Cybersecurity Checklist for Political Campaigns
zeltser.com
zeltser.com
https://techsolidarity.org/resources/congressional_howto.htm...
In comparison:
* This is way too long and full of technical jargon. Even relatively major campaigns still aren't staffed with technical experts. Very few do their own application development. The person managing IT probably has 30 other jobs.
* This "checklist" has no coherent notion of the actual threat model campaigns face. It's just a laundry list of security advice of the sort a bank would provide to a downstream business partner.
* It's extremely casual about the two biggest threats campaigns face --- phishing and attachments. Campaigns need clear, actionable advice for dealing with these, and "be careful about links" absolutely doesn't cut it --- your mental model of phishing should be that it always works, and the attack needs to be broken directly (security key authentication has the virtue of actually doing this; "two factor authentication" does not).
* It contains silly advice, like "modern anti-malware" and "install a WAF".
This list would be unimpressive and ineffective even in trying to secure a small business that actually had an IT team. I don't think it will be helpful at all to campaigns.
However, given events like this: https://thehill.com/policy/technology/406437-google-execs-la...
Any conservative Republicans running in 2020 would have to be morons to trust their entire communications infrastructure to a company who openly opposes their policies.
(Cue jokes about how the 2nd half of that last sentence is redundant...)
Contrast with https://techsolidarity.org/resources/congressional_howto.htm... which is a checklist by the person behind The Great Slate, a tech-backed grassroots Democratic funding push who has actually worked with politicians. It tells you what phone to buy, what links to click to enable more security for GMail, what app to install to have secure communications. Most politicans are about as savvy as your grandmother.
The two biggest threats campaigns face are phishing and attachments. There are two good ways we know of to break attachment attacks: view attachments in cloud viewers, like Google's PDF viewer, or view them on mobile devices, where they can't trivially be clicked into monstrously insecure desktop productivity applications. Of the two approaches, the latter --- sticking to mobile devices --- is the one that can be deployed with the least amount of end-user training.
I'm not sure I get the rational behind this one? Is it just because they are already using Chrome, so it's better to reduce the attack avenues?
Also, it seems to me if you need to use Tor, it's probably not a good idea to do so on your regular Windows desktop. Wouldn't Tails be better advice while also being more foolproof for less tech savy people?
People who match the description above don't need to be found as much as they need a point-of-contact to campaign staff. Many of us are more than willing to dedicate the time and resources needed to advise those who wish to take security seriously, free of charge. The issue lies in the shared opaqueness of the two parties that must come together; neither know quite who to contact and both are unsure how to engage. We should not let a lack of understanding get in the way of protecting our (anyones really) election process.
You really have to get a sense for how ragtag a political campaign is. Startups --- themselves pretty ragtag --- are raising funds and building for an imagined future in which they're big. They might engage professional IT and security (though many don't). Campaigns aren't like that; every single one of them will be "out of business" within a year and a half. They have minimal infrastructure and a mostly volunteer staff, and there are many hundreds of them every cycle.
At best, you might suggest that the upstream service providers for campaigns, like NGP VAN, should get better at security. The DNC, for instance, has an experienced CSO. But that CSO can't do all that much for individual campaigns.
This is so wrong it's hilarious. I've been doing computers for forever, and "security keys" are STILL a universally lousy user experience.
What happens when you lose one? How do I install multiple keys? How does their manager revoke their keys when they leave the company? And where is the server that controls all this, and how do you administer that? I could go on ...
If you have any pointers to tutorials how to do this, I'M ALL EARS. Seriously.
So you can buy and enroll 2 keys, or just do what Google forces you to do: enroll an additional second factor, like a code generator.
I do not understand your revocation argument at all. When you let a staffer go, you lock their account. You do not care about their keys.