<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Breaking: Coleman&#8217;s unsecured donor database revealed on Wikileaks</title>
	<atom:link href="http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/feed" rel="self" type="application/rss+xml" />
	<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks</link>
	<description>News. Politics. Media.</description>
	<lastBuildDate>Wed, 30 Nov 2011 23:48:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: TTNET ADSL Basvuru</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-59759</link>
		<dc:creator>TTNET ADSL Basvuru</dc:creator>
		<pubDate>Sat, 05 Jun 2010 06:39:38 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-59759</guid>
		<description>But don’t forget, Republicans like Sen. Coleman are the ones who kept you safe from Islamofascist terrists (9/12 and after, that is; everything before that was Klintoon’s fault) and socialest Demoncrats and lieberals who want to redistribute your hard-earned wealth to furriners and to lazy losers who don’t want to work and who buy houses they can’t afford.
Teabag party</description>
		<content:encoded><![CDATA[<p>But don’t forget, Republicans like Sen. Coleman are the ones who kept you safe from Islamofascist terrists (9/12 and after, that is; everything before that was Klintoon’s fault) and socialest Demoncrats and lieberals who want to redistribute your hard-earned wealth to furriners and to lazy losers who don’t want to work and who buy houses they can’t afford.<br />
Teabag party</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Privacy vs. Technology (again)</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-27485</link>
		<dc:creator>Privacy vs. Technology (again)</dc:creator>
		<pubDate>Mon, 23 Mar 2009 13:51:53 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-27485</guid>
		<description>[...] stored and your purchasing history tracked (and perhaps sold). Or a political campaign worker can compromise your credit card information on its web site (committing numerous violations of CISP in the [...]</description>
		<content:encoded><![CDATA[<p>[...] stored and your purchasing history tracked (and perhaps sold). Or a political campaign worker can compromise your credit card information on its web site (committing numerous violations of CISP in the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Woolf</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26758</link>
		<dc:creator>Tom Woolf</dc:creator>
		<pubDate>Thu, 12 Mar 2009 20:53:16 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26758</guid>
		<description>Widtap - that&#039;s EX-Senator.</description>
		<content:encoded><![CDATA[<p>Widtap &#8211; that&#8217;s EX-Senator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smartalek</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26734</link>
		<dc:creator>Smartalek</dc:creator>
		<pubDate>Thu, 12 Mar 2009 17:48:03 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26734</guid>
		<description>But don&#039;t forget, Republicans like &lt;b&gt;Sen. Coleman&lt;/b&gt; are the ones who kept you safe from Islamofascist terrists (9/12 and after, that is; everything before that was Klintoon&#039;s fault) and socialest Demoncrats and lieberals who want to redistribute your hard-earned wealth to furriners and to lazy losers who don&#039;t want to work and who buy houses they can&#039;t afford.
Teabag party!

-- A True &#039;Murkin</description>
		<content:encoded><![CDATA[<p>But don&#8217;t forget, Republicans like <b>Sen. Coleman</b> are the ones who kept you safe from Islamofascist terrists (9/12 and after, that is; everything before that was Klintoon&#8217;s fault) and socialest Demoncrats and lieberals who want to redistribute your hard-earned wealth to furriners and to lazy losers who don&#8217;t want to work and who buy houses they can&#8217;t afford.<br />
Teabag party!</p>
<p>&#8211; A True &#8216;Murkin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NORM COLEMAN: Abyssmally Stupid Republican &#124; culturekitchen</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26726</link>
		<dc:creator>NORM COLEMAN: Abyssmally Stupid Republican &#124; culturekitchen</dc:creator>
		<pubDate>Thu, 12 Mar 2009 16:57:42 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26726</guid>
		<description>[...] the Minnesota Independent: ...scrutiny by web enthusiasts exposed a bigger problem for the campaign: an unprotected database [...]</description>
		<content:encoded><![CDATA[<p>[...] the Minnesota Independent: &#8230;scrutiny by web enthusiasts exposed a bigger problem for the campaign: an unprotected database [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oooopsie! &#171; Mercury Rising 鳯女</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26688</link>
		<dc:creator>Oooopsie! &#171; Mercury Rising 鳯女</dc:creator>
		<pubDate>Thu, 12 Mar 2009 05:49:50 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26688</guid>
		<description>[...] by Phoenix Woman on March 12, 2009  &#8211; The MnIndy reports that Norm Coleman&#8217;s donor list was found on an unsecured portion of his web... The discovery was made as a result of people trying to determine if Coleman had crashed his own [...]</description>
		<content:encoded><![CDATA[<p>[...] by Phoenix Woman on March 12, 2009  &#8211; The MnIndy reports that Norm Coleman&#8217;s donor list was found on an unsecured portion of his web&#8230; The discovery was made as a result of people trying to determine if Coleman had crashed his own [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Crossed Pond &#187; All Norm Coleman Donors: Cancel Your Credit Cards</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26620</link>
		<dc:creator>The Crossed Pond &#187; All Norm Coleman Donors: Cancel Your Credit Cards</dc:creator>
		<pubDate>Wed, 11 Mar 2009 19:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26620</guid>
		<description>[...] never got replies, leading Wikileaks to eventually call the donors directly. Good reporting on it here, with a twist. Wikileaks claims that the Coleman campaign was aware of the breach, and has been [...]</description>
		<content:encoded><![CDATA[<p>[...] never got replies, leading Wikileaks to eventually call the donors directly. Good reporting on it here, with a twist. Wikileaks claims that the Coleman campaign was aware of the breach, and has been [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Webster</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26612</link>
		<dc:creator>Tony Webster</dc:creator>
		<pubDate>Wed, 11 Mar 2009 16:39:06 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26612</guid>
		<description>Norm Coleman&#039;s campaign is the only party at fault in this situation.  They are the ones who actively put their entire database online for anyone to download simply by clicking a link; no hacking nor special knowledge required.  This is documented on several websites back in January.  So why has this taken so long to enter the public forum?  Why has the Coleman campaign taken so long to give notice to their supporters that they not only released, but illegally stored their credit card information?

