13 ms·
What I Learned Trying to Secure Congressional Campaigns
- RickJWagner 7y agoA good read, thanks to the author. Biggest surprise (for me): Nobody uses Twitter.
- microcolonel 7y agoTwitter users tend to be under the impression that everyone is on Twitter.
- dswalter 7y agoDepending on who you follow, it's one of the best link aggregation sites around. Care deeply about refugee rights in Myanmar? Follow a few folks and you'll gain insight into the kinds of things like-minded folks are thinking about. There is the on-Twitter conversation, too, but the best thing about the site is what people are linking to out of it.
- microcolonel 7y agoSure, I'm a Twitter user too, just pointing out the tendency of people to forget that there's a world outside their own, especially if they spend enough time in their own little curated space on a site structured like Twitter.
- p1necone 7y agoTwitter has always seemed to be of very minimal utility to me compared to other social media. It basically takes the vacuous shouting into the void of Facebooks wall, and makes it the only feature. I'm kind of not surprised that people don't use it.
- kasey_junk 7y agoOnly because I'm one of Maciej's number one fans am I going to point out the delicious irony that more skill in digital advertising would have been helpful to his mission this time.
- aquabeagle 7y agoI'm confused by how difficult it was to get a meeting and convince these people to change their ways, but how easy it was to hand them a USB device and "Collect information about what devices people are using, their email provider, whether they have two-factor authentication, how they share documents in the campaign, how they keep track of passwords, and so on". Were you just some random outsider to them, coming in to do free security training? Or did others have to vouch for you? It seems like it would be terribly easy to do all of this under the guise of being a helpful security person, but you're actually just sabotaging them with rogue USB devices and learning the details of all of their security practices. Especially by getting on their good side with things like "A friend wrote a script that did this conversion automatically when you dragged things to a desktop folder, and I would mention this during campaign visits. Suddenly I was no longer the dentist, but Santa Claus come early." Could anyone else have been doing this without being vouched for?
- ceejayoz 7y agoThis is mentioned. > You should understand that there are a zillion people and groups out there who want to do tech experiments on campaigns, and without someone to vouch for you, you will make no headway.
- sdoering 7y agoFor me Chrome password management works fine. I have all passwords on my work Mac, had to switch Macs about 9 times due to Apple's quality issues in the last year and passwords were always available after logging in to chrome. And they are also always available on my Android. But. I need to trust Google. I also have 1password (without cloud sync). Works great on my Mac. But switching devices is a pain. And syncing to mobile doesn't work at all currently. So my state with managed passwords is somewhat of a mixed bag. PS: Well, due to policy changes I need to create a central password for logging into my computer and company systems in the future. And I need to type it multiple times per day. And need to change passwords regularly. I am not really looking forward to that form of "security".
- idlewords 7y ago
- Bucephalus355 7y agoGood write up that I think extends to many environments beyond congressional campaigns. One thing I would like to add (and perhaps the author mentioned but I did not see). Secure your cellular accounts such as Sprint, T-Mobile, Verizon with 2FA, good password, etc. This also includes the maximum length VM password, although usually that is only between 7 digits to 10 digits sadly.
- lifeisstillgood 7y agoFrom a UK perspective the "call time" seemed amazing - the amount of time dedicated to that, and the eco system around it (EMILY's list?) I am sure that exists in all countries just it presumably is less prevalent? Any insiders have knowledge? Weirdly I would think that process of dialing and recording would be very automatable too
- jabart 7y agoThe important part of call time is the phone number or caller ID, shows the candidates name. We have automated it some, but paper is still quick and easy to write on to later be entered at the end of the day
- cavisne 7y agoThis stood out to me also, things that are unique about the US compared to other countries 1) Relatively low personal and corporate donation limits - a lot more phone calls are needed to raise the same amount of money 2) Low rate of voting - you need an entire get out the vote campaign along with your existing campaign 3) Hatch act - your congressional staff cant work on your campaign, so you need two sets of staff, this combined with 2 year election cycle is probably what makes "campaign ronin" a viable career path and a also more expensive 4) Presidential system - a bit counterintuitive but i think in a parliamentary system house races are less important as people are more voting for the party
- ineedasername 7y agoBeing in the US, the whole idea that UK doesn't elect their leader directly always struck me as odd, until I realized that their PM's generally feel much more beholden to their party's platform than politicians in the US. In which case, it really is less relevant who the particular person is and more than the party you support is in power.
