{"id":9128,"date":"2017-09-07T02:45:03","date_gmt":"2017-09-07T10:45:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/09\/07\/news-2901\/"},"modified":"2017-09-07T02:45:03","modified_gmt":"2017-09-07T10:45:03","slug":"news-2901","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/09\/07\/news-2901\/","title":{"rendered":"The DNC\u2019s Technology Chief is Phishing His Staff. Good."},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59b0872057ed43108b20f135\/master\/pass\/DNC-tech-chief_MG_6666.jpg\"\/><\/p>\n<p><strong>Credit to Author: Issie Lapowsky| Date: Thu, 07 Sep 2017 10:00:00 +0000<\/strong><\/p>\n<p data-reactid=\"220\"><span class=\"lede\" data-reactid=\"221\"><!-- react-text: 222 -->If you are <!-- \/react-text --><\/span><!-- react-text: 223 -->among the millions of Americans concerned about cybersecurity at the Democratic National Committee\u2014and how could you not be?\u2014then the home of the party\u2019s tech braintrust might not give you much hope. The tiny, charmless office, with &quot;DNC Tech&quot; scribbled in dry-erase marker on the door, contains one desk and two computer monitors. Nearby, an overturned couch pokes out from an elevator shaft, a leftover from the widespread departures that followed Hillary Clinton&#x27;s defeat. And that, of course, came after intruders, <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/2017\/01\/feds-damning-report-russian-election-hack-wont-convince-skeptics\/\" data-reactid=\"224\"><!-- react-text: 225 -->believed to be tied to Russia<!-- \/react-text --><\/a><!-- react-text: 226 -->, hacked into the DNC&#x27;s computers.<!-- \/react-text --><\/p>\n<p data-reactid=\"227\"><!-- react-text: 228 -->If the office itself seems lacking, the resume of its newish occupant is anything but. Raffi Krikorian, the Massachusetts Institute of Technology grad who joined the DNC as chief technology officer this summer, most recently led Uber\u2019s Advanced Technologies Center, meaning he was responsible for getting <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/2016\/09\/self-driving-autonomous-uber-pittsburgh\/\" data-reactid=\"229\"><!-- react-text: 230 -->Uber\u2019s self-driving cars on the road in Pittsburgh<!-- \/react-text --><\/a><!-- react-text: 231 -->. Before that, he rose through the ranks at Twitter to vice president of engineering, where he managed the infrastructure that runs the platform.<!-- \/react-text --><\/p>\n<p data-reactid=\"232\"><!-- react-text: 233 -->Following six years of CTOs steeped in political campaigns, Krikorian brings a uniquely hardcore technical pedigree. That may serve both him, and the party, well. Preventing history from repeating itself requires embedding Silicon Valley technological chops in a nearly 200-year-old political non-profit. Already, Krikorian has recruited engineers from Uber, Twitter, and Pinterest to join his team of 20 and counting. Together, they\u2019re devising ways both to use technology to engage a broader swath of the electorate, and also ensure that technology doesn\u2019t create new vulnerabilities.<!-- \/react-text --><\/p>\n<p data-reactid=\"234\"><!-- react-text: 235 -->Working for the \u201cblue team\u201d as Krikorian calls it, comes with all of the pressure and few of the perks of Silicon Valley. After word spread of the Russian hack, the DNC tech team was widely criticized for failing to heed warnings from the Federal Bureau of Investigation that the party was under attack. Now, the responsibility of cleaning up that mess falls to Krikorian. This week, he spoke with WIRED about why he took the job, his plans for securing the party\u2019s infrastructure, and why he\u2019s trying to phish his own staff. Edited excerpts follow:<!-- \/react-text --><\/p>\n<p data-reactid=\"236\"><strong data-reactid=\"237\"><!-- react-text: 238 -->Issie Lapowsky: You joined the DNC at a time when many others had run away. How come?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"239\"><strong data-reactid=\"240\"><!-- react-text: 241 -->Raffi Krikorian:<!-- \/react-text --><\/strong><!-- react-text: 242 --> It never crossed my mind until around Inauguration Day. I was in a hotel room in San Francisco, and I was just like, \u201cGahhh!\u201d I called my friend Alexander Macgillivray, who used to be deputy CTO of the United States and said, \u201cWhat can someone like me even do in this world?\u201d He laid out two or three options. The DNC was the hardest to get a hold of. I kept pinging, pinging, pinging until the chief of staff took my call. He then introduced me to DNC Chairman Tom Perez, and Tom\u2019s first question was, \u201cWhat can we do about our cyber problem?\u201d I was like, \u201cCan we just not call it a cyber problem? Can we start there?\u201d<!-- \/react-text --><\/p>\n<p data-reactid=\"243\"><strong data-reactid=\"244\"><!-- react-text: 245 -->IL: Your predecessors took a lot of heat for the hack last year. Why did you want to put yourself in that same hot seat?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"246\"><strong data-reactid=\"247\"><!