/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

2020 political campaigns secured emails with physical security keys from a nonprofit working with Google and Microsoft; source says Biden's campaign used keys

Jordan Novet / CNBC : Tweets: @netik , @codinghorror , and @eladgil Tweets: John Adams / @netik : U2F and FIDO worked to stop email attacks this year. Stop using SMS 2FA. Let's get this in the hands of every email and at risk user; https://www.cnbc.com/... Jeff Atwood / @codinghorror : 2FA progress! 👏 https://www.cnbc.com/... Elad Gil / @eladgil : Material Security has great solutions for email security @material_sec https://twitter.com/...

CNBC Jordan Novet

Context & Ripple Effects

This closes a loop that opened with the 2016 DNC breach and the follow-up reporting that Democratic campaigns were still struggling with basic email security two years later. The fix arrived through Google's February 2020 partnership with the nonprofit Defending Digital Campaigns, which put Titan keys and Advanced Protection in campaigners' hands for free, with Material Security extending key-based protection across both Google and Microsoft email.

First-order effects

  • The Biden campaign entered the general election with phishing-resistant hardware keys on its email accounts, per the source — the highest-value target of the cycle covered by the same nonprofit channel built earlier that year.
  • Campaigns running on either Google or Microsoft mail could adopt the same defense, since Material Security's setup works across both platforms rather than locking them into one vendor.

Second-order effects

  • Adoption at the top of the ticket validated the free-distribution model, and Google followed by expanding to free security training for state-level campaigns after supplying Titan keys to more than 140 federal campaigns in 2020.
  • Security-key advocates like John Adams used the result to press the case against SMS-based two-factor authentication, putting pressure on campaigns and vendors still relying on phone codes.

Third-order effects

  • If the pattern holds, campaign cybersecurity stops being an ad-hoc scramble after each breach cycle and becomes standing infrastructure: nonprofits brokering vendor-donated hardware keys as a default for political staff, with state and local races as the next adoption frontier.

The trend: US political campaigns are institutionalizing hardware-key authentication through nonprofit-vendor partnerships, moving from post-breach cleanup toward pre-emptive phishing defense.

Discussion

  • @eladgil Elad Gil on x
    Material Security has great solutions for email security @material_sec https://twitter.com/...
  • @martin_casado Martin Casado on x
    👏👏👏 of course security keys are just a part of an overall defense, but still great to see their use in the campaigns 👏👏👏 https://www.cnbc.com/...
  • @elizabeth_joh Elizabeth Joh on x
    Widespread campaign use of physical security keys—good https://twitter.com/...
  • @boblord Bob Lord on x
    Security keys work. You should use them too. Thanks to @DefendCampaigns for all their efforts! https://www.cnbc.com/...
  • @jordannovet Jordan Novet on x
    many 2020 federal campaigns, including the Biden campaign, distributed physical security keys to their teams, and it appears to have prevented a Podesta-like leak of emails in this cycle. one person i spoke with imagines that keys could be required by law https://www.cnbc.com/...
  • @netik John Adams on x
    U2F and FIDO worked to stop email attacks this year. Stop using SMS 2FA. Let's get this in the hands of every email and at risk user; https://www.cnbc.com/...
  • @codinghorror Jeff Atwood on x
    2FA progress! 👏 https://www.cnbc.com/...