This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
Email security on Democratic campaigns is as bad as 2016
31–40 of 114 posts
Re: Email security on Democratic campaigns is as bad as 2016
#32Earlier quoted context omitted.
Thanks. Hopefully this will be solved when they adopt Web Authentication?
If Apple doesn't come up with an alternative iAuth NIH "standard".
Re: Email security on Democratic campaigns is as bad as 2016
#33Earlier quoted context omitted.
Since support for APP seems to be limited to specific browsers/hardware, why not at least do TFA with a one-time passcode app? That seems to be much more widely supported, and it considerably better than whatever they may/may not be doing today..
That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.
What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate.
I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..). If you choose a solution that might be technically superior but require people to make major workflow changes, you'll find they won't use it. TFA seems like a good compromise to me, so I'd really like to understand why you think it is not.
Re: Email security on Democratic campaigns is as bad as 2016
#34Earlier quoted context omitted.
That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.
> the phishing scenario that is one of the biggest threats to campaigns What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate. I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..).…
If I do the same and your second factor is a security key, I get a useless binary blob that I can't turn around and hand to Google.
The U2F key gets the actual URL of the page you are on from the browser, so it can't be fooled by impostor websites, however clever. That's the difference, and the reason that Google moved their employees onto security keys. Too many people were getting phished otherwise.
Re: Email security on Democratic campaigns is as bad as 2016
#35Earlier quoted context omitted.
actually, they do all have gsuite! at least when i worked for them in 2016.
What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)
Re: Email security on Democratic campaigns is as bad as 2016
#36This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
APP is great if you're traveling abroad or if there is a specific threat you need to mitigate for a few weeks, but it's not really a viable longterm solution since it disables all of the third-party apps that candidates need to use for their campaigns. For the average candidate, they're going to improve their chances of winning much more by using a CRM than by forgoing its use on the off chance a state-sponsored atta…
Re: Email security on Democratic campaigns is as bad as 2016
#37Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.
Re: Email security on Democratic campaigns is as bad as 2016
#38Earlier quoted context omitted.
What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)
They're trying to protect work-related communications. These can be separated from personal accounts.
I think people have a broken idea of what a congressional campaign actually is. It's not an enterprise with a security team. It's a bunch of random people working together for a year or so, and only for a few months full time, at that. That's what makes them targets. Whatever our industry does to protect campaigns needs to engage with the reality of what a campaign is, rather than pretending they're all credit scoring firms that should have known better than to not spend all of their $13,000,000 security budget this year.
Re: Email security on Democratic campaigns is as bad as 2016
#39Amazing that the article contained not one word about Hillary Clinton's private email server. I'd have thought that would deserve at least a little coverage.
Private servers can be secure, that's not really relevant to the issues being discussed in the article.
Thats just how it is on HN.
Re: Email security on Democratic campaigns is as bad as 2016
#40Earlier quoted context omitted.
What we're trying to protect here is people's personal accounts. So even campaigns that use GSuite have people's personal stuff just on random Gmail (or Yahoo, or AOL...)
They're trying to protect work-related communications. These can be separated from personal accounts.
The Podesta emails show how much more mileage attackers got out of drama than substance.