- drjesusphd 7y agoSame here. I think one of the critical flaws of the US constitution is that it completely ignores the existence of political parties.
- jabart 7y agoThis is why my company (Campaign Deputy) bundles Web, DNS, and Email hosting along with our Fundraising platform for political campaigns. Not mentioned was DMARC and SPF, which is really tough to setup when you don't have direct access to the Domain Registrar. We are also competitors to NGP. Our users actually like us too!
- Deimorz 7y agoGreat article, as always. I think one of the key points is how awful password managers are for non-technical people to use. It's not necessarily the developers' fault because it's difficult to interact with all the things they need to, but it makes it practically impossible to get someone to use one unless they're technical enough to be able to figure out all the random issues that come up all the time. I'd love to be able to get some non-technical family/friends to use one, but there are just way too many times that showing someone how to use a password manager goes something like: "Okay, so now you've generated a password and you click 'Register' and... oh hold on, the page redirected for some reason and the pop-up to save the account info is gone, so, uh... well, I think there's a generated-password history page somewhere, let me just look through the Settings area even though it's not a setting... okay, there it is, so it should be this one. I'll just copy that and now I have to create a new vault entry for the site manually by typing in everything and pasting this password in there, and then..." It's terrible, because a password manager that would just work and stay out of the way could make such a huge difference to general account security, but they all seem to still be difficult to use and require you to have a pretty good understanding of what's going on to be able to deal with random problems.
- simonw 7y agoCurrent versions of iOS have a built-in password manager as part of Mobile Safari - it feels like this could be a much more user-friendly option, I'd love to see some formal usability studies of how it compares to 1Password et al.
- dev_dull 7y agoIt works really well provided you enable iCloud and use safari as both desktop and mobile browser, which I think is probably a lot of people in the author’s orbit.
- ec109685 7y agoOn desktop Mac, you can copy password from keychain to chrome. Kinda crappy, but gets job done in slightly more secure manner as Notes.
- jammygit 7y agoWhy does only chrome support the security keys? It seems to imply that apple doesn’t support them very well also. I thought they were more widely supported?
- downrightmike 7y agoFIDO2 etc are widely supported, it is just that their usage is a pain in the ass. Like PGP, the tools to use them suck. Especially for non-technical people, they just won't use them. The real solution is to make using them transparent, which hasn't been solved and there isn't enough uptake for anyone to fix it, because the easy option is to just reuse passwords. Once security keys are that easy, then they'll be used. Even if you use a password manager to generate a 100 char password, who the hell is going to type that into a phone? no one, if they can't find a solution simply, they simply won't use it.
- rietta 7y agoFirefox supports them too, but it has to be enabled. https://support.yubico.com/support/solutions/articles/15000017511-enabling-u2f-support-in-mozilla-firefox https://support.yubico.com/support/solutions/articles/150000... I've run into one important (investment brokerage) site does user-agent sniffing and dropped immediately to calling your registered phone number instead of letting Firefox continue to use the Yubikey that it does actually support.
- closeparen 7y agoThat would probably be Vanguard, the only retail brokerage implementing non-SMS 2FA as far as I know.
- LUmBULtERA 7y agoFidelity offers 2FA using the Symantec VIP app.
- rietta 7y agoYou guessed very well. I guess I should have just come out and said the name!
- j1x9 7y agoMixed content warning on the website. :/ EDIT: And it gets much worse... https://www.hardenize.com/report/idlewords.com/1559008811 https://www.hardenize.com/report/idlewords.com/1559008811 I wouldn't trust the author to secure an ice-cream stand.
