Email security on Democratic campaigns is as bad as 2016
washingtonpost.com
washingtonpost.com
And I know this because the creds are shared in plain text with multiple people over email (like me) or put into a shared google doc.
We enforce 2fa for our consultancy staff. I would love to enforce it for campaigns but I can guarantee endless problems and troubleshooting especially needy candidates calling because they can't figure out how to get their email.
Another big problem is shitty wordpress sites filled with plugins. Literally I see $10k sites (FEC reports!) designed using a $100 paid drag and drop theme with even more plugins thrown on top. It's a big pet peeve of mine and when I can I move clients to a static plain html site hosted on s3 or similar.
My big concern here is if you have write access to wordpress I could see a scenario where you could upload say verification-hash.html and then reclaim ownership of a domain or regain access to email. Or perhaps some turst attack domain.com/my-innocent-file-has-virus.file
The main D voter file GUI (votebuilder) which all campaigns use to contact voters and work with voterfile data does have 2fa but it's still only SMS. This is my real name so I don't want to throw too much public shade, but let's just say when I have to work with campaign data stored in van first thing I do is export out.
ActBlue which is increasingly the monopoly online fundraising app in my experience has good engineering and for me personally they are the only 'tech' provider for Dems that I jive with (don't get me started on NGPVAN or maybe do, but over PM). AB has 2fa token support, though they should make it mandatory given that if you have AB login access you can do a lot of damage (I've actually had this conversation with them about campaign provided js that shows up on donate pages, putting on separate cookie domain, iframe etc).
What kind of 2FA and how are you doing it?
Who do you think should have overall responsibility for campaign security in 2020? The parties? DHS? Some kind of private sector consortium?
The parties can provide support but there are so many races up and down ballot, plus primaries it's impossible. Plus why should the DCCC or whoever waste resources on some non-winnable tiny race.
If say DHS did get involved proactively there would be huge trust and legal issues; any top down direction from govt to politics would be perceived as interfering with political speech/democracy.
Couldn't the DHS provide recommendations (e.g. practices, particular providers and configurations), and the parties provide turnkey solutions to their candidates and elected officials?
It seems foolish to leave such decisions up to such small, short-term groups that shouldn't be expected to have the IT expertise to pick a good vendor.
On the other hand, imagine the government mandating "if you run for office, you and everyone in your campaign must use this email for all communications, and if you communicate electronically outside of these approved methods we'll come down on you". The number of ways that could be misused is mind-boggling. Even if it isn't used to sniff on the communications of the opposition, it could simply be raised to higher and higher levels of complexity (and perhaps $$ cost) until new political parties (or insurgencies within a party) cannot afford to compete, because the legal requirements for IT are too stringent.
Political speech is sacrosanct and despite being pretty liberal I agree with your skepticism of Government. Not so much that it would ever be used for bad, but I think far more likely it just becomes a huge, slow, shitty mess.
It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure.
It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outraged. This discussion sometimes gets dangerously close to victim blaming.
Turns out you can hack an inbox and claim it contained anything. People won't read. They just want their tribal allegiances confirmed.
I think people have a broken idea of what a congressional campaign actually is. It's not an enterprise with a security team. It's a bunch of random people working together for a year or so, and only for a few months full time, at that. That's what makes them targets. Whatever our industry does to protect campaigns needs to engage with the reality of what a campaign is, rather than pretending they're all credit scoring firms that should have known better than to not spend all of their $13,000,000 security budget this year.
That means no IT support to get that 2FA protected (if you even have it) email account onto your phone. Guess what email they will start using?
There are other bonuses to this too. The first that comes to mind are that campaigns are transient; using your own email can help you with document retention requests in the event of lawsuits. But I think mostly that political professionals use their email for a lot of different things, and keeping everything in a single account is a lot more convenient than dealing with multiple campaign accounts.
work related emails already are on gsuite. yeah they could require 2FA and other stuff, but the more friction, the more people will fall back on personal emails.
Campaign workers have like 2 days of training total. it is what it is. Even at high levels of staff, many are on sabbatical from their main careers.
