Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

31–40 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#31

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

APP is great if you're traveling abroad or if there is a specific threat you need to mitigate for a few weeks, but it's not really a viable longterm solution since it disables all of the third-party apps that candidates need to use for their campaigns. For the average candidate, they're going to improve their chances of winning much more by using a CRM than by forgoing its use on the off chance a state-sponsored attacker tries to steal their data from Intercom or HubSpot or whatever. When you're starting out with zero supporters and zero dollars and need to somehow connect with over 50% of voters within the span of a few months, it just isn't a super realistic trade off to make. Especially when you can enable almost all of the same security features piecemeal without it.

Re: Email security on Democratic campaigns is as bad as 2016

#32

Earlier quoted context omitted.

Thanks. Hopefully this will be solved when they adopt Web Authentication?

If Apple doesn't come up with an alternative iAuth NIH "standard".

https://webkit.org/status/#feature-web-authentication

Re: Email security on Democratic campaigns is as bad as 2016

#33

Earlier quoted context omitted.

Since support for APP seems to be limited to specific browsers/hardware, why not at least do TFA with a one-time passcode app? That seems to be much more widely supported, and it considerably better than whatever they may/may not be doing today..

That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.

> the phishing scenario that is one of the biggest threats to campaigns

What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate.

I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..). If you choose a solution that might be technically superior but require people to make major workflow changes, you'll find they won't use it. TFA seems like a good compromise to me, so I'd really like to understand why you think it is not.

Re: Email security on Democratic campaigns is as bad as 2016

#34

Earlier quoted context omitted.

That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.

> the phishing scenario that is one of the biggest threats to campaigns What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate. I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..).…

If I show you an impostor website purporting to be Gmail, and get you to type in your password plus authenticator code / SMS code / app notification code, I can get into your email account.

If I do the same and your second factor is a security key, I get a useless binary blob that I can't turn around and hand to Google.

The U2F key gets the actual URL of the page you are on from the browser, so it can't be fooled by impostor websites, however clever. That's the difference, and the reason that Google moved their employees onto security keys. Too many people were getting phished otherwise.

Re: Email security on Democratic campaigns is as bad as 2016

#35

Earlier quoted context omitted.

actually, they do all have gsuite! at least when i worked for them in 2016.

What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)

They're trying to protect work-related communications. These can be separated from personal accounts.

Re: Email security on Democratic campaigns is as bad as 2016

#36

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

APP is great if you're traveling abroad or if there is a specific threat you need to mitigate for a few weeks, but it's not really a viable longterm solution since it disables all of the third-party apps that candidates need to use for their campaigns. For the average candidate, they're going to improve their chances of winning much more by using a CRM than by forgoing its use on the off chance a state-sponsored atta…

Anecdotally: there are campaigns using APP, and it apparently hasn't been problematic in that regard.

Re: Email security on Democratic campaigns is as bad as 2016

#37

Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.

Private servers can be secure, that's not really relevant to the issues being discussed in the article.

Re: Email security on Democratic campaigns is as bad as 2016

#38

Earlier quoted context omitted.

What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)

They're trying to protect work-related communications. These can be separated from personal accounts.

I've been working on sensitive projects with trained professionals for 2 decades and have watched how hard it is for people to keep personal computing resources and professional ones separate. The idea that campaign staffers would be required to maintain a level of OPSEC that IT security people can't reliably maintain seems unrealistic and unproductive.

I think people have a broken idea of what a congressional campaign actually is. It's not an enterprise with a security team. It's a bunch of random people working together for a year or so, and only for a few months full time, at that. That's what makes them targets. Whatever our industry does to protect campaigns needs to engage with the reality of what a campaign is, rather than pretending they're all credit scoring firms that should have known better than to not spend all of their $13,000,000 security budget this year.

Re: Email security on Democratic campaigns is as bad as 2016

#39

Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.

Private servers can be secure, that's not really relevant to the issues being discussed in the article.

But if the situation was reversed and Trump was the email server bandit this thread would be 50% hate on Trump posts.

Thats just how it is on HN.

Re: Email security on Democratic campaigns is as bad as 2016

#40

Earlier quoted context omitted.

What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)

They're trying to protect work-related communications. These can be separated from personal accounts.

No, it's the stuff in the personal accounts that's a more interesting target. You're trying to dredge up stuff on J. Random Candidate (or their manager, or staffer) that will distract and derail the campaign. Pictures of someone doing a bong rip in college, details of interpersonal drama, that kind of thing.

The Podesta emails show how much more mileage attackers got out of drama than substance.

Post reply on HN