- robbiet480 7y agoMaciej has a well known track record as a security expert. He has testified very recently before the US Congress [0] on these matters as well as single-handedly (to the best of my knowledge) built and maintains the fantastic Pinboard bookmarking service [1]. Just because he has a mixed content warning on a image of a fish (his site logo it appears) and has a Google search form inline (not ajax mind you, an actual standard HTML form with a real submit button) should not cause you to consider him unskilled or untrustworthy. Furthermore, lack of HSTS or a CSP shouldn't be a red flag since it is his own personal blog, therefore it's probably not worth his own time to configure either. I'm not sure what your personal threat model looks like, but I think we can assume most people that read HN wouldn't worry about such things. Full disclosure: I am a Pinboard lifetime member but to the best of my knowledge have never contacted or been contacted by Maciej, and obviously he didn't ask me to vouch for him, these are my thoughts alone. 0: https://www.americanrhetoric.com/speeches/maciejceglowskicongressprivacy.htm https://www.americanrhetoric.com/speeches/maciejceglowskicon... 1: http://pinboard.in/ http://pinboard.in/ EDIT: Added links & "to the best of my knowledge"
- tptacek 7y ago.
- robbiet480 7y agoYeah I was trying to decide if they were trolling or not, gave the benefit of the doubt on this one.
- idlewords 7y agoThis whole exchange makes me regret adding https to the blog last month.
- bo1024 7y agoGreat article! Can you say exactly why Signal is more secure than email in this context?
- deleted 7y ago[deleted]
- idlewords 7y agoSignal is end-to-end encrypted, so your message is stored only on your device and the recipient's. If you want, you can have it auto-delete after a configurable period of time. Email wanders across the Internet and is stored on multiple servers by design. It can be tampered with or spoofed in ways that Signal messages can't, and your email account can potentially be broken into by an adversary.
- rediguanayum 7y agoJust wanted to point out that Gmail has a Confidential Mode that can prevent forwarding, auto-deletes and allows the sender to control access to a sent email including removing access. https://support.google.com/mail/answer/7674059?co=GENIE.Platform%3DDesktop&hl=en https://support.google.com/mail/answer/7674059?co=GENIE.Plat... Understood that Signal has other useful security properties but this is useful for folks that use email. Disclaimer: I work at Google.
- bo1024 7y ago(Sorry I saw this a few days late.) I think it's very misleading to call this "confidential mode for email". It's just putting the message on a webpage and sending the person a link to authorize access to the page, right? (And maybe messing with the gmail interface to hide that this is happening.) It's a really different concept altogether than email. If I understand right, it's basically like creating a google doc and sharing it with only certain recipients (and ability to revoke later).
- tacosx 7y agoIt is amazing when you consider both the number of and the sheer depth of the problems that would be fixed instantly by moving to publicly financed campaigns.
- kasey_junk 7y agoWhat single thing in this article is solved by that? (Note I’m extremely sympathetic to publicly financed campaigns)
- 9nGQluzmnq3M 7y agoCongressional campaigns are largely about fundraising, so if fundraising is no longer required, most of the problems listed here also cease to be a problem. That's a mighty big "if", though.
- steve76 7y agoSure. A drug cartel launders a billion into your candidate and looses. They don't murder the police chief's family because it was all taxpayer dollars.
- canada_dry 7y agoCouple tidbits. > telling people not to use Android I personally use Android as I dislike the Apple-itunes-lock-in. But, you'll be able to sleep better at night if you lose your iPhone with confidential info. ... > Google's Advanced Protection Program is almost comically unusable for campaigns. The expensive dongles break easily, and when the dongle breaks you are locked out of your fundraising spreadsheets until you can reach Google support (if such a thing exists). Ouch.
