or SSN goes to Cloudflare Inc. Cloudflare is not only a privacy offender but they also operate a walled garden that excludes some demographics of people from access. Voters can always register on paper, but whoever the state hires to do the data entry will likely use the Cloudflare website anyway. So the only way to escape Cloudflare getting your sensitive info in the above-mentioned states is to not register to vote.

To add to the embarrassment, the ā€œUS Election Assistance Commissionā€ (#USEAC) has jailed their website in Cloudflareā€™s walled garden. Access is exclusive and yet they proudly advertise: ā€œAdvancing Safe, Secure, Accessible Electionsā€.

solutions

What can a self-respecting privacy seeker do? When I read @BirdyBoogleBop@lemmy.dbzer0.comā€™s mentionĀ¹ of casting a ā€œspoiledā€ vote which gets counted, I thought Iā€™ll do thatā€¦ but then realized I probably canā€™t even get my hands on a ballot if I am not registered to vote. So I guess the penis drawing spoiled vote option only makes a statement about the ballot options. Itā€™s useless for those who want to register their protest against the voter registration disclosures.

Are there any states besides Alaska that at least give voters a way to keep their residential address out of publicly accessible records?

  1. it was mentioned in this thread: https://lemmy.dbzer0.com/post/8502419
  • brygphilomena@lemmy.world
    link
    fedilink
    arrow-up
    6
    Ā·
    9 months ago

    Your residential address is not private. Even if you do not vote.

    Your political party is self reported. I donā€™t believe the primaries have anything to do with actual government protection and are run by each party. Therefore they can make the rules on who can and cannot vote. As itā€™s self reported, you can always lie.

    Voting activity is a strange one. I have never gotten those postcards.

    Cloudflare, is well, cloudflare. Because of how they do their ddos protection they do have the ability to decrypt traffic, but itā€™s highly unlikely that they do. Anything done along the wire would destroy their reputation. It is a big issue regarding consolidation of Internet resources into the hands of a few large companies, but just because traffic goes through them doesnā€™t mean that privacy is violated. Iā€™m curious, can you expand on what demographics they block?

    • freedomPusher@sopuli.xyzOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      5
      Ā·
      edit-2
      9 months ago

      Your residential address is not private. Even if you do not vote.

      Of course your residential address is private. Itā€™s sensitive information because it can be used against you in countless ways. Do you mean to say that you personally donā€™t care if your residential address is published? Anyone who is street-wise treats it as private. Note that this is different from mailing address. Residential address is where you can physically be foundā€¦ where you sleep at night.

      Your political party is self reported. I donā€™t believe the primaries have anything to do with actual government protection and are run by each party. Therefore they can make the rules on who can and cannot vote. As itā€™s self reported, you can always lie.

      By ā€œself-reportedā€, do you mean that registrants are entering it on the voter reg. form themselves? Yes they have a choice whether or not to provide that, but it depends on the state whether itā€™s a precondition to participation in primaries. (see the earlier discussion below).

      Voting activity is a strange one. I have never gotten those postcards.

      I havenā€™t either. Just heard about it going on. The bigger issue is that the information to do that is /available publicly/. The postcards arenā€™t coming from the gov. The fact that people are exploiting the info is expected. The non-voter shaming is a bit eye opening but then again so are so many abusive tactics we encounter in the election run-up you could fill a book with all the ways voters are manipulated and exploited. AI of course supercharges it. Cambridge Analytica is merely the beginning.

      Cloudflare, is well, cloudflare. Because of how they do their ddos protection they do have the ability to decrypt traffic, but itā€™s highly unlikely that they do.

      Thatā€™s not true. The ability is used inherently in how they operate. Of course they decrypt the traffic; thatā€™s a precondition to the DDoS protection. How do you think CF offloads the userā€™s server workload without directly processing payloads? Any packets they donā€™t decrypt cannot be treated and must be passed through to the customer who cannot afford the bandwidth to handle all the traffic which is why they use CF to begin with.

      To give you a concrete example, you use #lemmyWorld, a Cloudflare instance. Your username and password is revealed to Cloudflare every time you login, along with all your actions including actions that do not manifest in a public way. Cloudflare inherently sees that all in the clear (to them). Whether they abuse it is guesswork. But itā€™s obviously not a wise move to choose a centralized CFā€™d instance when there are non-CF instances to choose from. You compromise privacy and support an anti-netneutrality tech giant for nothing.

      The option to allow the customer to have their own key is a premium option (non-gratis), which makes it rare, not to mention it defeats the DDoS protection. The use of that is obviously quite niche.

      Anything done along the wire would destroy their reputation.

      If they are caught abusing that data, it may or may not matter considering what theyā€™ve gotten away with so far. One would be a fool to not assume CF is feeding 3 letter orgs just like the other tech giants. Of course they are. There just hasnā€™t been a specific leak in that regard yet.

      CFā€™s reputation should be in the shitter because they doxxed a CSAM whistle blower to a CSAM host they were protecting, who then published the identity of the whistle blower so users could retaliate. If thatā€™s not startling enough evidence of Cloudflareā€™s untrustworthyness, consider as well that the (manchild) CEO said the whistle blower ā€œshould have used a fake nameā€ when reporting the CSAM to CF. Effectively, the CEO admitted that CF cannot be trusted with peopleā€™s real identities. That should have been a PR nightmare for them but most people donā€™t give a shit or donā€™t even know enough to understand it, which enables CF to grow. Theyā€™ve taken ~25-30% of all the worldā€™s websites so far and itā€™s rapidly increasing. Cloudbleed should have been an alarming disaster for them but people shrugged it off and a couple weeks later it was back to business as usual.

      Find me a PRISM corp whose reputation was destroyed by the Snowden leaks. Microsoftā€¦ Googleā€¦ Facebookā€¦ Appleā€¦ They are all doing well.

      It is a big issue regarding consolidation of Internet resources into the hands of a few large companies, but just because traffic goes through them doesnā€™t mean that privacy is violated.

      Thatā€™s not how wise infosec works. You do not wait until your data gets exploited before deciding not to do a reckless disclosure. That would be like leaving the keys in your car on the basis that your car has never been stolen. Not to mention Cloudflare has proven to be untrustworthy anyway. Just like Facebook. It doesnā€™t stop people using them. And the nature of the beast is the admin is putting other unwitting people at risk. Mallory solves her problems by transferring risk onto Alice.

      Iā€™m curious, can you expand on what demographics they block?

      By default, Cloudflare blocks access to the following groups of people:

      • users whose ISP uses CGNAT to distribute a limited range of IPv4 addresses (this generally impacts poor people in impoverished regions)
      • the Tor community
      • VPN users
      • users of public libraries (consequently people who canā€™t afford a PC and internet subscription), and generally networks where IP addresses are shared
      • privacy enthusiasts who will not disclose ~25% of their web traffic to one single corporation in a country without privacy safeguards
      • blind people who disable images in their browsers (which triggers false positives for robots, as scripts are generally not interested in images either)
      • environmentalists and the permacomputing community and people on limited internet connections, who also disable browser images to reduce bandwidth which consequently makes them appear as bots
      • people who actually run bots ā€“ Cloudflare is outspokenly anti-robot and treats beneficial bots the same as malicious bots

      ā€¦ and thatā€™s just what has been noticed and complained about. Itā€™s likely a bigger list but they are non-transparent. Cloudflare does not publicize who they marginalize. They just say they block the baddies, and then proceed to assume all those they block are baddies in a circular logic fashion. Marketing works wonders on people.