{"id":17700,"date":"2020-02-11T10:45:18","date_gmt":"2020-02-11T18:45:18","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2020\/02\/11\/news-11435\/"},"modified":"2020-02-11T10:45:18","modified_gmt":"2020-02-11T18:45:18","slug":"news-11435","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/11\/news-11435\/","title":{"rendered":"Google&#8217;s Giving Out Security Keys to Help Protect Campaigns"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e420645c37d1a0008ff67cb\/master\/pass\/security-feature_art-google_election_titan_key.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Tue, 11 Feb 2020 11:00:00 +0000<\/strong><\/p>\n<p class=\"byline bylines__byline byline--author\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\"><span class=\"byline__name byline--with-bg\"><a class=\"byline__name-link\" href=\"\/contributor\/lily-hay-newman\">Lily Hay Newma<span class=\"link__last-letter-spacing\">n<\/span><\/a><\/span> <\/span><\/p>\n<p class=\"content-header__row content-header__dek\">Candidates can also get trained up on how to use Advanced Protection to keep their accounts safe.<\/p>\n<p>Malign foreign <a href=\"https:\/\/www.wired.com\/story\/russia-election-hacking-playbook\/\">influence operations<\/a> during the 2016 United States presidential election season raised awareness about the need for <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.belfercenter.org\/CyberPlaybook&quot;}\" href=\"https:\/\/www.belfercenter.org\/CyberPlaybook\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">tighter security<\/a> within campaigns. And while the 2020 presidential campaigns have shown <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.npr.org\/2020\/01\/28\/799062773\/2020-political-campaigns-are-trying-to-avoid-a-2016-style-hack&quot;}\" href=\"https:\/\/www.npr.org\/2020\/01\/28\/799062773\/2020-political-campaigns-are-trying-to-avoid-a-2016-style-hack\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">some<\/a> improvement, many are still <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.valimail.com\/blog\/campaign-security-milestone\/&quot;}\" href=\"https:\/\/www.valimail.com\/blog\/campaign-security-milestone\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">seriously<\/a> lagging\u2014and facing <a href=\"https:\/\/www.wired.com\/story\/iran-hackers-target-us-presidential-candidate\/\">real threats<\/a>\u2014with nine months left before election day. Now Google is trying to help move the needle.<\/p>\n<p>Today the search giant is announcing new efforts to help campaigns secure their GSuite accounts through the Advanced Protection <a href=\"https:\/\/www.wired.com\/story\/google-advanced-protection-locks-down-accounts\/\">program<\/a>\u2014complete with free <a href=\"https:\/\/www.wired.com\/story\/google-titan-security-key-recall-ble\/\">Titan security keys<\/a>. Google is working with the nonpartisan, nonprofit Defending Digital Campaigns, which will interact with political groups and distribute the free keys. DDC will also take the critical step of offering consultants to help campaigns actually activate the protections.<\/p>\n<p>&quot;We&#x27;re delighted to now have a partnership with Defending Digital Campaigns through which we can reach all the presidential and congressional campaigns and help get them the security that they need, that they\u2019ve been asking for, without having to worry about cost and complexity,&quot; says Mark Risher, director of product management, identity, and user security at Google.<\/p>\n<p>By definition campaigns are transient and ad hoc, which makes it even less likely that they&#x27;ll prioritize digital security than more traditional organizations might. For such a fleeting project, high-quality infrastructure isn&#x27;t typically a focus in general\u2014or in the budget. (Pete Buttigieg&#x27;s campaign did employ a chief information security officer, but they parted ways several weeks ago.) Looking to bridge this gap, free and low-cost digital security services have <a href=\"https:\/\/www.wired.com\/story\/free-tools-2020-election-security\/\">flooded the election industry<\/a> over the last few years, especially since the Federal Election Commission relaxed campaign finance <a href=\"https:\/\/www.wired.com\/story\/fec-campaign-law-cybersecurity-limits\/\">restrictions<\/a> last year to allow offers of free security services. Many, like <a href=\"https:\/\/www.wired.com\/story\/jigsaw-protect-campaigns-from-online-attacks\/\">Project Shield<\/a> from Google&#x27;s Jigsaw, offer web security services like DDoS defense.