Though, if there was a moment for behavior change, this would be it.
Really, it might be easiest to get campaign staff on some secure messaging app instead of email, cause trying to explain different levels of email security will simply go over laypersons heads. My region of staffers all used GroupMe -- I wouldn't be surprised if the DNC doubles down on Slack or something similar.
The Podesta emails show how much more mileage attackers got out of drama than substance.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1409573
If so, I totally understand a migration period, and it's nothing to hold against them.
And there shouldn't be a "migration period" that holds the entire feature hostage until browsers implement Chrome-specific stuff.
What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate.
I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..). If you choose a solution that might be technically superior but require people to make major workflow changes, you'll find they won't use it. TFA seems like a good compromise to me, so I'd really like to understand why you think it is not.
If I do the same and your second factor is a security key, I get a useless binary blob that I can't turn around and hand to Google.
The U2F key gets the actual URL of the page you are on from the browser, so it can't be fooled by impostor websites, however clever. That's the difference, and the reason that Google moved their employees onto security keys. Too many people were getting phished otherwise.
Can't this be defeated by DNS poisoning? TLS/HSTS would help, but that assume folks are verifying that the hostname matches the cert... (big assumption)
In any case, I see your point, thank you for explaining it.
Another is that GSuite doesn't protect people's personal accounts, which is the big risk here.
APP is nice in theory, but I don't believe it's workable in practice for Congressional campaigns. The keys break too easily, and there is no fallback if they are lost or broken. We have one candidate trying out APP and I'll be eager to hear her feedback. But for the time being, just getting them onto 2FA with yubikeys maxes out people's mental budget for "security stuff".
Seems more reasonable to lose an account to a damaged key than to lose an election.
It's not that people are lazy or feckless. This is a genuinely hard problem for working campaigns to solve. It's a fascinating environment.
Look, even security keys may not provide "enough" security. An adversary capable of performing a targeted, in-physical-range attack will be able to sneak a keylogger onto a staffer's laptop (to steal the password) and then take advantage of an opportunity where the security key isn't guarded to swipe the security key for either momentary access or to register the attacker's key for long term access - which won't be caught without persistent auditing efforts, which most campaigns won't do. As always, the question is "how do we raise the cost of an attack while keeping the cost of defense relatively low" and that's what security keys do really well.
Edit: look, specific campaigns may have different ways of adopting the pattern. Maybe the candidate without a dedicated campaign office could keep the keys in a safe in the candidate's home. Maybe national candidates / candidates whose staffers would need to drive for an unreasonable amount of time to get a replacement key, maybe there can be local caches of keys in different cities, where some independent business figures out a way to register numbered security keys for online accounts in a relatively anonymous way for both remote businesses and whoever else. Still doesn't mean that security keys are a bad idea.
In general though I think we'd be better off with Google just adding more restrictive OAuth scopes and improving their logging functionality so that users can see how apps are using their data. I'm clearly biased since my app is built on Gmail OAuth, but I generally just think that for whatever issues OAuth has, pushing people toward browser extensions or IMAP is a step in the wrong direction.
I think a good starting point is to simply offer in-person training at key points in the campaign (on filing, after a primary win, and before the general election).
But also consider downticket races like secretary of state or state ag. Then you're talking state parties who have almost no power at all.
So yeah I think carrot is definitely better than stick, but there basically is no stick. I do think the DCCC should set up gapps for every general campaign and provide it for free, and should probably also offer it to professional Democrats, also for free, but this is a larger tech infrastructure question that starts to include organizing tech, website tech, VAN, email tech, etc. I personally think we should provide all those things, but there are a lot of (vendor, of course) politics involved, it's not cheap, and things like 2FA are so far down the list you can't see them. Again I think we agree, I just think a lot of people think the party controls campaigns and that's largely not the case, and even when it is there are arguably more urgent issues (campaign finance law training, ex) that could benefit from any kind of standardization.
My team did some work for the KS04 special election last year, and now we've developed a service for political campaigns. But traction.. maybe we're getting screwed by this approved vendors thing.
