Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

1–10 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#2
This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0].

It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure.

[0] https://landing.google.com/advancedprotection/

Re: Email security on Democratic campaigns is as bad as 2016

#4
Note the plural: campaigns, hinting at the explanation: There are many campaigns, and they operate entirely independent from each other, at least when it comes to technology infrastructure.

The reason for that is something that HN would usually respect, namely the attempt to keep ownership of information. So of course the old discussion about cloud services is being replayed here: "Why would you trust Google?" / "Why do you think my small company has better security than Google" / ...

I'm pretty sure their next presidential candidate will activate 2-factor authentication etc.

Re: Email security on Democratic campaigns is as bad as 2016

#5

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

I seem to remember Podesta, whose email was leaked, was already using GMail, either because the campaign used it, or he was using a personal account. Activating 2-factor auth would probably have stopped the attack.

It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outraged. This discussion sometimes gets dangerously close to victim blaming.

Re: Email security on Democratic campaigns is as bad as 2016

#6
I think that's because email, fundamentally just isn't very secure.

Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually, the cop out comes in the form of "too complicated for non-technical/less-technical users, and thus potentially harmful to profits."

As if to say, we've been espousing the use of an insecure method of communication for decades, so, to suddenly reverse our position, and encourage bring-your-own-encryption might provoke discussions of liability, or something. Nevermind, the premise of ad tech and scanning user messages, to sell data.

But you know, running your own server, and hiring people who can't be bothered to go deeper than using word art in MS PowerPoint slides, well, hey. Bring a horse to water... know what I'm saying?

PGP is easy to use. At this point, I'd like to think people are fatigued enough by the bottomless pit of nightmares we've fallen into, that they'd step up and tell people: yes, people are using SSH keys and SSL keys billions of times a day. It's okay to use PGP on your email. Go ahead, start doing it.

Or, you know, whatever. Lose another election. Right?

[0] https://en.wikipedia.org/wiki/Email_encryption

[1] https://blog.filippo.io/the-sad-state-of-smtp-encryption/

[2] https://security.stackexchange.com/questions/51552/how-insec...

Re: Email security on Democratic campaigns is as bad as 2016

#7

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

actually, they do all have gsuite! at least when i worked for them in 2016.

Re: Email security on Democratic campaigns is as bad as 2016

#8

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

Curious why Google requires their users to use Chrome or Firefox but can't use Safari to access Google Services when enrolled in that program? "And you will only be able to use Chrome and Firefox to access your signed-in Google services like Gmail or Photos." I could see them just requiring Chrome but curious why they would block Safari over Firefox.

Re: Email security on Democratic campaigns is as bad as 2016

#9
post #5

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

I seem to remember Podesta, whose email was leaked, was already using GMail, either because the campaign used it, or he was using a personal account. Activating 2-factor auth would probably have stopped the attack. It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outrag…

I wonder if the reaction to the hacking would have been different if dirt was found. A greater good argument might have prevailed even though it was a crime, like it the public generally has sympathy for Snowden. Breaking in and finding nothing just looks bad from top to bottom though for the hackers and those associated.

Re: Email security on Democratic campaigns is as bad as 2016

#10

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

Curious why Google requires their users to use Chrome or Firefox but can't use Safari to access Google Services when enrolled in that program? "And you will only be able to use Chrome and Firefox to access your signed-in Google services like Gmail or Photos." I could see them just requiring Chrome but curious why they would block Safari over Firefox.

Safari doesn't support the hardware.
Post reply on HN