This release of information is not the only bad part, as it seems the parties involved with the Wikileaks disclosure actually protected the cardholder&#039;s full credit card number.  Coleman&#039;s campaign actively violated Payment Card Industry Data Security Standards (PCI DSS) by storing the full card number and expiration date unencrypted, which isn&#039;t permitted.  Even worse, they stored the security code on the back of the card, and storage isn&#039;t permitted in any case, for any reason, with or without encryption.

This is complicated by the political nature of the information.  Donors who gave an amount small enough to avoid being reported in campaign financial reporting documents will now find that their full name, address, employer, occupation and credit card information has been published by the campaign they donated to!

This is a disgusting example of poor security, and blame needs to lie with the Coleman campaign and their web developers.  Blame further lies with the Coleman campaign and their media operations for not notifying their donors that their information had been published.  I say published, because the information wasn&#039;t breached, stolen, or otherwise hacked.  It was PUBLISHED and DISTRIBUTED via the Coleman website.  No &quot;federal authorities&quot; are going to look at firewall logs when the Coleman campaign actively disclosed their own database, so who do you think should be the parties the &quot;federal authorities&quot; investigate?  Hopefully they&#039;ll investigate the Coleman campaign itself.

Certainly, if someone were to use the card numbers or actively distribute the card numbers, it would be a illegal and unethical.  But at this point, Wikileaks and their source didn&#039;t release full card numbers.  Who knows what will happen next in that regard?  If &quot;federal authorities&quot; found that nobody had accessed the database, which was again openly published on the Coleman website, how did Wikileaks get an &lt;a href=&quot;http://wikileaks.org/wiki/The_Big_Bad_Database_of_Senator_Norm_Coleman&quot; rel=&quot;nofollow&quot;&gt;Excel spreadsheet of every single web donation&lt;/a&gt;?

Coleman Campaign Manager Cullen Sheehan writes in a press release that there is a &quot;...strong likelihood that these individuals have found a way to
breach private and confidential information.&quot;  Well, generally there&#039;s MORE than a &quot;strong likelihood&quot; when the campaign PUBLISHES the said private and confidential information on their website!

So, what&#039;s next?  The Coleman campaign needs to admit fault, and tell donors that there&#039;s not a &quot;likelihood&quot; of a breach, but that it actually happened, and that they are at fault.  They need to stop blaming &quot;hackers,&quot; and start blaming their web developers.  