The reason for that is something that HN would usually respect, namely the attempt to keep ownership of information. So of course the old discussion about cloud services is being replayed here: "Why would you trust Google?" / "Why do you think my small company has better security than Google" / ...
I'm pretty sure their next presidential candidate will activate 2-factor authentication etc.
Ever donate to a candidate? Notice an increase in emails from same-party candidates afterwards?
That brings downsides, but also upsides: it becomes feasible to give everyone a standard security solution for tech.
Still hard to train everyone to use it, but not impossible.
It's very hard to move people entirely off of email. A big part of campaign security training is to move people onto Signal or Whatsapp, though, and I'm glad you brought it up.
What would have to change about that description to make it the description of the actions of a bundler?
I tweet about campaigns and people I don't know give or not based on that. The modal donation is something like $50.
If that's "bundling", I'm fine with the term. But in my eyes bundling is showing up at a campaign office knowing how much you can deliver, and from whom.
Lots of email servers support fallback to non-encrypted, plaintext transmission, which can expose entire chains of replies to MITM attacks with a single message being routed questionably. [0,1,2] End-to-end encryption, via user-defined keys is actively discouraged by those who might assuredly know better, and be in a position to change minds. Usually, the cop out comes in the form of "too complicated for non-technical/less-technical users, and thus potentially harmful to profits."
As if to say, we've been espousing the use of an insecure method of communication for decades, so, to suddenly reverse our position, and encourage bring-your-own-encryption might provoke discussions of liability, or something. Nevermind, the premise of ad tech and scanning user messages, to sell data.
But you know, running your own server, and hiring people who can't be bothered to go deeper than using word art in MS PowerPoint slides, well, hey. Bring a horse to water... know what I'm saying?
PGP is easy to use. At this point, I'd like to think people are fatigued enough by the bottomless pit of nightmares we've fallen into, that they'd step up and tell people: yes, people are using SSH keys and SSL keys billions of times a day. It's okay to use PGP on your email. Go ahead, start doing it.
Or, you know, whatever. Lose another election. Right?
[0] https://en.wikipedia.org/wiki/Email_encryption
[1] https://blog.filippo.io/the-sad-state-of-smtp-encryption/
[2] https://security.stackexchange.com/questions/51552/how-insec...
Encryption can be its own foot gun. It can aid attackers, by totally destroying evidence that might exonerate you from being framed for other crimes. It can cost people dearly, in terms of lost data. Consider how many people have lost old bitcoin wallets, containing small fortunes, and similar tails of woe.
But look at how that plays out. A dropped bitcoin wallet, gone forever. The failure mode of something like that is often a better look than things going the other way. Imagine that same bitcoin wallet getting stolen, and seeing the thief profit from it. Sort of like watching elections get stolen, no?
So, think about that, the next time you warn someone against forcing you to exchange PGP keys, in order to communicate more securely.
I await the day that a great PGP client for everyone might emerge, but I'm not sure that it is possible, nor am I certain that people will want it. There is substantial utility involved in letting Google read all of my email for spam/malware filtering and more.
People think PGP is important for campaigns because they want it to be important, not because there's any empirical evidence that it is important.
PGP actually does do something about incoming email attachments. It offers the opportunity to programmatically reject anything that is non-encrypted ASCII text, and renders malicious files as non-executable ASCII text, when such policies are properly enforced. At this point, the promiscuous user is protected from delving deeper into emails. The server can effectively isolate attachments entirely, by proxying mail delivery, and refusing to decrypt attachments automatically. This would further defend against account compromise, through practices that require special handling of attachments. Email then becomes a medium of communication, rather than file transfer, and file transfer is pushed to other protocols and applications.
Sort of like a point-and-call policy. Forcing a user to cognitively jump through hoops to discover the contents of an attachment, when they should really be using email for the exchange of messages with humans, or automated control messages, such as multi-factor auth. Doing something like this limits email to character data only, rather than interpretable instructions. You know, much in the way we don't execute JavaScript from an email context.
