Earlier quoted context omitted.
Wow, so, you really believe that asking people to lock up their important messages to you, using a public key that you've provided through a verified, alternate non-email channel really won't work? PGP actually does do something about incoming email attachments. It offers the opportunity to programmatically reject anything that is non-encrypted ASCII text, and renders malicious files as non-executable ASCII text, whe…
You can downvote all you want, but you're simply matadoring behavioral issues as if they are technical hurtles, and that's dishonest.
Email security on Democratic campaigns is as bad as 2016
101–110 of 114 posts
Re: Email security on Democratic campaigns is as bad as 2016
#102Earlier quoted context omitted.
Thank you for this very informative comment! Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?
I mean the government doesn't take on basic IT security responsibilities for corporations. It's up to each campaign. The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race. If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction…
Re: Email security on Democratic campaigns is as bad as 2016
#103Earlier quoted context omitted.
... that's why you have backup security keys, numbered per account, in a safe in campaign offices.
One of the candidates I've trained tours his district full-time in a campaign Winnebago, and doesn't have a campaign office. He interacts with his staff mostly remotely. Almost every candidate is constantly on the road. It's not that people are lazy or feckless. This is a genuinely hard problem for working campaigns to solve. It's a fascinating environment.
Look, even security keys may not provide "enough" security. An adversary capable of performing a targeted, in-physical-range attack will be able to sneak a keylogger onto a staffer's laptop (to steal the password) and then take advantage of an opportunity where the security key isn't guarded to swipe the security key for either momentary access or to register the attacker's key for long term access - which won't be caught without persistent auditing efforts, which most campaigns won't do. As always, the question is "how do we raise the cost of an attack while keeping the cost of defense relatively low" and that's what security keys do really well.
Edit: look, specific campaigns may have different ways of adopting the pattern. Maybe the candidate without a dedicated campaign office could keep the keys in a safe in the candidate's home. Maybe national candidates / candidates whose staffers would need to drive for an unreasonable amount of time to get a replacement key, maybe there can be local caches of keys in different cities, where some independent business figures out a way to register numbered security keys for online accounts in a relatively anonymous way for both remote businesses and whoever else. Still doesn't mean that security keys are a bad idea.
Re: Email security on Democratic campaigns is as bad as 2016
#104any word on Republican campaign security?
Re: Email security on Democratic campaigns is as bad as 2016
#105Earlier quoted context omitted.
The standard political nomenclature is "bundler", but I don't think I've ever witnessed a bundler describing himself as such. They prefer euphemism.
You can call me a bundler if you want, but I believe that term means something different than what I do. This site, of all places, should respect technical terminology!
What would have to change about that description to make it the description of the actions of a bundler?
Re: Email security on Democratic campaigns is as bad as 2016
#106Earlier quoted context omitted.
No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimp…
The main DSCC and DCCC can and will force campaigns to use approved vendors and they could very easily enforce google apps. This only works where they provide $ or staff though as leverage. But generally I think carrot works better than stick
But also consider downticket races like secretary of state or state ag. Then you're talking state parties who have almost no power at all.
So yeah I think carrot is definitely better than stick, but there basically is no stick. I do think the DCCC should set up gapps for every general campaign and provide it for free, and should probably also offer it to professional Democrats, also for free, but this is a larger tech infrastructure question that starts to include organizing tech, website tech, VAN, email tech, etc. I personally think we should provide all those things, but there are a lot of (vendor, of course) politics involved, it's not cheap, and things like 2FA are so far down the list you can't see them. Again I think we agree, I just think a lot of people think the party controls campaigns and that's largely not the case, and even when it is there are arguably more urgent issues (campaign finance law training, ex) that could benefit from any kind of standardization.
Re: Email security on Democratic campaigns is as bad as 2016
#107Earlier quoted context omitted.
Thank you for this very informative comment! Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?
I mean the government doesn't take on basic IT security responsibilities for corporations. It's up to each campaign. The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race. If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction…
Couldn't the DHS provide recommendations (e.g. practices, particular providers and configurations), and the parties provide turnkey solutions to their candidates and elected officials?
It seems foolish to leave such decisions up to such small, short-term groups that shouldn't be expected to have the IT expertise to pick a good vendor.
Re: Email security on Democratic campaigns is as bad as 2016
#108Earlier quoted context omitted.
One of the candidates I've trained tours his district full-time in a campaign Winnebago, and doesn't have a campaign office. He interacts with his staff mostly remotely. Almost every candidate is constantly on the road. It's not that people are lazy or feckless. This is a genuinely hard problem for working campaigns to solve. It's a fascinating environment.
That doesn't mean that his campaign staff are going to constantly lose their security keys. Losing a security key is an infrequent-enough occurrence that the inconvenience of needing to go to campaign headquarters to get a new key shouldn't be too onerous, not to mention that the inconvenience of showing up in person to get a new key serves as the real motivator not to lose the key in the first place. Look, even secu…
Re: Email security on Democratic campaigns is as bad as 2016
#109Earlier quoted context omitted.
You can call me a bundler if you want, but I believe that term means something different than what I do. This site, of all places, should respect technical terminology!
...I began visiting rural congressional campaigns to help progressive candidates with fundraising. As a self-employed programmer, I was able to travel and serve as a kind of political truffle pig for tech workers who wanted to donate to candidates but didn’t know where to begin. What would have to change about that description to make it the description of the actions of a bundler?
I tweet about campaigns and people I don't know give or not based on that. The modal donation is something like $50.
If that's "bundling", I'm fine with the term. But in my eyes bundling is showing up at a campaign office knowing how much you can deliver, and from whom.
Re: Email security on Democratic campaigns is as bad as 2016
#110Earlier quoted context omitted.
...I began visiting rural congressional campaigns to help progressive candidates with fundraising. As a self-employed programmer, I was able to travel and serve as a kind of political truffle pig for tech workers who wanted to donate to candidates but didn’t know where to begin. What would have to change about that description to make it the description of the actions of a bundler?
My understanding of a bundler is someone who delivers high-dollar donations aggregated from a bloc of wealthy donors. I tweet about campaigns and people I don't know give or not based on that. The modal donation is something like $50. If that's "bundling", I'm fine with the term. But in my eyes bundling is showing up at a campaign office knowing how much you can deliver, and from whom.