- tptacek 7y agoWith technically savvy users, I think it's safe to say that you can get a flagship Android phone asymptotically as secure as an iPhone. But most users aren't savvy, and need clear guidance, and if you say "Android phone" to them, you're effectively clearing them to use the worst smartphones on the market. Like, "I found this thing on the street and stuck my SIM card into it" bad.
- po 7y agoI think one other major factor is that if you (as the technical nerd who can figure this stuff out) give a non-technical user a fully updated secured Android phone today and then come back to that user in 6 months, it's way less likely to still be secure. Apple does a much better job of maintaining security over the lifetime of the device by pushing updates out.
- ineedasername 7y agoHow does google compare when you get their updates ASAP with a pixel? Is it on par with iOS then?
- kasey_junk 7y agoThe issue isnt with Android flagships, especially the pixel line. The issue is that by banning android you van hundreds of low quality phones. Every iPhone is high quality & only a low % of android are.
- po 7y agoMaciej, do you consider the built in keychain functionality of iOS/MacOS to be a "password manager"? I only ask because I typically have found that when setting up non-technical people with iPhones or new laptops, that it has recently passed the bar of 'easy enough for non technical people'. True, it can be hard to get to the stored passwords for manual entry and it doesn't work with a few sites, but generally speaking it picks random passwords, saves them fairly reliably and prompts to use them with biometric protection.
- idlewords 7y agoYeah, for sure. If people were already using it, I gave them a thumbs up. In my mind it occupies some middle ground between a password manager and "I keep my passwords in this note app", but only because it doesn't tie in to Chrome.
- skybrian 7y agoWhat do you think about Chrome's built-in password management?
- coredog64 7y agoOne flaw for people who aren’t political campaigns is that frequently you’ll need to log in to something that’s not using a browser window. After years of headaches and literal tears, I broke down and bought LastPass for my kids. My wife isn’t technical, and I would come home to kids that had lost/forgotten their Minecraft password. They took it out on their mom, so instead of post-work no-tech downtime, I was coming home to Sev1 incidents that were already out of SLA.
- po 7y agoAh yeah I forgot that your strategy revolved around Chrome due to the Yubi keys. Each browser offers a critical feature: cross device password management vs. easy hardware 2FA. I have a feeling Apple sees their iOS devices as Yubi keys and Google doesn't want chrome reading/writing to a 3rd party keychain. Not a great situation.
- po 7y agoI have great hope that the upcoming Web Authn standard (https://webauthn.io https://webauthn.io) will greatly improve server-side security and make phishing a thing of the past but I worry about how the threat model will then turn towards securing access to the user's personal devices. Endpoint security is going to get even harder. People double-click and blindly run whatever on their devices all the time.
- miles_matthias 7y agoGreat job! I'd like to echo your sentiment about password managers, they are way too complicated to use for non-technical people.
- drilldrive 7y agoGreat writeup Maciej. I do have some questions: (1) Is there an easier secure way to open attachments to Emails? This is a critical point of error in campaigns, and yet your suggested solutions are lacking in my eyes. I for one do not use a smart phone, and even when I use a Gmail account I use the html version that does not have a Google Docs option for files. So I am left with your option 3, and this could take several minutes in contrast to double clicking the file. (2) Why do you recommend to avoid SMS but to treat Twitter/Slack as a public messaging option? Why not just treat all three as public? (3) Why do you recommend only Chrome browser? In particular, why not Firefox or Tor?
- idlewords 7y agoThank you! Answers in order: 1) I can't think of a safe alternative for you, but maybe someone else here can. 2) Signal is a drop-in replacement for SMS, while there is no real replacement for Twitter or Slack. That's why I tell people to treat it as public, rather than move off those sites. 3) The consensus among my security friends is that Chrome is the safest mainstream browser, though Firefox is making big strides. The Tor browser is not safe for the reasons tptacek outlines here: https://news.ycombinator.com/item?id=19981733 https://news.ycombinator.com/item?id=19981733 I explain elsewhere in the post that I like to tell people to use a specific product. If they really love Firefox, I don't fight them.
