Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

111–114 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#111

Earlier quoted context omitted.

The main DSCC and DCCC can and will force campaigns to use approved vendors and they could very easily enforce google apps. This only works where they provide $ or staff though as leverage. But generally I think carrot works better than stick

Kind of and in some cases sure (most obvious is union printing), but if a campaign says "no", really all the DCCC can do is threaten to pull resources (which they wouldn't for a competitive campaign). Really this happens more as advice and political pressure. But also consider downticket races like secretary of state or state ag. Then you're talking state parties who have almost no power at all. So yeah I think carro…

Do you work in politics? My experience working with these orgs is you're either on the approved vendor list or your not getting competitive clients

Re: Email security on Democratic campaigns is as bad as 2016

#112

Earlier quoted context omitted.

Thank you for this very informative comment! Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?

I mean the government doesn't take on basic IT security responsibilities for corporations. It's up to each campaign. The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race. If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction…

I'm a little conflicted on this. Clearly if we leave security to political parties, for many reasons we can expect poor security in IT, which leaves our very democracy vulnerable.

On the other hand, imagine the government mandating "if you run for office, you and everyone in your campaign must use this email for all communications, and if you communicate electronically outside of these approved methods we'll come down on you". The number of ways that could be misused is mind-boggling. Even if it isn't used to sniff on the communications of the opposition, it could simply be raised to higher and higher levels of complexity (and perhaps $$ cost) until new political parties (or insurgencies within a party) cannot afford to compete, because the legal requirements for IT are too stringent.

Re: Email security on Democratic campaigns is as bad as 2016

#113

Earlier quoted context omitted.

Kind of and in some cases sure (most obvious is union printing), but if a campaign says "no", really all the DCCC can do is threaten to pull resources (which they wouldn't for a competitive campaign). Really this happens more as advice and political pressure. But also consider downticket races like secretary of state or state ag. Then you're talking state parties who have almost no power at all. So yeah I think carro…

Do you work in politics? My experience working with these orgs is you're either on the approved vendor list or your not getting competitive clients

Would you be willing to chat about approved vendors? I can't find your email, but here's mine: derrick@amass.ai

My team did some work for the KS04 special election last year, and now we've developed a service for political campaigns. But traction.. maybe we're getting screwed by this approved vendors thing.

Re: Email security on Democratic campaigns is as bad as 2016

#114

Earlier quoted context omitted.

I mean the government doesn't take on basic IT security responsibilities for corporations. It's up to each campaign. The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race. If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction…

I'm a little conflicted on this. Clearly if we leave security to political parties, for many reasons we can expect poor security in IT, which leaves our very democracy vulnerable. On the other hand, imagine the government mandating "if you run for office, you and everyone in your campaign must use this email for all communications, and if you communicate electronically outside of these approved methods we'll come dow…

I think that's the bigger issue than disparate organization complexity/scale (which is a huge hurdle).

Political speech is sacrosanct and despite being pretty liberal I agree with your skepticism of Government. Not so much that it would ever be used for bad, but I think far more likely it just becomes a huge, slow, shitty mess.

Post reply on HN