Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

71–80 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#71
post #65

Earlier quoted context omitted.

Interesting. I wonder if they're just using browser extensions though to get the same functionality? Since if you have any browser plug-ins installed (e.g. AdBlock), you've got the same potential issue.

Here I will defer to everyone else who knows more about APP than I do; that one tidbit I brought up was related to me by an HN-phobe who didn't want to say it themselves. :)

Yeah I don't know much about APP. As far as I know, no one does; there doesn't seem to be any information at all about what OAuth scopes (if any) are allowed.

In general though I think we'd be better off with Google just adding more restrictive OAuth scopes and improving their logging functionality so that users can see how apps are using their data. I'm clearly biased since my app is built on Gmail OAuth, but I generally just think that for whatever issues OAuth has, pushing people toward browser extensions or IMAP is a step in the wrong direction.

Re: Email security on Democratic campaigns is as bad as 2016

#72
post #42

Earlier quoted context omitted.

You don't have to verify that your hostname matches the cert. The browser does that for you. That's part of the point.

Not all browsers do that, and many major ones display a warning that users have been trained to click through because of at least a decade of similar browser warnings.

What browsers do not?

Re: Email security on Democratic campaigns is as bad as 2016

#73

Hmm...reading the headline I thought "Wait...Bob Lord works for them, surely everyone there has to have an NFC smart card surgically embedded into their skull at this point, so knowing their passwords is useless??". But then I realized he's at the DNC and the article is about _campaigns_ which presumably are separate organizations?

Yeah. Each campaign is its own (tiny) organization. The group that is supposed to help House campaigns is the DCCC (Democratic Congressional Campaign Committee) and for Senate campaigns, it's the DSCC (Democratic Senatorial Campaign Committee).

Re: Email security on Democratic campaigns is as bad as 2016

#74

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimportant in the grand scheme of things" to "infeasible".

Re: Email security on Democratic campaigns is as bad as 2016

#75

Earlier quoted context omitted.

Not all browsers do that, and many major ones display a warning that users have been trained to click through because of at least a decade of similar browser warnings.

What browsers do not?

NCSA Mosaic 2.0.0 (and all versions prior).

Re: Email security on Democratic campaigns is as bad as 2016

#76
post #74

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimp…

Campaigns I have worked with are generally eager for this kind of training and would gladly accept it if it were offered. They are aware of the hacking threat and feel out of their depth.

I think a good starting point is to simply offer in-person training at key points in the campaign (on filing, after a primary win, and before the general election).

Re: Email security on Democratic campaigns is as bad as 2016

#77
post #38

Earlier quoted context omitted.

I've been working on sensitive projects with trained professionals for 2 decades and have watched how hard it is for people to keep personal computing resources and professional ones separate. The idea that campaign staffers would be required to maintain a level of OPSEC that IT security people can't reliably maintain seems unrealistic and unproductive. I think people have a broken idea of what a congressional campai…

Shouldn't the fact that they're a bunch of random people make it easier to separate work from personal communications?

That would be one way to do it, but it's a lot more effort than "everyone just uses their own email, we never set anything up", which is the default and also free -- and default/zero effort/free is extremely popular. Even if there is an IT setup on a campaign it's not guaranteed everyone will be onboarded onto it. People come and go, balls get dropped, etc.

There are other bonuses to this too. The first that comes to mind are that campaigns are transient; using your own email can help you with document retention requests in the event of lawsuits. But I think mostly that political professionals use their email for a lot of different things, and keeping everything in a single account is a lot more convenient than dealing with multiple campaign accounts.

Re: Email security on Democratic campaigns is as bad as 2016

#78
post #74

Earlier quoted context omitted.

No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimp…

Campaigns I have worked with are generally eager for this kind of training and would gladly accept it if it were offered. They are aware of the hacking threat and feel out of their depth. I think a good starting point is to simply offer in-person training at key points in the campaign (on filing, after a primary win, and before the general election).

Super agree, this would be fantastic. I'm sure there are people at the DNC and elsewhere who would happy to advocate for the (very small amount of) funding it would take -- as you wrote it should be a top priority.

Re: Email security on Democratic campaigns is as bad as 2016

#79

Earlier quoted context omitted.

Google didn't support U2F for Gmail in Firefox for a long time because Chrome was incorrectly implementing the spec [1] and relied on interoperability with their previous proprietary implementation [2] of U2F, and Gmail relied on that. Apple has been a better actor in this regard than Google has, since they are planning to implement the spec as written [3]. [1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1409573 [2…

Didn't Google implement before the browser integration APIs spec was final? If so, I totally understand a migration period, and it's nothing to hold against them.

Google UA sniffed on Gmail to exclude Firefox (and every browser that wasn't specifically Chrome).

And there shouldn't be a "migration period" that holds the entire feature hostage until browsers implement Chrome-specific stuff.

Re: Email security on Democratic campaigns is as bad as 2016

#80

Earlier quoted context omitted.

Not all browsers do that, and many major ones display a warning that users have been trained to click through because of at least a decade of similar browser warnings.

What browsers do not?

Probably `M-x eww`.
Post reply on HN