Live data from Hacker News

Did the Intercept bungle the NSA leak?

washingtonpost.com

11–20 of 245 posts

Re: Did the Intercept bungle the NSA leak?

#11
post #3

Yes, or maybe no. It doesn't really matter, because this is just one of many battles being waged in the current cyber-war gripping our lives. I mean, we have to just see it in the larger context: there is very definitely a war going on among various, nefarious, otherwise, or indeterminate, hostile parties. It seems that if we must dismantle the military-industrial state, it is going to be through info-wars. The key t…

Yeah I think it's basically guaranteed that this is what we would hear regardless of how they found the leaker. Maybe this method was used, maybe they looked at printer looks, maybe they looked at access logs to the document, etc. Regardless, they _say_ that the problem was The Intercept's handling because there is no way to verify it and it makes them look bad. Really this news should be taken with a grain of salt.

That said, the important thing for any leaker to do is to try as much as possible to obscure any links they have to the documents before handing them off to third parties even if those third parties are supposedly trusted (because once you hand the documents off, you are no longer in control).

Re: Did the Intercept bungle the NSA leak?

#12

Have we learned nothing about the NSA's tactics? The Intercept publishes reporting that they would rather not have been printed, and the very day the DOJ unseals charges where they try to say they learned about the leak from a paper crease from what can be reasonably inferred to be The Intercept. Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept (in contradiction with their recomm…

> It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again.

A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.

Re: Did the Intercept bungle the NSA leak?

#13
post #2

As with every headline that poses a yes/no question, the answer is usually "no". EDIT: I'm also unsure what the point of shifting the focus onto The Intercept's alleged "mishandling" of the leaker's identity is. It seems like a smear job meant to discredit a publication that the natsec community and mainstream media like WaPo dislike. It also removes the focus from the substance of the leaks and puts it on the "chara…

I'm not sure how you can arrive at "no" here. Regardless of how you feel about the politics involved, if you publish information that outs a source you've "bungled" it almost by definition.

Re: Did the Intercept bungle the NSA leak?

#15
post #12

Have we learned nothing about the NSA's tactics? The Intercept publishes reporting that they would rather not have been printed, and the very day the DOJ unseals charges where they try to say they learned about the leak from a paper crease from what can be reasonably inferred to be The Intercept. Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept (in contradiction with their recomm…

> It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again. A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.

If you trust that what the NSA/DOJ says is true, sure.

Re: Did the Intercept bungle the NSA leak?

#16
Any article that ends with a yes/no question is always answered with "no". This one is no exception. Print classified info out at work on work printers from a monitored work computer you are logged into and said info ends up with reporters days later? Reporters you communicated with over gmail?! This person isn't exactly an infosec genius. Which, I mean, isn't a sin or anything, but when you know the organization you are directly burning is the NSA and the president of the United States, that's almost an insane level of ignorance.

Re: Did the Intercept bungle the NSA leak?

#17
post #3

Yes, or maybe no. It doesn't really matter, because this is just one of many battles being waged in the current cyber-war gripping our lives. I mean, we have to just see it in the larger context: there is very definitely a war going on among various, nefarious, otherwise, or indeterminate, hostile parties. It seems that if we must dismantle the military-industrial state, it is going to be through info-wars. The key t…

I'm curious: If there is a war going on, did this leak help or hinder? Which side did it help or hinder? Who benefits from this leak, and who is harmed?

I have a sinking suspicion that the average American, for example, isn't benefited by this leak.

Re: Did the Intercept bungle the NSA leak?

#18
post #12

Have we learned nothing about the NSA's tactics? The Intercept publishes reporting that they would rather not have been printed, and the very day the DOJ unseals charges where they try to say they learned about the leak from a paper crease from what can be reasonably inferred to be The Intercept. Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept (in contradiction with their recomm…

> It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again. A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.

There's no evidence that it was The Intercept's actions that caused her to be found. I agree that they should be more careful (they should _always_ be more careful), but there are many ways the source could have been found independent of the newspaper. Regardless, the government has many incentives to claim that it was The Intercept's deficient opsec that caused them to find the leaker.

There really isn't much you can reasonably conclude about this. Is the government lying? Is The Intercept incompetent? The only thing you should remember is that if you are going to leak documents you need to do as much as possible while they are still in your control to hide your involvement. Once you send them off, your fate is in the hands of others.

Re: Did the Intercept bungle the NSA leak?

#19
post #12

Have we learned nothing about the NSA's tactics? The Intercept publishes reporting that they would rather not have been printed, and the very day the DOJ unseals charges where they try to say they learned about the leak from a paper crease from what can be reasonably inferred to be The Intercept. Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept (in contradiction with their recomm…

> It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again. A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.

In a situation like this, you as the leaker have a lot more to lose than whoever you're leaking to.

In that situation, I'm sorry, but the responsibility for protecting your identity is on you. Anonymize the data. Do not leak something that only you would have access to. etc, etc.

Because unless you're leaking to Infowars, you have to expect that a legitimate journalist will present your data to the organization from which you leaked it to, and request comment.

Snoweden did everything right, and it still wasn't good enough.

Re: Did the Intercept bungle the NSA leak?

#20
post #10

The yellow dots thing was certainly a mistake on their part. But there's a much bigger issue I haven't seen anyone point out yet. One thing that the Intercept--and Glenn Greenwald in particular--have been very critical of is news organizations that blindly publish leaks as verified facts. Here[0] is just one example where Greenwald writes: > THE WASHINGTON POST late Friday night published an explosive story that, in…

How does the information you're describing (IP addresses used, ties to Russia, malware shape) help the average American if disclosed publicly? Because the harm seems immediate: bad actors will change their tactics and burn their channels, making them harder to detect, trace, or understand.

Given that the average American barely understands what a computer virus is, is the level of technical detail you're calling for sensible for public dissemination?

Post reply on HN