-- react-text: 248 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 249 --> [My wife and I] came to the conclusion this was probably the highest leverage thing that someone like me could do, and I didn\u2019t want to wake up in four years and think I could have helped.<!-- \/react-text --><\/p>\n<p data-reactid=\"250\"><!-- react-text: 251 -->Tom said this a lot when he was recruiting me: This is my generation\u2019s moment to pick up the charge. My generation\u2019s got a whole bunch of people who build self-driving cars and build social-media platforms. We can go do the right things to secure our country, secure our democracy. When my wife and I looked at it through that lens, we were like, \u201cYeah, this is going to be super hard, but we\u2019ve got to try.\u201d<!-- \/react-text --><\/p>\n<p>Krikorian at the DNC headquarters in Washington, D.C.<\/p>\n<p data-reactid=\"261\"><strong data-reactid=\"262\"><!-- react-text: 263 -->IL: Since you\u2019ve gotten here, what have you done to make the party more secure?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"264\"><strong data-reactid=\"265\"><!-- react-text: 266 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 267 --> It\u2019s a whole bunch of staff training. Turn off text messages. Move to end-to-end encryption. Get two-factor authentication in place. We\u2019ve moved all our stuff into the cloud. The nice thing is that so many people want to help us. We\u2019re approached by email and storage providers who are willing to fully disclose what their security plans are and how it\u2019ll help us. We\u2019re taking them up on their offers. We\u2019re figuring out how to partner with Microsoft for email or Google for collaboration tools, and then we use a login provider across all our stuff that enforces two-factor authentication.<!-- \/react-text --><\/p>\n<p data-reactid=\"268\"><!-- react-text: 269 -->It\u2019s not exactly rocket science, but you have to do it holistically. I got Tom Perez to stand up in front of the all-staff meeting and be like, \u201cIf you\u2019re going to talk to me, Tom Perez, you\u2019re using [the encrypted-messaging app] Signal. I will not respond otherwise.\u201d This is important. The nation\u2019s future is at play here. It\u2019s about getting people to think that way. Even in the next few days we\u2019re going to do a series of simulated phishing attacks on the entire DNC staff.<!-- \/react-text --><\/p>\n<p data-reactid=\"270\"><strong data-reactid=\"271\"><!-- react-text: 272 -->IL: Do they know that?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"273\"><strong data-reactid=\"274\"><!-- react-text: 275 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 276 --> You\u2019re the first person I\u2019ve told.<!-- \/react-text --><\/p>\n<p class=\"article-list-item-embed-component__title\" data-reactid=\"290\">Trump&#39;s Win Signals Open Season for Russia&#39;s Political Hackers<\/p>\n<p class=\"article-list-item-embed-component__title\" data-reactid=\"300\">A Guide to Russia\u2019s High Tech Tool Box for Subverting US Democracy<\/p>\n<p class=\"article-list-item-embed-component__title\" data-reactid=\"310\">Email Is Fracturing the Democratic Convention Before It Even Starts<\/p>\n<p data-reactid=\"311\"><strong data-reactid=\"312\"><!-- react-text: 313 -->IL: How much of what you do is tech support and how much is strategizing how tech can help Democratic campaigns?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"314\"><!-- react-text: 315 -->My email is very full. But the vast majority is the latter. You have to remember how tech has worked on the blue team historically. Most innovation happens only around the presidential cycle, then you go through this crash-and-burn period. Right after the presidential cycle, this building emptied out. No institutional knowledge. No information got carried over. There isn\u2019t a culture of make your technology better and better and better over time, so one of the things that we\u2019re trying to do is take a bunch of those really cool things we built for Hillary for America, whether it be volunteer stuff, maybe SMS stuff, email stuff, and make it available to candidates further down the ballot, people who in their campaign budgets can\u2019t afford to fund that type of innovation. The DNC has it. We have all of Hillary\u2019s technology in a code repository, and we have data in our databases.<!-- \/react-text --><\/p>\n<p data-reactid=\"316\"><strong data-reactid=\"317\"><!-- react-text: 318 -->IL: Speaking of Hillary, she&#x27;s been criticizing the DNC\u2019s voter file lately. In an <!-- \/react-text --><a href=\"https:\/\/www.recode.net\/2017\/5\/31\/15723064\/hillary-clinton-trump-twitter-war-covfefe\" target=\"_blank\" data-reactid=\"319\"><!-- react-text: 320 -->interview with Recode<!-- \/react-text --><\/a><!-- react-text: 321 -->, she called the DNC\u2019s data \u201cmediocre to poor, nonexistent, wrong.\u201d What do you make of that?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"322\"><strong data-reactid=\"323\"><!