<\/p>\n<p>But even these low-cost tools face adoption issues, because campaigns still have to know what protections they need and how to implement them. Both Google and Defending Digital Campaigns say that low-cost security keys are the number one request they get from election officials and campaigns. DDC already offers reduced-price <a href=\"https:\/\/www.wired.com\/story\/how-to-use-a-yubikey\/\">YubiKeys<\/a>, but as part of its collaboration with Google, the group is going farther. DDC can&#x27;t provide unlimited tech support to everyone, but it is going to have a handful of dedicated staffers ready to help campaigns order security keys from Google, set up Advanced Protection on as many Google accounts as possible, and add the keys.<\/p>\n<p>&quot;You\u2019ve got to get people to take the time to actually turn it on, so we\u2019re going to be working with campaigns and helping them,&quot; says Michael Kaiser, president and CEO of Defending Digital Campaigns. &quot;Hardening your accounts is really something that every campaign needs, and not only the campaign workers themselves, but the spouse of the candidate, friends, family. There are a lot of different folks in the orbit of the campaign that need to make sure that they\u2019ve got some kind of enhanced protection, because the bad actors are going to probe every potential access into a campaign.&quot;<\/p>\n<p>These threats aren&#x27;t just theoretical. On Monday, Brianna Wu, a Democrat running for the US House of Representatives in Massachusetts\u2019 8th District, <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/BriannaWu\/status\/1226908022112505863&quot;}\" href=\"https:\/\/twitter.com\/BriannaWu\/status\/1226908022112505863\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">announced<\/a> that two of her non-campaign Google accounts were recently compromised by hackers. As TechCrunch <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/techcrunch.com\/2020\/02\/10\/house-brianna-wu-campaign-hack\/&quot;}\" href=\"https:\/\/techcrunch.com\/2020\/02\/10\/house-brianna-wu-campaign-hack\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">reported<\/a>, one account was linked to Wu&#x27;s Nest home camera system and the other was an alternate personal Gmail account, but both had strong, unique passwords. Wu reported the incident to the FBI.<\/p>\n<p>Google and Defending Digital Campaigns&#x27; new initiative is an immediate way to reduce account takeovers like the ones Wu experienced. Google recently <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.google\/technology\/safety-security\/new-advanced-protection-program-account-security-instant\/&quot;}\" href=\"https:\/\/blog.google\/technology\/safety-security\/new-advanced-protection-program-account-security-instant\/\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">announced<\/a> that users can set up Advanced Protection without a separate security key\u2014using their phones as the extra authentication factor. The move aims to allow users to set up Advanced Protection as soon as they think about it, rather than having to wait to order physical keys. But Google&#x27;s Risher emphasizes that separate security tokens still offer the strongest protection against phishing, and provide a backup in case you damage or lose your phone.<\/p>\n<p>&quot;There are a lot of things to secure, and campaign operational security, in particular access to accounts and email, is one of them,&quot; says Ben Adida, executive director VotingWorks, a nonprofit maker of voting machines. &quot;I think if something comes with training and a plan for adoption it&#x27;s great.&quot;<\/p>\n<p>Google and Defending Digital Campaigns hope that Advanced Protection&#x27;s ease of use combined with extra troubleshooting and support will make this free offering a no-brainer for campaigns to actually set up and use. But even for a giant like Google, campaign security is a stubbornly difficult problem to solve.<\/p>\n<p>&quot;I understand what a big mountain this has been. These kinds of basic tools, if we could get really broad adoption across the campaign ecosystem we would have shifted the space quite a way from where it\u2019s been,&quot; DDC&#x27;s Kaiser says. &quot;We would love everybody to be driving the Cadillac of cybersecurity, but just getting them into the car would be really good.&quot;<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/google-free-security-keys-campaigns\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e420645c37d1a0008ff67cb\/master\/pass\/security-feature_art-google_election_titan_key.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Tue, 11 Feb 2020 11:00:00 +0000<\/strong><\/p>\n<p>Candidates can also get trained up on how to use Advanced Protection to keep their accounts safe.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-17700","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17700"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17700\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17700"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}