Email security on Democratic campaigns is as bad as 2016
81–90 of 114 posts
Re: Email security on Democratic campaigns is as bad as 2016
#82Re: Email security on Democratic campaigns is as bad as 2016
#83Earlier quoted context omitted.
Private servers can be secure, that's not really relevant to the issues being discussed in the article.
But if the situation was reversed and Trump was the email server bandit this thread would be 50% hate on Trump posts. Thats just how it is on HN.
Re: Email security on Democratic campaigns is as bad as 2016
#84Earlier quoted context omitted.
You can opt in personal accounts to APP can't you? Or are you just saying it's not easy to enforce?
I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).
Seems more reasonable to lose an account to a damaged key than to lose an election.
Re: Email security on Democratic campaigns is as bad as 2016
#85Earlier quoted context omitted.
They're trying to protect work-related communications. These can be separated from personal accounts.
I've been working on sensitive projects with trained professionals for 2 decades and have watched how hard it is for people to keep personal computing resources and professional ones separate. The idea that campaign staffers would be required to maintain a level of OPSEC that IT security people can't reliably maintain seems unrealistic and unproductive. I think people have a broken idea of what a congressional campai…
work related emails already are on gsuite. yeah they could require 2FA and other stuff, but the more friction, the more people will fall back on personal emails.
Campaign workers have like 2 days of training total. it is what it is. Even at high levels of staff, many are on sabbatical from their main careers.
Though, if there was a moment for behavior change, this would be it.
Really, it might be easiest to get campaign staff on some secure messaging app instead of email, cause trying to explain different levels of email security will simply go over laypersons heads. My region of staffers all used GroupMe -- I wouldn't be surprised if the DNC doubles down on Slack or something similar.
Re: Email security on Democratic campaigns is as bad as 2016
#86This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/
No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimp…
Re: Email security on Democratic campaigns is as bad as 2016
#87Earlier quoted context omitted.
You can opt in personal accounts to APP can't you? Or are you just saying it's not easy to enforce?
I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).
Re: Email security on Democratic campaigns is as bad as 2016
#88Note the plural: campaigns , hinting at the explanation: There are many campaigns, and they operate entirely independent from each other, at least when it comes to technology infrastructure. The reason for that is something that HN would usually respect, namely the attempt to keep ownership of information. So of course the old discussion about cloud services is being replayed here: "Why would you trust Google?" / "Wh…
That brings downsides, but also upsides: it becomes feasible to give everyone a standard security solution for tech.
Still hard to train everyone to use it, but not impossible.
Re: Email security on Democratic campaigns is as bad as 2016
#89Re: Email security on Democratic campaigns is as bad as 2016
#90Earlier quoted context omitted.
That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.
Why do we need a physical key though? Why don't browsers communicate the url to the password/totp app, and the app only respond or allow fill-ins for matching domains?