-- react-text: 324 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 325 --> Well, when I first heard it I was really depressed by it. I was like, \u201cReally? I just took the job!\u201d But we have a lot of work to do. Post-2012, there just hasn\u2019t been very much funding of infrastructure or analytics at the DNC. It\u2019s not surprising what she said. We need to modernize our data file. The voter file is an early 2000s thing. We live in a very new world where most people\u2019s time is spent online or on social media or in apps. So that\u2019s where we need to spend our time connecting with people. If you only think about voters as name, landline, and a physical address, you\u2019re not going to connect with that many people that way.<!-- \/react-text --><\/p>\n<p data-reactid=\"326\"><strong data-reactid=\"327\"><!-- react-text: 328 -->IL: Smaller campaigns often complain about the DNC&#x27;s exclusive relationship with one vendor, saying this gives the DNC\u2019s preferred candidates a leg up. Others want the DNC to open its data set to more tech companies with new ideas for targeting voters. How do you plan to approach that tension?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"329\"><strong data-reactid=\"330\"><!-- react-text: 331 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 332 --> What it comes down to is how do we build an ecosystem so more tools can play faster? What we\u2019re seeing in the Virginia governor\u2019s race right now is a whole bunch of tools want to come in and help. It\u2019s not a money-making scheme. They want to try out new methodologies for campaigns, but they\u2019re all getting road-blocked.<!-- \/react-text --><\/p>\n<p data-reactid=\"333\"><!-- react-text: 334 -->What\u2019s missing are some rules of the road around how we\u2019re going to engage around Democratic data. How do we make it really clear that if you\u2019re Tool A, this is the process you need to go through to get access to the data, and if it costs money, this is how much it costs. But the DNC is starting some targeted tests using these tools, because we\u2019re curious about what the effects will be.<!-- \/react-text --><\/p>\n<p data-reactid=\"339\"><strong data-reactid=\"340\"><!-- react-text: 341 -->IL: Shifting gears slightly, you spent five years at Twitter. Given what we&#x27;ve seen recently, do you believe Twitter\u2019s good or bad for democracy?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"342\"><strong data-reactid=\"343\"><!-- react-text: 344 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 345 --> I\u2019ve been at the Twitter VP table. I can imagine what these conversations are like. [sighs]. When I was at Twitter, we literally saw people\u2019s high school proms on the platform. I want people to remember that\u2019s the stuff Twitter is really good at, and then I want to figure out how to teach people to use Twitter better. The president has clearly mastered it, but that\u2019s only one way of doing it. There\u2019s amazing grassroots organizing on the platform. Twitter is a medium, and we need to focus on the people using it.<!-- \/react-text --><\/p>\n<p data-reactid=\"346\"><strong data-reactid=\"347\"><!-- react-text: 348 -->IL: Since Charlottesville, there&#x27;s been a loud debate about how social networks should respond to hate groups. Does Twitter have a role in policing white supremacist content?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"349\"><strong data-reactid=\"350\"><!-- react-text: 351 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 352 --> Probably. I understand the insane position they\u2019re in trying to run a platform for all, while running a business at the same time. But probably is the answer.<!-- \/react-text --><\/p>\n<p data-reactid=\"353\"><strong data-reactid=\"354\"><!-- react-text: 355 -->IL: Last question: were you scared the first time you logged on to the wifi here?<!-- \/react-text --><\/strong><\/p>\n<p data-reactid=\"356\"><strong data-reactid=\"357\"><!-- react-text: 358 -->RK:<!-- \/react-text --><\/strong><!-- react-text: 359 --> Um yeah.<!-- \/react-text --><\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/the-dncs-technology-chief-is-phishing-his-staff-good\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59b0872057ed43108b20f135\/master\/pass\/DNC-tech-chief_MG_6666.jpg\"\/><\/p>\n<p><strong>Credit to Author: Issie Lapowsky| Date: Thu, 07 Sep 2017 10:00:00 +0000<\/strong><\/p>\n<p>Uber&#8217;s former head of self-driving cars is now driving the DNC&#8217;s tech team, hoping to help the shattered organization recover from one of the worst tech fails in history.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-9128","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9128","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9128"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9128\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9128"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9128"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9128"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}