I further call for the Minnesota Attorney General&#039;s office and state authorities to investigate this matter and charge the Coleman campaign for violations of Minnesota Statute §325E.61, specifically relating to their disclosure of personal information and neglect to notify donors, or more accurately, lie about the reasons behind the disclosure.</description>
		<content:encoded><![CDATA[<p>Norm Coleman&#8217;s campaign is the only party at fault in this situation.  They are the ones who actively put their entire database online for anyone to download simply by clicking a link; no hacking nor special knowledge required.  This is documented on several websites back in January.  So why has this taken so long to enter the public forum?  Why has the Coleman campaign taken so long to give notice to their supporters that they not only released, but illegally stored their credit card information?</p>
<p>This release of information is not the only bad part, as it seems the parties involved with the Wikileaks disclosure actually protected the cardholder&#8217;s full credit card number.  Coleman&#8217;s campaign actively violated Payment Card Industry Data Security Standards (PCI DSS) by storing the full card number and expiration date unencrypted, which isn&#8217;t permitted.  Even worse, they stored the security code on the back of the card, and storage isn&#8217;t permitted in any case, for any reason, with or without encryption.</p>
<p>This is complicated by the political nature of the information.  Donors who gave an amount small enough to avoid being reported in campaign financial reporting documents will now find that their full name, address, employer, occupation and credit card information has been published by the campaign they donated to!</p>
<p>This is a disgusting example of poor security, and blame needs to lie with the Coleman campaign and their web developers.  Blame further lies with the Coleman campaign and their media operations for not notifying their donors that their information had been published.  I say published, because the information wasn&#8217;t breached, stolen, or otherwise hacked.  It was PUBLISHED and DISTRIBUTED via the Coleman website.  No &#8220;federal authorities&#8221; are going to look at firewall logs when the Coleman campaign actively disclosed their own database, so who do you think should be the parties the &#8220;federal authorities&#8221; investigate?  Hopefully they&#8217;ll investigate the Coleman campaign itself.</p>
<p>Certainly, if someone were to use the card numbers or actively distribute the card numbers, it would be a illegal and unethical.  But at this point, Wikileaks and their source didn&#8217;t release full card numbers.  Who knows what will happen next in that regard?  If &#8220;federal authorities&#8221; found that nobody had accessed the database, which was again openly published on the Coleman website, how did Wikileaks get an <a href="http://wikileaks.org/wiki/The_Big_Bad_Database_of_Senator_Norm_Coleman" rel="nofollow">Excel spreadsheet of every single web donation</a>?</p>
<p>Coleman Campaign Manager Cullen Sheehan writes in a press release that there is a &#8220;&#8230;strong likelihood that these individuals have found a way to<br />
breach private and confidential information.&#8221;  Well, generally there&#8217;s MORE than a &#8220;strong likelihood&#8221; when the campaign PUBLISHES the said private and confidential information on their website!</p>
<p>So, what&#8217;s next?  The Coleman campaign needs to admit fault, and tell donors that there&#8217;s not a &#8220;likelihood&#8221; of a breach, but that it actually happened, and that they are at fault.  They need to stop blaming &#8220;hackers,&#8221; and start blaming their web developers.  </p>
<p>I further call for the Minnesota Attorney General&#8217;s office and state authorities to investigate this matter and charge the Coleman campaign for violations of Minnesota Statute §325E.61, specifically relating to their disclosure of personal information and neglect to notify donors, or more accurately, lie about the reasons behind the disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Keliher</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26611</link>
		<dc:creator>Mike Keliher</dc:creator>
		<pubDate>Wed, 11 Mar 2009 16:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26611</guid>
		<description>That would be &quot;Excel spreadsheet.&quot; The data has nothing to do with our local energy company.</description>
		<content:encoded><![CDATA[<p>That would be &#8220;Excel spreadsheet.&#8221; The data has nothing to do with our local energy company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WIDTAP</title>
		<link>http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks/comment-page-1#comment-26605</link>
		<dc:creator>WIDTAP</dc:creator>
		<pubDate>Wed, 11 Mar 2009 15:51:09 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28711#comment-26605</guid>
		<description>I find it curious that not only did Coleman campaign fail to secure the data as well an any mom &amp; pop internet storefront would, but also that they were storing the credit card security codes. There are specific credit card industry regulations, called PCI, that call this out as a big no-no. It&#039;s the sort of thing that can allow you bank to cancel your credit card payee clearing privileges. You can also get sued for doing this. Well, you or I could get sues. A Senator like Coleman is probably above the law and common industry regulations like the rest of us.</description>
		<content:encoded><![CDATA[<p>I find it curious that not only did Coleman campaign fail to secure the data as well an any mom &amp; pop internet storefront would, but also that they were storing the credit card security codes. There are specific credit card industry regulations, called PCI, that call this out as a big no-no. It&#8217;s the sort of thing that can allow you bank to cancel your credit card payee clearing privileges. You can also get sued for doing this. Well, you or I could get sues. A Senator like Coleman is probably above the law and common industry regulations like the rest of us.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

