时间:2025-01-18 16:49:02 来源:网络整理编辑:時尚
When it comes to United States Senate email accounts, you'd think the powers that be would enact a b
When it comes to United States Senate email accounts, you'd think the powers that be would enact a basic security feature that even Yahoo Mail and AOL have down.
Shocker: You would be wrong.
SEE ALSO:The best thing you can do to protect yourself from hackersAs an April 20 open letter from Oregon Senator Ron Wyden makes clear, Senate email accounts lack the option to enable two-factor authentication. Like, senators can't turn it on even if they want to.
"As you know, the cybersecurity and foreign intelligence threats directed at Congress aresignificant," wrote Wyden in the letter addressed to two Senate colleagues. "However, the Senate is far behind when it comes to implementing basic cybersecurity practices like two-factor authentication."
What exactly is two-factor authentication (2FA), and why does this matter? Let's let the experts over at the Electronic Frontier Foundation explain.
"Login systems that require only a username and password risk being broken when someone else can obtain (or guess) those pieces of information," notes the organization. "Services that offer two-factor authentication also require you to provide a separate confirmation that you are who you say you are. The second factor could be a one-off secret code, a number generated by a program running on a mobile device, or a device that you carry and that you can use to confirm who you are."
An easy-to-grasp example of 2FA is your bank ATM card. In order to withdraw cash, you need the PIN (something you know) and the card itself (something you have). Those two factors combine to allow you, and hopefully only you, to access to your hard-earned dollars.
Sen. Ron Wyden just can't believe this.Credit: Chip Somodevilla /Getty ImagesWith 2FA turned on, even if someone gains your email password (like maybe just possibly through a phishing attack) they still lack the necessary credentials to get into your inbox. This seems like something sitting members of the United States Senate and their staff would be interested in, right?
And yet.
"Today, the Senate neither requires nor offers two-factor authentication as an additionalprotection for desktop computers and email accounts," writes Wyden. "The Senate Sergeant at Arms does require two-factor authentication for staff who wish to log in to Senate IT systems from home, using a Virtual Private Network. This is a good first step, but the Senate must go further and embrace two-factor authentication for the workplace, and not just for staff connecting from home."
Offering 2FA is often viewed as one of several basic security litmus tests for online services. Gmail, Twitter, Facebook, AOL, and even the much-maligned Yahoo Mail make it easy to turn this on — meaning your grandmother's email account is potentially more secure than your senator's.
As that depressing little nugget of information sinks in, Wyden hits us with a jaw-dropping follow. The executive branch, you see, offers employees Personal Identity Verification (PIV) cards which contain smart chips. The chips work as part of a 2FA system for employees to log into computers. The senate also offers PIV cards, Wyden tells us, but these don't have smart chips.
What do they have instead?
"[In] contrast to the executive branch's widespread adoption of PIV cards with a smartchip, most senate staff ID cards have a photo of a chip printed on them, rather than a real chip."
That's right, a photo of a chip printed on them.
So, to recap: Senate email accounts aren't protected by 2FA, and most Senate staff ID cards have fake smart chips.
Next on the agenda, we assume, is the revelation that the password to each and every senators' personal voicemail account is just "0000."
TopicsCybersecurityYahoo
Xiaomi accused of copying again, this time by Jawbone2025-01-18 16:47
西甲資訊:巴薩升入積分榜第二 皇馬賽季中簽約新援2025-01-18 16:03
郝偉透露莫伊塞斯將離隊 李鬆益基本確定加盟申花2025-01-18 16:03
津門虎隊新賽季人員構架搭建完成 楊帆完成回歸第一練2025-01-18 15:55
Nate Parker is finally thinking about the woman who accused him of rape2025-01-18 15:53
本澤馬 :飛一般的感覺 讓我們回主場見證最終結果2025-01-18 15:27
官方 :科曼從2023年起擔任荷蘭隊主帥 簽約至2026年2025-01-18 15:23
歐冠最佳進球 :本澤馬哈弗茨掰頭 丁丁馬內團隊秀2025-01-18 15:04
Darth Vader is back. Why do we still care?2025-01-18 14:33
丁丁一擊製勝撕破床單軍 連斬皇薩競成歐冠第六人2025-01-18 14:10
We asked linguists if Donald Trump speaks like that on purpose2025-01-18 16:30
莫雷諾談02世界杯執法韓意戰:生涯最佳表現之一 沒有偏袒韓國2025-01-18 16:19
泰山海港敲定外援中鋒 中超“一擲千金”的時代徹底翻篇2025-01-18 16:16
曼聯新帥另一大人選鎖定安切洛蒂 已進行初步谘詢2025-01-18 15:56
Olympic security asks female Iranian fan to drop protest sign2025-01-18 15:50
曼晚:博格巴期待偉大回歸 不是回曼聯而是回尤文2025-01-18 15:28
英媒 :兩年一屆世界杯計劃失敗 FIFA欲改為3年一屆2025-01-18 15:14
魯尼卡拉格稱C羅應離開曼聯 CR7回應 :兩個嫉妒的人2025-01-18 15:14
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2025-01-18 15:02
姆巴佩薩拉赫極限1換1? 克洛普 :買哈蘭德不好玩2025-01-18 15:00