I'd have thought that would deserve at least a little coverage.
Email security on Democratic campaigns is as bad as 2016
21–30 of 114 posts
Re: Email security on Democratic campaigns is as bad as 2016
#22This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
Re: Email security on Democratic campaigns is as bad as 2016
#23Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.
Re: Email security on Democratic campaigns is as bad as 2016
#24This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
Another is that GSuite doesn't protect people's personal accounts, which is the big risk here.
APP is nice in theory, but I don't believe it's workable in practice for Congressional campaigns. The keys break too easily, and there is no fallback if they are lost or broken. We have one candidate trying out APP and I'll be eager to hear her feedback. But for the time being, just getting them onto 2FA with yubikeys maxes out people's mental budget for "security stuff".
Re: Email security on Democratic campaigns is as bad as 2016
#25Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.
Re: Email security on Democratic campaigns is as bad as 2016
#26This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
Since support for APP seems to be limited to specific browsers/hardware, why not at least do TFA with a one-time passcode app? That seems to be much more widely supported, and it considerably better than whatever they may/may not be doing today..
Re: Email security on Democratic campaigns is as bad as 2016
#27This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
actually, they do all have gsuite! at least when i worked for them in 2016.
Re: Email security on Democratic campaigns is as bad as 2016
#28I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually…
People think PGP is important for campaigns because they want it to be important, not because there's any empirical evidence that it is important.
Re: Email security on Democratic campaigns is as bad as 2016
#29Re: Email security on Democratic campaigns is as bad as 2016
#30Earlier quoted context omitted.
You don't need to MITM anything if your campaign manager uses the password "joealison10231997" for every website.
Yeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe email attachments, destroying systems with ransomware, and so on. Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost…