It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure.
It isn't perfect but it would be a massive step up from everyone having their own home-ground solutions that may or may not be secure.
Another is that GSuite doesn't protect people's personal accounts, which is the big risk here.
APP is nice in theory, but I don't believe it's workable in practice for Congressional campaigns. The keys break too easily, and there is no fallback if they are lost or broken. We have one candidate trying out APP and I'll be eager to hear her feedback. But for the time being, just getting them onto 2FA with yubikeys maxes out people's mental budget for "security stuff".
Seems more reasonable to lose an account to a damaged key than to lose an election.
It's not that people are lazy or feckless. This is a genuinely hard problem for working campaigns to solve. It's a fascinating environment.
Look, even security keys may not provide "enough" security. An adversary capable of performing a targeted, in-physical-range attack will be able to sneak a keylogger onto a staffer's laptop (to steal the password) and then take advantage of an opportunity where the security key isn't guarded to swipe the security key for either momentary access or to register the attacker's key for long term access - which won't be caught without persistent auditing efforts, which most campaigns won't do. As always, the question is "how do we raise the cost of an attack while keeping the cost of defense relatively low" and that's what security keys do really well.
Edit: look, specific campaigns may have different ways of adopting the pattern. Maybe the candidate without a dedicated campaign office could keep the keys in a safe in the candidate's home. Maybe national candidates / candidates whose staffers would need to drive for an unreasonable amount of time to get a replacement key, maybe there can be local caches of keys in different cities, where some independent business figures out a way to register numbered security keys for online accounts in a relatively anonymous way for both remote businesses and whoever else. Still doesn't mean that security keys are a bad idea.
In general though I think we'd be better off with Google just adding more restrictive OAuth scopes and improving their logging functionality so that users can see how apps are using their data. I'm clearly biased since my app is built on Gmail OAuth, but I generally just think that for whatever issues OAuth has, pushing people toward browser extensions or IMAP is a step in the wrong direction.
I think a good starting point is to simply offer in-person training at key points in the campaign (on filing, after a primary win, and before the general election).
But also consider downticket races like secretary of state or state ag. Then you're talking state parties who have almost no power at all.
So yeah I think carrot is definitely better than stick, but there basically is no stick. I do think the DCCC should set up gapps for every general campaign and provide it for free, and should probably also offer it to professional Democrats, also for free, but this is a larger tech infrastructure question that starts to include organizing tech, website tech, VAN, email tech, etc. I personally think we should provide all those things, but there are a lot of (vendor, of course) politics involved, it's not cheap, and things like 2FA are so far down the list you can't see them. Again I think we agree, I just think a lot of people think the party controls campaigns and that's largely not the case, and even when it is there are arguably more urgent issues (campaign finance law training, ex) that could benefit from any kind of standardization.
My team did some work for the KS04 special election last year, and now we've developed a service for political campaigns. But traction.. maybe we're getting screwed by this approved vendors thing.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1409573
If so, I totally understand a migration period, and it's nothing to hold against them.
And there shouldn't be a "migration period" that holds the entire feature hostage until browsers implement Chrome-specific stuff.
I think people have a broken idea of what a congressional campaign actually is. It's not an enterprise with a security team. It's a bunch of random people working together for a year or so, and only for a few months full time, at that. That's what makes them targets. Whatever our industry does to protect campaigns needs to engage with the reality of what a campaign is, rather than pretending they're all credit scoring firms that should have known better than to not spend all of their $13,000,000 security budget this year.
work related emails already are on gsuite. yeah they could require 2FA and other stuff, but the more friction, the more people will fall back on personal emails.
Campaign workers have like 2 days of training total. it is what it is. Even at high levels of staff, many are on sabbatical from their main careers.
Though, if there was a moment for behavior change, this would be it.
Really, it might be easiest to get campaign staff on some secure messaging app instead of email, cause trying to explain different levels of email security will simply go over laypersons heads. My region of staffers all used GroupMe -- I wouldn't be surprised if the DNC doubles down on Slack or something similar.
There are other bonuses to this too. The first that comes to mind are that campaigns are transient; using your own email can help you with document retention requests in the event of lawsuits. But I think mostly that political professionals use their email for a lot of different things, and keeping everything in a single account is a lot more convenient than dealing with multiple campaign accounts.
That means no IT support to get that 2FA protected (if you even have it) email account onto your phone. Guess what email they will start using?
The Podesta emails show how much more mileage attackers got out of drama than substance.
What phishing scenario, and how is TFA completely defeated by it? The article just says "the best defense against phishing is a 'security key'", but doesn't explain why other options like TFA are inadequate.
I didn't say TFA would be the ultimate solution, but that it's likely to be supported by more things that people use (like apple devices..). If you choose a solution that might be technically superior but require people to make major workflow changes, you'll find they won't use it. TFA seems like a good compromise to me, so I'd really like to understand why you think it is not.
If I do the same and your second factor is a security key, I get a useless binary blob that I can't turn around and hand to Google.
The U2F key gets the actual URL of the page you are on from the browser, so it can't be fooled by impostor websites, however clever. That's the difference, and the reason that Google moved their employees onto security keys. Too many people were getting phished otherwise.
Can't this be defeated by DNS poisoning? TLS/HSTS would help, but that assume folks are verifying that the hostname matches the cert... (big assumption)
In any case, I see your point, thank you for explaining it.
It also bears repeating that the leaked emails contained nothing illegal or even immoral beyond a few peeks of how the sausage is made that were only outrageous for people looking for a reason to be outraged. This discussion sometimes gets dangerously close to victim blaming.
Turns out you can hack an inbox and claim it contained anything. People won't read. They just want their tribal allegiances confirmed.