Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

21–30 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#22

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

Since support for APP seems to be limited to specific browsers/hardware, why not at least do TFA with a one-time passcode app? That seems to be much more widely supported, and it considerably better than whatever they may/may not be doing today..

Re: Email security on Democratic campaigns is as bad as 2016

#23

Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.

Are you familiar with the term 'beating a dead horse'? There's absolutely no chance of having a productive discussion around that topic. Everyone knows that what she did was bad, it's now illegal, the ship has sailed, move on.

Re: Email security on Democratic campaigns is as bad as 2016

#24

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

There are a couple of problems with this (and it's a good question!). One is that many campaigns are just small and don't have any in-house IT expertise, even the kind needed to run GSuite.

Another is that GSuite doesn't protect people's personal accounts, which is the big risk here.

APP is nice in theory, but I don't believe it's workable in practice for Congressional campaigns. The keys break too easily, and there is no fallback if they are lost or broken. We have one candidate trying out APP and I'll be eager to hear her feedback. But for the time being, just getting them onto 2FA with yubikeys maxes out people's mental budget for "security stuff".

Re: Email security on Democratic campaigns is as bad as 2016

#25

Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.

I wrote the article. In what way do you think the email server is germane?

Re: Email security on Democratic campaigns is as bad as 2016

#26

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

Since support for APP seems to be limited to specific browsers/hardware, why not at least do TFA with a one-time passcode app? That seems to be much more widely supported, and it considerably better than whatever they may/may not be doing today..

That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.

Re: Email security on Democratic campaigns is as bad as 2016

#27

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

actually, they do all have gsuite! at least when i worked for them in 2016.

What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)

Re: Email security on Democratic campaigns is as bad as 2016

#28

I think that's because email, fundamentally just isn't very secure. Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually…

PGP addresses literally none of the operational security problems congressional campaigns have. No matter how you protect individual emails, for most users (and probably every single congressional campaign staffer) your email account is still the most important account you have, the key to every other account you control. And PGP doesn't do a thing about incoming emails with malicious attachments.

People think PGP is important for campaigns because they want it to be important, not because there's any empirical evidence that it is important.

Re: Email security on Democratic campaigns is as bad as 2016

#29

Earlier quoted context omitted.

The Advanced Protection program requires a U2F security key. Safari doesn't support it.

Thanks. Hopefully this will be solved when they adopt Web Authentication?

If Apple doesn't come up with an alternative iAuth NIH "standard".

Re: Email security on Democratic campaigns is as bad as 2016

#30

Earlier quoted context omitted.

You don't need to MITM anything if your campaign manager uses the password "joealison10231997" for every website.

Yeah, there's no accounting for glaring cluelessness. Leaving S3 buckets open to the world, and totally unencrypted, for example. Downloading and running *.exe email attachments, destroying systems with ransomware, and so on. Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost…

U2F keys were invented in part because the glaringly clueless employees at Google were routinely shown to be phishable. People who dismiss phishing as a threat vector betray a lack of understanding of how difficult it is to mitigate reliably.
Post reply on HN