Example:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQENBFuPKDYBCAC6xIbamQ3hTFCp8qcu8fLiz8XrSMXod/Xo5/iV/7FbqN8pE6uB
9EFyrWX1gy6ZNP+EGXrQ017sNcGHL7LquV74m+Z4/CRZlKpHMR2U9WEIhjgfL46c
vtQP/l9MB39P/VK3xsPXHTWSBiVdDdhWQTTZ5Tl88Zwo5n81ToOMFDLSXqZThlBl
CjUNOmHt1nLpkUzyn5h8c9/x2gNe/ArD2nY6DewHZCALLSDAEKLqrru+v2N6ABRh
Ad7GTVaHrD7aM84nlDMYiJmWSbx+IX2i4sxOeescjFPCmgjIuLLfIv94Oc7a6cV/
O7JzaX5Vyr+wBiHqhG2Xrwo+/V6+hRLv3Aj7ABEBAAG0H2xhdXJlbnQgbWlndWVs
IDxsbUBleGFtcGxlLmNvbT6JAVQEEwEIAD4WIQRrmP8aKYfcI7jMLtoYF2U5ECzk
nQUCW48oNgIbAwUJA8JnAAULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRAYF2U5
ECzkneaeCACVHmasl2V+gz2dDKJr3ELuCM82ZGltq44kSj2Wod5KyvAulb8XB4Ox
d5LXw8rdLuHiGl8vFrPljRO1do+8ahQyPy6Sk5UNb73zi8ujubhLHm/jpSdO5lUO
ryb/TN4lnBnGSDeYkUtKn2FUr0+i4EgnqAi2L2svQoDwzzyyeWrkXBgqqm1NT0bw
hbBhQfozdafqvFF3gBfaBqrFpD/KAgHzmTe3YejrD9tJTVJamTsEvmMXNMhaXF3s
FVqlWGoGr0/17Ft75SyuKj+ssJ7oxeblxhocUum8XvtmVlu8Ee/wxqugApeDLN0x
6cqEH837QIU6vQgx3mGK7Vv035uRru1yuQENBFuPKDYBCADC1Hea+6AMj7gwNnfX
tOIJ8X/rKeqw6u3Up1vt7DC3IOrml0AQHk08bklLbXokO/GlW0uUwX/tqKeIz35y
l+uzqBooR62H99CQc36trN96GD6zxeVYlbMpWdTzPqgxSVmEx9EvfCPhsgCueTz1
oTJw5SW4dUOHuL3k8R/cEFraJJpigp8PceXJWsxinUTOVSKH1VhWsZaActRRicf4
Y9GOcEJhgFhNlvVgFW+x/+hYL3vLXeUNTb6UCH6O9X0I+zv03VbLO/GdZFGA3Vps
MYzzk8y/n93DkAIAD6vCPZAvcOLGMXaEv5GER2Scpv/sgINefh67+ExH/Vc8ZrUl
C421ABEBAAGJATwEGAEIACYWIQRrmP8aKYfcI7jMLtoYF2U5ECzknQUCW48oNgIb
DAUJA8JnAAAKCRAYF2U5ECzknTEMB/0ZcvUYZq5IlqsBNYdZjCaXY5KQqWqKnQlW
jISSM7RmjCQwDqjTgyOVfl19PeVpj63h/tAPTXcsJ31LlpyHUklBVAeQmXuvMRry
WMfLeHa5nAQmS3VgZNyahFyps+mGFiDChy7Zz14v/bpfUAeqBIY4txVHwT4fLWEM
M1ZRbu8DcgwUErXt5xe5kOJZRWd8Q/xnspn9Tg+QvdWF67xi4CZ7RTl2+aL8MshT
051atXtkskDomQD/kNhP757cUuvDBkC4FydP8rztMdNLUiiC0L1R6V4bxhr4Yhsh
dbf+w0XrcuUaSnaka5TAeh+NCK//CoUsnVF/fun2bJ8bRikMPwxy
=/JKx
-----END PGP PUBLIC KEY BLOCK-----