【】

When it comes to United States Senate email accounts, you'd think the powers that be would enact a basic security feature that even Yahoo Mail and AOL have down.
Shocker: You would be wrong.
SEE ALSO:The best thing you can do to protect yourself from hackersAs an April 20 open letter from Oregon Senator Ron Wyden makes clear, Senate email accounts lack the option to enable two-factor authentication. Like, senators can't turn it on even if they want to.
"As you know, the cybersecurity and foreign intelligence threats directed at Congress aresignificant," wrote Wyden in the letter addressed to two Senate colleagues. "However, the Senate is far behind when it comes to implementing basic cybersecurity practices like two-factor authentication."
What exactly is two-factor authentication (2FA), and why does this matter? Let's let the experts over at the Electronic Frontier Foundation explain.
"Login systems that require only a username and password risk being broken when someone else can obtain (or guess) those pieces of information," notes the organization. "Services that offer two-factor authentication also require you to provide a separate confirmation that you are who you say you are. The second factor could be a one-off secret code, a number generated by a program running on a mobile device, or a device that you carry and that you can use to confirm who you are."
An easy-to-grasp example of 2FA is your bank ATM card. In order to withdraw cash, you need the PIN (something you know) and the card itself (something you have). Those two factors combine to allow you, and hopefully only you, to access to your hard-earned dollars.

With 2FA turned on, even if someone gains your email password (like maybe just possibly through a phishing attack) they still lack the necessary credentials to get into your inbox. This seems like something sitting members of the United States Senate and their staff would be interested in, right?
And yet.
"Today, the Senate neither requires nor offers two-factor authentication as an additionalprotection for desktop computers and email accounts," writes Wyden. "The Senate Sergeant at Arms does require two-factor authentication for staff who wish to log in to Senate IT systems from home, using a Virtual Private Network. This is a good first step, but the Senate must go further and embrace two-factor authentication for the workplace, and not just for staff connecting from home."
Offering 2FA is often viewed as one of several basic security litmus tests for online services. Gmail, Twitter, Facebook, AOL, and even the much-maligned Yahoo Mail make it easy to turn this on — meaning your grandmother's email account is potentially more secure than your senator's.
As that depressing little nugget of information sinks in, Wyden hits us with a jaw-dropping follow. The executive branch, you see, offers employees Personal Identity Verification (PIV) cards which contain smart chips. The chips work as part of a 2FA system for employees to log into computers. The senate also offers PIV cards, Wyden tells us, but these don't have smart chips.
What do they have instead?
"[In] contrast to the executive branch's widespread adoption of PIV cards with a smartchip, most senate staff ID cards have a photo of a chip printed on them, rather than a real chip."
That's right, a photo of a chip printed on them.
So, to recap: Senate email accounts aren't protected by 2FA, and most Senate staff ID cards have fake smart chips.
Next on the agenda, we assume, is the revelation that the password to each and every senators' personal voicemail account is just "0000."
Featured Video For You
Edward Snowden says Russians probably hacked the NSA
TopicsCybersecurityYahoo
相关文章
This coloring book is here for all your relationship goals
LONDON -- We are living through the golden age of celebrity relationships. Gone are the days of tort2025-02-28- 前言:答 :《問情》演唱:蔡幸娟山川載不動太多悲哀歲月禁不起太長的等待春花最愛向風中搖擺黃沙偏要將癡和怨掩埋一世的聰明情願糊塗一身的遭遇向誰訴愛到不能愛聚到終須散繁華過後成一夢啊海水永不幹天也望不穿紅塵2025-02-28
- 借你吉吉什麽梗?借你吉吉是什麽梗:up主祝福,彈幕就表達感謝“借你吉言” 。視頻隻要有祝福之類的就開始刷“借你吉言”,我尋思這些人生活裏是有多淒慘?一行刷可以,半屏刷也O...借你吉吉是什麽意思?你真實2025-02-28
- ?隻要老鼠被黃鼠狼盯上,90%是跑不掉的,黃鼠狼捉老鼠可厲害了,和貓一樣直接鎖喉 。基本上一隻黃鼠狼,一 。黃鼠狼吃老鼠肉嗎?黃鼠狼吃老鼠是老鼠的 。黃鼠狼是吃老鼠的,是老鼠的天敵,它機智靈活的身體能製服比2025-02-28
- With the Pokémon Go fever still shaking half the world, there's bound to be plenty of trainer2025-02-28
- 水性筆是什麽筆?水性筆水性筆使用油墨為純水性,紙對其的吸收性強。水性筆一般使用在吸收麵上,即使塗在非吸收麵上,也可以擦去,書寫在紙上一般沒有背痕。優點是書寫手感與書。水性筆是中性筆嗎?水筆是寫小楷用的2025-02-28
最新评论