- bsder 7y ago> backup U2F key How do you set this up!? Every time I try to set the folks in my company up with security keys, the biggest problems are always: 1) How do I deal with the fact that someone just left? Something invariably is tied to their login, and I need to transfer control. 2) How do I deal with a broken/lost/stolen key? So many services simply will not let you install multiple keys on an account and it drives me up a tree.
- dillondoyle 7y agoDisclaimer: I work in politics professionally, as a digital consultant. ActBlue is better at security (and just in general product) than NGP, but neither supports physical 2fa keys. I don't want to speak too publicly about NGP VAN but I think this area is very ripe for disruption, but it would be hard to get the finance side 100% correct, automated FEC & compliance and all. This built up moat I personally believe lets them stagnate on technology. I think their API is proof they know the weakness or are afraid of easily better tools built on top (no important data in and out). One attack vector I dont see mentioned is locking down domains and websites. Campaigns are incredibly cheap, it only took a few consultants selling shitty pre-built wordpress themes and now it's tough to get a Congressional to pay much or anything. We now build static websites for clients who pay, but I'm still worried about some actor uploading a google-verification.txt, or updating DNS to send better phishing emails. Emailing passwords in plain text and shared twitter passwords for candidate accounts which are 'victory!2020' are VERY common and we've been trying to correct this behavior. Though this isn't perfect we have been sending one time links with no authentication info in email plaintext. If anyone has a better solution? (remember non-technical (no PGP) campaign staff and not in same geo a lot of time). In writing up some campaign plans this cycle I made some security notes, especially for a top 5 race target client we have (if win primary) I suggested separate senior staff office in a more secure location which no volunteers know about. This wont work at Congressional level, where anyone can get access to call time room or CMs office if they try.. Yes because I'm overly paranoid but also sadly because security in politics now means protecting from some random nut bag with a gun. Which is really scary to me. But mostly I'm surprised at Maciej's willingness to spend money (and valuable time) doing this. Sadly I think the willingness to help anyone including 'Green Party candidate in a district the Republicans carried by 60 points' combined that with the general (and I can understand and am not judging) attitude that 'the system' is broke, is probably a factor to why he was not taken as serious as I think he would have liked. Sorry this got really long.. I could go on and on (if @Maciej or is it @idlewords ? sees this would be happy to chat on DM). love seeing politics on HN a topic I have specialized knowledge in for once ;0
- idlewords 7y agoThanks for these comments, and I'm happy to talk; you can find me on Signal at 415 610 0231.
- ghani 7y agoThis was a good read, thanks.
- tomohawk 7y agoInteresting that the end result of campaign finance reform is that candidates spend way more time on fundraising than they ever did, and are beholden to more people than ever.
- losvedir 7y ago> For example, we told campaigns it was best to have a password manager, okay to have a written list of random passwords, dangerous to have a password pattern you would modify across sites, and unacceptable to re-use a single password across sites. As someone who likes the "password pattern" approach (remember one thing and use it to generate passwords for all sites), what's the threat model here? How is it dangerous?
- idlewords 7y agoTwo things off the top of my head: computers today can chew through a frightening number of passwords per second, so your pattern is almost certainly guessable. And second, you're more susceptible to phishing than if you used a password manager.
- lostphilosopher 7y agoThe general answer: Your pattern is a single point of failure. If someone figures it out they can figure out your passwords to multiple sites. The most likely threat is your password to one site leaks or gets fished and then the hackers recognizes it as pattern generated and reverse engineers the pattern. Then they just start trying that pattern on other sites. Not doing this is good general advice. Your specific risk level varies based on the pattern you use.
- kayfox 7y agoOne or more compromised passwords could reveal the pattern and at that point you might as well have just used the same password.
- UncleMeat 7y agoPeople suck at doing this consistently. We observe that people who claim to do this actually end up reusing passwords. It also becomes difficult to rotate passwords.