Live data from Hacker News

Email security on Democratic campaigns is as bad as 2016

washingtonpost.com

91–100 of 114 posts

Re: Email security on Democratic campaigns is as bad as 2016

#91

Earlier quoted context omitted.

I wrote the article. In what way do you think the email server is germane?

On a different topic, is it your impression that other political parties are better at email security than the Democrats? If so, why is that? If not, why is the media focus on Democrats?

>other political parties ... than the Democrats

plural "other parties" :)

Re: Email security on Democratic campaigns is as bad as 2016

#92
I work in digital D politics professionally. I can't tell you how many Congressman use multiple @yahoo or whatever personal email accounts, social, and wordpress accounts with very guessable and repeated passwords. Even the young 'savvy' ones.

And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc.

We enforce 2fa for our consultancy staff. I would love to enforce it for campaigns but I can guarantee endless problems and troubleshooting especially needy candidates calling because they can't figure out how to get their email.

Another big problem is shitty wordpress sites filled with plugins. Literally I see $10k sites (FEC reports!) designed using a $100 paid drag and drop theme with even more plugins thrown on top. It's a big pet peeve of mine and when I can I move clients to a static plain html site hosted on s3 or similar.

My big concern here is if you have write access to wordpress I could see a scenario where you could upload say verification-hash.html and then reclaim ownership of a domain or regain access to email. Or perhaps some turst attack domain.com/my-innocent-file-has-virus.file

The main D voter file GUI (votebuilder) which all campaigns use to contact voters and work with voterfile data does have 2fa but it's still only SMS. This is my real name so I don't want to throw too much public shade, but let's just say when I have to work with campaign data stored in van first thing I do is export out.

ActBlue which is increasingly the monopoly online fundraising app in my experience has good engineering and for me personally they are the only 'tech' provider for Dems that I jive with (don't get me started on NGPVAN or maybe do, but over PM). AB has 2fa token support, though they should make it mandatory given that if you have AB login access you can do a lot of damage (I've actually had this conversation with them about campaign provided js that shows up on donate pages, putting on separate cookie domain, iframe etc).

Re: Email security on Democratic campaigns is as bad as 2016

#93

Earlier quoted context omitted.

Didn't Google implement before the browser integration APIs spec was final? If so, I totally understand a migration period, and it's nothing to hold against them.

Google UA sniffed on Gmail to exclude Firefox (and every browser that wasn't specifically Chrome). And there shouldn't be a "migration period" that holds the entire feature hostage until browsers implement Chrome-specific stuff.

My memory was that Firefox had implemented a newer draft (or final version?) of the spec. Sniffing the UA to avoid providing broken stuff to people isn't exactly evil.

Re: Email security on Democratic campaigns is as bad as 2016

#94

I work in digital D politics professionally. I can't tell you how many Congressman use multiple @yahoo or whatever personal email accounts, social, and wordpress accounts with very guessable and repeated passwords. Even the young 'savvy' ones. And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc. We enforce 2fa for our consultancy staff.…

> We enforce 2fa for our consultancy staff.

What kind of 2FA and how are you doing it?

Re: Email security on Democratic campaigns is as bad as 2016

#95
post #94

I work in digital D politics professionally. I can't tell you how many Congressman use multiple @yahoo or whatever personal email accounts, social, and wordpress accounts with very guessable and repeated passwords. Even the young 'savvy' ones. And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc. We enforce 2fa for our consultancy staff.…

> We enforce 2fa for our consultancy staff. What kind of 2FA and how are you doing it?

Google authenticator app

Re: Email security on Democratic campaigns is as bad as 2016

#96

I work in digital D politics professionally. I can't tell you how many Congressman use multiple @yahoo or whatever personal email accounts, social, and wordpress accounts with very guessable and repeated passwords. Even the young 'savvy' ones. And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc. We enforce 2fa for our consultancy staff.…

Thank you for this very informative comment!

Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?

Re: Email security on Democratic campaigns is as bad as 2016

#97

Earlier quoted context omitted.

I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).

Seems like the threshold for caring if a staffer loses email access was crossed when the DNC got hacked. Seems more reasonable to lose an account to a damaged key than to lose an election.

Having your finance manager lose access to spreadsheets for four days is also not tenable. The trade-offs are complicated here.

Re: Email security on Democratic campaigns is as bad as 2016

#98

I work in digital D politics professionally. I can't tell you how many Congressman use multiple @yahoo or whatever personal email accounts, social, and wordpress accounts with very guessable and repeated passwords. Even the young 'savvy' ones. And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc. We enforce 2fa for our consultancy staff.…

Thank you for this very informative comment! Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?

I mean the government doesn't take on basic IT security responsibilities for corporations. It's up to each campaign.

The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race.

If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction from govt to politics would be perceived as interfering with political speech/democracy.

Re: Email security on Democratic campaigns is as bad as 2016

#99

Interesting comparing this with the Risky Business interview with Bob Lord (the incoming CSO for the DNC) a few weeks back. There seems to be a bit of a disconnect between the security posture of the DNC and the individual campaigns discussed in this story. https://risky.biz/510_feature/

I think the problem is at DCCC, which is supposed to be the liaison for Congressional campaigns.

Re: Email security on Democratic campaigns is as bad as 2016

#100
post #87

Earlier quoted context omitted.

I'm arguing that it's a nonstarter to hand campaign staff who had not heard of security keys at the start of the meeting an easily breakable dongle and say this is the only way to get in to your email now; don't lose it. They need fallbacks (like security codes or Google Authenticator).

... that's why you have backup security keys, numbered per account, in a safe in campaign offices.

One of the candidates I've trained tours his district full-time in a campaign Winnebago, and doesn't have a campaign office. He interacts with his staff mostly remotely. Almost every candidate is constantly on the road.

It's not that people are lazy or feckless. This is a genuinely hard problem for working campaigns to solve. It's a fascinating environment.

Post reply on HN