Are the 2020 Democrats Really Ready for Hackers?

Meet the Pete Buttigieg staffer working “to make sure 2016 doesn’t happen again.”

Christy Prosser/ZUMA Wire

Fight disinformation: Sign up for the free Mother Jones Daily newsletter and follow the news that matters.

What’s it like to be responsible for the digital security of a presidential campaign? Ask Mick Baccio, the only publicly-designated chief information security officer on the staff of a 2020 candidate.

“As far as I know, I’m the only CISO on any presidential campaign,” he said Thursday. “I have no idea why.”

Given the impact that information security lapses had on Hillary Clinton’s 2016 campaign, it’s a good question why he’s alone. Baccio, who works for Democrat and South Bend Mayor Pete Buttigieg, says his job is to help keep the campaign’s data secure and train staffers on security issues related to their jobs “to make sure 2016 doesn’t happen again.”

It’s not easy. Campaigns add and shed employees in fits and starts, with people moving in any number of directions at once. Staff come in with their own phones, computers, and digital habits, and with varying levels of security literacy after working on other campaigns or in government.

Baccio took the job in July after a long career in information security including stints at the Pentagon and the White House. He was hesitant to sign on, given the temporary nature of political campaigns. “This job might end in March, it might end in November, it might end at any point in between then,” he said. “So it’s not really a good selling point.”

But he found the set of challenges presented by the campaign interesting, and decided it was an opportunity that might not come again, Baccio says. “It’s been non-stop since.”

One such challenge are the third-party vendors that modern campaigns rely on for fundraising, field planning, and managing donor lists. A whole universe of companies facilitate these efforts, offering campaigns convenience and scale. The tradeoff is another avenue by which sensitive data can be compromised, warns Baccio. The danger was highlighted in 2016 when Guccifer 2.0, a front persona created by Russian military intelligence that provided stolen Democratic materials to WikiLeaks and journalists baselessly claimed that it had accessed records through NGP VAN, a fundraising and donor organizational platform for progressive campaigns. (Experts believe Russian hackers obtained the documents from other Democratic systems.)*

“All the campaigns access this ecosystem. I’m only as secure as [these platforms and their users],” Baccio explained.

Baccio, who was speaking at Cyberwarcon, a day-long information security gathering in northern Virginia, raised two outside threats to the campaign that he’s tracking. One is the potential for “deepfakes,” or fabricated or manipulated videos that seem to show a person saying or doing something they never said or did. “We keep the mayor in front of a camera pretty much all his waking hours,” Baccio said. “So if there is that doctored video we have the original and we can combat it.”

Another is spoofed website domains or other methods that can deceive internet users. For example, the website petebuttigieg.org redirects to donaldjtrump.com. “We should have bought that domain a while ago,” he joked.

While Baccio avoided certain specifics about the campaign’s security practices and training methods, he said he’s focused on creating an overall security culture with a particular eye on the major threats represented by nation-states like Russia and China, both of whom have hacked US presidential campaigns before.

“I’m putting something into place where it’s never, ever been before, and we’re moving at 100 miles an hour,” he said. “Any campaign that’s out there, I think we’re competitors, not opponents.”

“I don’t care if it’s left or right, I care if it’s Russian or Iranian,” he said.

This paragraph has been updated with additional context about Guccifer 2.0’s claims.

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate