Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

81–90 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#81
Interesting comparing this with the Risky Business interview with Bob Lord (the incoming CSO for the DNC) a few weeks back. There seems to be a bit of a disconnect between the security posture of the DNC and the individual campaigns discussed in this story.

https://risky.biz/510_feature/

Re: Email security on Democratic campaigns is as bad as 2016

#82
post #68

Earlier quoted context omitted.

You can downvote all you want, but you're simply matadoring behavioral issues as if they are technical hurtles, and that's dishonest.

"Matadoring the technical hurtles" should be some startup's slogan.

Matadoring behavioral issues is my bands name.

Re: Email security on Democratic campaigns is as bad as 2016

#83

Earlier quoted context omitted.

Private servers can be secure, that's not really relevant to the issues being discussed in the article.

But if the situation was reversed and Trump was the email server bandit this thread would be 50% hate on Trump posts. Thats just how it is on HN.

Citation needed

Re: Email security on Democratic campaigns is as bad as 2016

#84

Earlier quoted context omitted.

You can opt in personal accounts to APP can't you? Or are you just saying it's not easy to enforce?

I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).

Seems like the threshold for caring if a staffer loses email access was crossed when the DNC got hacked.

Seems more reasonable to lose an account to a damaged key than to lose an election.

Re: Email security on Democratic campaigns is as bad as 2016

#85
post #38

Earlier quoted context omitted.

They're trying to protect work-related communications. These can be separated from personal accounts.

I've been working on sensitive projects with trained professionals for 2 decades and have watched how hard it is for people to keep personal computing resources and professional ones separate. The idea that campaign staffers would be required to maintain a level of OPSEC that IT security people can't reliably maintain seems unrealistic and unproductive. I think people have a broken idea of what a congressional campai…

this is exactly it.

work related emails already are on gsuite. yeah they could require 2FA and other stuff, but the more friction, the more people will fall back on personal emails.

Campaign workers have like 2 days of training total. it is what it is. Even at high levels of staff, many are on sabbatical from their main careers.

Though, if there was a moment for behavior change, this would be it.

Really, it might be easiest to get campaign staff on some secure messaging app instead of email, cause trying to explain different levels of email security will simply go over laypersons heads. My region of staffers all used GroupMe -- I wouldn't be surprised if the DNC doubles down on Slack or something similar.

Re: Email security on Democratic campaigns is as bad as 2016

#86
post #74

This may sound a bit glib but the Democrats should just get a contract with Google, give all of their people GSuite accounts, and enroll them in the Advanced Protection Program[0]. It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure. [0] https://landing.google.com/advancedprotection/

No Democratic organization (DNC, DSCC, DCCC, OFA) really holds sway over campaigns. The DCCC would basically never say "hey, use these 2FA dongles or we're not sending money" to a competitive campaign, and they definitely can't do that over personal accounts ("hey ditch Yahoo! or we're not running any ads"). Maybe they should, it's debatable, but there's a lot of things we should do that are on the spectrum of "unimp…

The main DSCC and DCCC can and will force campaigns to use approved vendors and they could very easily enforce google apps. This only works where they provide $ or staff though as leverage. But generally I think carrot works better than stick

Re: Email security on Democratic campaigns is as bad as 2016

#87

Earlier quoted context omitted.

You can opt in personal accounts to APP can't you? Or are you just saying it's not easy to enforce?

I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).

... that's why you have backup security keys, numbered per account, in a safe in campaign offices.

Re: Email security on Democratic campaigns is as bad as 2016

#88
post #4

Note the plural: campaigns , hinting at the explanation: There are many campaigns, and they operate entirely independent from each other, at least when it comes to technology infrastructure. The reason for that is something that HN would usually respect, namely the attempt to keep ownership of information. So of course the old discussion about cloud services is being replayed here: "Why would you trust Google?" / "Wh…

One of the interesting experiments of the 2016 election was that all local and national campaigns were rolled into one Coordinated Campaign. With shared offices/tech/infrastructure.

That brings downsides, but also upsides: it becomes feasible to give everyone a standard security solution for tech.

Still hard to train everyone to use it, but not impossible.

Re: Email security on Democratic campaigns is as bad as 2016

#90

Earlier quoted context omitted.

That does not guard against the phishing scenario that is one of the biggest threats to campaigns. Any kind of two-factor auth short of a security key is inadequate against that threat.

Why do we need a physical key though? Why don't browsers communicate the url to the password/totp app, and the app only respond or allow fill-ins for matching domains?

Because phones aren't trustworthy. Operating systems can be hacked, privileges can be granted to flawed apps, etc. U2F hardware is single-purpose with a trusted stack end to end.
Post reply on HN