US election laws, which prohibit companies from providing candidates services at a discount, are hampering cybersecurity work, a weakness for 2020 campaigns
small organizations, with short life spans, small budgets, and little to no IT expertise — to go up against the intelligence agencies of adversarial governments. It's not a fair fight. https://twitter.com/... @pinboard : Really good article in the New York Times about how campaign finance law makes it nearly impossible to secure campaigns. This is a narrow area where you really want companies to give be able to give special treatment and freebies to political campaigns. https://www.nytimes.com/... @nytimes : Campaign finance rules are limiting cybersecurity options for presidential candidates who, in most cases, cannot afford to pay outside experts market rates for such services https://www.nytimes.com/... Nicole Perlroth / @nicoleperlroth : NEW: One year out from 2020, presidential candidates face legal roadblocks to acquiring the tools and assistance necessary to defend against the phishing attacks and disinformation campaigns that plagued the 2016 presidential campaign. https://www.nytimes.com/... Nicole Perlroth / @nicoleperlroth : Just your periodic reminder that @senatemajldr Mitch McConnell has refused to bring any election security bill to the Senate floor. And our president thinks any discussion of shoring up 2020 is just a knock on the legitimacy of the '16 election. https://www.nytimes.com/...
Context & Ripple Effects
The Times' reporting lands on a specific legal choke point in a system already documented as fragile: hackers penetrated voter-registration networks in 2016 and much of that infrastructure remains largely unchanged two years on, while federal responses to Russian interference are still judged inadequate heading into 2020. This piece adds a layer the earlier vulnerability coverage didn't name — campaign finance rules treat discounted security services as illegal contributions, so the entities most exposed to state-sponsored hacking are barred from accepting help at below-market rates.
First-order effects
- Presidential campaigns — short-lived organizations with small budgets and no in-house IT expertise — must either pay full commercial rates for cybersecurity or run unprotected against adversarial intelligence agencies.
Second-order effects
- Security vendors and experts route around the prohibition by organizing outside the contribution framework: the related coverage shows volunteer-matching efforts like Election Cyber Surge pairing experts with local election officials, who sit outside campaign finance limits entirely.
Third-order effects
- With Mitch McConnell refusing to bring election security legislation to the Senate floor and the White House framing security measures as attacks on 2016's legitimacy, the structural fix — a campaign-finance carve-out for defensive cyber services — has no legislative path, leaving ad hoc private volunteering as the de facto policy.
The trend: US election defense is increasingly supplied by informal expert-volunteer networks because both campaign finance law and congressional inaction close off the official channels.