Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

11–20 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#11
post #9
post #5

Earlier quoted context omitted.

I seem to remember Podesta, whose email was leaked, was already using GMail, either because the campaign used it, or he was using a personal account. Activating 2-factor auth would probably have stopped the attack. It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outrag…

I wonder if the reaction to the hacking would have been different if dirt was found. A greater good argument might have prevailed even though it was a crime, like it the public generally has sympathy for Snowden. Breaking in and finding nothing just looks bad from top to bottom though for the hackers and those associated.

The greater good argument already prevailed with a big chunk of the country. Whether the dirt was real or outlandish made-up satanism allegations didn't wind up mattering.

Turns out you can hack an inbox and claim it contained anything. People won't read. They just want their tribal allegiances confirmed.

Re: Email security on Democratic campaigns is as bad as 2016

#12

I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually…

You don't need to MITM anything if your campaign manager uses the password "joealison10231997" for every website.

Re: Email security on Democratic campaigns is as bad as 2016

#13

Earlier quoted context omitted.

Curious why Google requires their users to use Chrome or Firefox but can't use Safari to access Google Services when enrolled in that program? "And you will only be able to use Chrome and Firefox to access your signed-in Google services like Gmail or Photos." I could see them just requiring Chrome but curious why they would block Safari over Firefox.

Safari doesn't support the hardware.

Uh, what?

Re: Email security on Democratic campaigns is as bad as 2016

#14

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

actually, they do all have gsuite! at least when i worked for them in 2016.

Probably not the using the Advanced Protection Program, though. It would have made the accounts much harder to break into since you need a physical key to log in to the account.

Re: Email security on Democratic campaigns is as bad as 2016

#15

I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually…

You don't need to MITM anything if your campaign manager uses the password "joealison10231997" for every website.

Yeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe email attachments, destroying systems with ransomware, and so on.

Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost data. Consider how many people have lost old bitcoin wallets, containing small fortunes, and similar tails of woe.

But look at how that plays out. A dropped bitcoin wallet, gone forever. The failure mode of something like that is often a better look than things going the other way. Imagine that same bitcoin wallet getting stolen, and seeing the thief profit from it. Sort of like watching elections get stolen, no?

So, think about that, the next time you warn someone against forcing you to exchange PGP keys, in order to communicate more securely.

Re: Email security on Democratic campaigns is as bad as 2016

#17

Earlier quoted context omitted.

Uh, what?

The Advanced Protection program requires a U2F security key. Safari doesn't support it.

Thanks. Hopefully this will be solved when they adopt Web Authentication?

Re: Email security on Democratic campaigns is as bad as 2016

#18
post #5

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

I seem to remember Podesta, whose email was leaked, was already using GMail, either because the campaign used it, or he was using a personal account. Activating 2-factor auth would probably have stopped the attack. It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outrag…

https://en.wikipedia.org/wiki/Podesta_emails#Presidential_de...

Re: Email security on Democratic campaigns is as bad as 2016

#19
post #4

Note the plural: campaigns , hinting at the explanation: There are many campaigns, and they operate entirely independent from each other, at least when it comes to technology infrastructure. The reason for that is something that HN would usually respect, namely the attempt to keep ownership of information. So of course the old discussion about cloud services is being replayed here: "Why would you trust Google?" / "Wh…

I'd say the reason is closer to parochialism and/or intraparty rivalry in primaries. The beginning of every campaign is buying information and the end is selling it.

Ever donate to a candidate? Notice an increase in emails from same-party candidates afterwards?

Re: Email security on Democratic campaigns is as bad as 2016

#20

I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually…

PGP is so easy to use that the first day I attempted to configure it, I accidentally emailed my friends my private, rather than public, key.

I await the day that a great PGP client for everyone might emerge, but I'm not sure that it is possible, nor am I certain that people will want it. There is substantial utility involved in letting Google read all of my email for spam/malware filtering and more.

Post reply on HN