People who are involved with political campaigns face increased digital security threats from well-funded, sophisticated attackers, especially nation-states. Improving political campaign security is a vital part of protecting democracy. To identify campaign security issues, we conducted qualitative research with 28 participants across the U.S. political spectrum to understand the digital security practices, challenges, and perceptions of people involved in campaigns. A main, overarching finding is that a unique combination of threats, constraints, and work culture lead people involved with political campaigns to use technologies from across platforms and domains in ways that leave them--and democracy--vulnerable to security attacks. Sensitive data was kept in a plethora of personal and work accounts, with ad hoc adoption of strong passwords, two-factor authentication, encryption, and access controls. No individual company, committee, organization, campaign, or academic institution can solve the identified problems on their own. To this end, we provide an initial understanding of this complex problem space and recommendations for how a diverse group of experts can begin working together to improve security for political campaigns.
翻译:参与政治运动的人面临来自资金充足、精密的攻击者,特别是民族国家,更多的数字安全威胁。改善政治运动安全是保护民主的重要部分。为了查明运动安全问题,我们与美国政治各界28名参与者进行了定性研究,以了解参与运动的人的数字安全做法、挑战和看法。一项主要的总体发现是,各种威胁、限制和工作文化的独特组合导致参与政治运动的人以使他们和民主易受安全攻击的方式利用各种平台和领域的技术。敏感数据被保存在无数的个人和工作账户中,临时采用了强有力的密码、两要素的认证、加密和准入控制。没有单个公司、委员会、组织、运动或学术机构能够自己解决所查明的问题。为此,我们初步了解了这一复杂问题空间,并建议一个多样化的专家组如何开始共同努力,改善政治运动的安全。