2020 political campaigns secured emails with physical security keys from a nonprofit working with Google and Microsoft; source says Biden's campaign used keys
Jordan Novet / CNBC : Tweets: @netik , @codinghorror , and @eladgil Tweets: John Adams / @netik : U2F and FIDO worked to stop email attacks this year. Stop using SMS 2FA. Let's get this in the hands of every email and at risk user; https://www.cnbc.com/... Jeff Atwood / @codinghorror : 2FA progress! 👏 https://www.cnbc.com/... Elad Gil / @eladgil : Material Security has great solutions for email security @material_sec https://twitter.com/...
Context & Ripple Effects
This closes a loop that opened with the 2016 DNC breach and the follow-up reporting that Democratic campaigns were still struggling with basic email security two years later. The fix arrived through Google's February 2020 partnership with the nonprofit Defending Digital Campaigns, which put Titan keys and Advanced Protection in campaigners' hands for free, with Material Security extending key-based protection across both Google and Microsoft email.
First-order effects
- The Biden campaign entered the general election with phishing-resistant hardware keys on its email accounts, per the source — the highest-value target of the cycle covered by the same nonprofit channel built earlier that year.
- Campaigns running on either Google or Microsoft mail could adopt the same defense, since Material Security's setup works across both platforms rather than locking them into one vendor.
Second-order effects
- Adoption at the top of the ticket validated the free-distribution model, and Google followed by expanding to free security training for state-level campaigns after supplying Titan keys to more than 140 federal campaigns in 2020.
- Security-key advocates like John Adams used the result to press the case against SMS-based two-factor authentication, putting pressure on campaigns and vendors still relying on phone codes.
Third-order effects
- If the pattern holds, campaign cybersecurity stops being an ad-hoc scramble after each breach cycle and becomes standing infrastructure: nonprofits brokering vendor-donated hardware keys as a default for political staff, with state and local races as the next adoption frontier.
The trend: US political campaigns are institutionalizing hardware-key authentication through nonprofit-vendor partnerships, moving from post-breach cleanup toward pre-emptive phishing defense.