时间:2026-01-02 12:29:03 来源:网络整理编辑:時尚
When it comes to United States Senate email accounts, you'd think the powers that be would enact a b
When it comes to United States Senate email accounts, you'd think the powers that be would enact a basic security feature that even Yahoo Mail and AOL have down.
Shocker: You would be wrong.
SEE ALSO:The best thing you can do to protect yourself from hackersAs an April 20 open letter from Oregon Senator Ron Wyden makes clear, Senate email accounts lack the option to enable two-factor authentication. Like, senators can't turn it on even if they want to.
"As you know, the cybersecurity and foreign intelligence threats directed at Congress aresignificant," wrote Wyden in the letter addressed to two Senate colleagues. "However, the Senate is far behind when it comes to implementing basic cybersecurity practices like two-factor authentication."
What exactly is two-factor authentication (2FA), and why does this matter? Let's let the experts over at the Electronic Frontier Foundation explain.
"Login systems that require only a username and password risk being broken when someone else can obtain (or guess) those pieces of information," notes the organization. "Services that offer two-factor authentication also require you to provide a separate confirmation that you are who you say you are. The second factor could be a one-off secret code, a number generated by a program running on a mobile device, or a device that you carry and that you can use to confirm who you are."
An easy-to-grasp example of 2FA is your bank ATM card. In order to withdraw cash, you need the PIN (something you know) and the card itself (something you have). Those two factors combine to allow you, and hopefully only you, to access to your hard-earned dollars.
Sen. Ron Wyden just can't believe this.Credit: Chip Somodevilla /Getty ImagesWith 2FA turned on, even if someone gains your email password (like maybe just possibly through a phishing attack) they still lack the necessary credentials to get into your inbox. This seems like something sitting members of the United States Senate and their staff would be interested in, right?
And yet.
"Today, the Senate neither requires nor offers two-factor authentication as an additionalprotection for desktop computers and email accounts," writes Wyden. "The Senate Sergeant at Arms does require two-factor authentication for staff who wish to log in to Senate IT systems from home, using a Virtual Private Network. This is a good first step, but the Senate must go further and embrace two-factor authentication for the workplace, and not just for staff connecting from home."
Offering 2FA is often viewed as one of several basic security litmus tests for online services. Gmail, Twitter, Facebook, AOL, and even the much-maligned Yahoo Mail make it easy to turn this on — meaning your grandmother's email account is potentially more secure than your senator's.
As that depressing little nugget of information sinks in, Wyden hits us with a jaw-dropping follow. The executive branch, you see, offers employees Personal Identity Verification (PIV) cards which contain smart chips. The chips work as part of a 2FA system for employees to log into computers. The senate also offers PIV cards, Wyden tells us, but these don't have smart chips.
What do they have instead?
"[In] contrast to the executive branch's widespread adoption of PIV cards with a smartchip, most senate staff ID cards have a photo of a chip printed on them, rather than a real chip."
That's right, a photo of a chip printed on them.
So, to recap: Senate email accounts aren't protected by 2FA, and most Senate staff ID cards have fake smart chips.
Next on the agenda, we assume, is the revelation that the password to each and every senators' personal voicemail account is just "0000."
TopicsCybersecurityYahoo
Researchers create temporary tattoos you can use to control your devices2026-01-02 11:54
2023冬季轉會窗盤點 :英超最壕、切爾西最闊綽 、恩佐最貴2026-01-02 11:53
喜訊!國羽男雙連爆冷門:22026-01-02 11:42
得分榜前8!7人集中在兩隊 ,1人為太陽效力 ,7人做過哈登隊友(詹姆斯生涯三分球排名)2026-01-02 11:20
Photos show the Blue Cut fire blazing a path of destruction in California2026-01-02 11:00
直擊詹皇衝擊3萬分失敗 :遭球迷狂噓 談換帥有遲疑(詹姆斯是nba最厲害的嗎)2026-01-02 11:00
官方 :2022/23賽季英超賽程公布2026-01-02 10:33
今日賽事:英超(布倫特福德vs利物浦)2026-01-02 10:13
This German startup wants to be your bank (without being a bank)2026-01-02 10:03
現役NBA帶動隊友最強的十名球星:自帶進攻體係!(詹姆斯投進了多少個三分)2026-01-02 09:42
Twitter grants everyone access to quality filter for tweet notifications2026-01-02 12:19
大P球星匯“超人類”勒布朗2026-01-02 12:18
除了詹姆斯 ,現役僅這4人有望突破30000分 ,庫裏哈登上榜(最強nba詹姆斯三分準嗎)2026-01-02 11:24
【波盈足球】 旭村盃少年足賽 女子組冠軍賽PK超刺激 ( 國泰,世華 )2026-01-02 11:18
Visualizing July's astounding global temperature records2026-01-02 11:06
成長不規劃 ,來年差距大 !2023斯坦星球全年賽事規劃請查收2026-01-02 10:57
原創 世界羽聯宣布2023年至2026年巡回賽將增加四站賽事!! !2026-01-02 10:43
【波盈足球】 影絕境靠C羅 !聯賽首球就是追平球 助艾納斯驚險逼和對手 ( 進球,聯賽 )2026-01-02 10:26
Pole vaulter claims his penis is not to blame2026-01-02 10:24
黑馬一路爆冷登頂 ,國羽2金2銀收獲頗豐,韓國名將3進決賽2冠1亞2026-01-02 09:48