Live data from Hacker News

Did the Intercept bungle the NSA leak?

washingtonpost.com

181–190 of 245 posts

Re: Did the Intercept bungle the NSA leak?

#181

Earlier quoted context omitted.

If somebody leaked internal FSB analysis docs claiming but offering no raw intelligence that Ukrainian government is full of US spies and Euromaidan was financed by Soros, would any mainstream media outlet take this kind of source as "evidence"?

It's embarrassing how much some people seem to forget about rationality and skepticism when thinking about this issue. The leaked info contains a few more specifics about the hand waving from a few months ago, but no actual evidence. What's worse is how the wording of the leaked document and press coverage (including that of The Intercept) interleaves simple assertions of fact into the narrative which do not support…

I'll re-pose the question I asked above: what would constitute evidence in this context?

Re: Did the Intercept bungle the NSA leak?

#182

Earlier quoted context omitted.

If somebody leaked internal FSB analysis docs claiming but offering no raw intelligence that Ukrainian government is full of US spies and Euromaidan was financed by Soros, would any mainstream media outlet take this kind of source as "evidence"?

It's embarrassing how much some people seem to forget about rationality and skepticism when thinking about this issue. The leaked info contains a few more specifics about the hand waving from a few months ago, but no actual evidence. What's worse is how the wording of the leaked document and press coverage (including that of The Intercept) interleaves simple assertions of fact into the narrative which do not support…

I don't know about Sam Biddle, but a former CIA agent and whistleblower who served 30 months in prison for leaking CIA's torture techniques, also names Matthew Cole as another reporter that worked on this article and has previously also burned him as a source: https://twitter.com/JohnKiriakou/status/872087259985694721

Re: Did the Intercept bungle the NSA leak?

#183

Nah. Only 6 people have printed the doc and of those only one could be found in phone call metadata making a call to a press related contact. I don't know what the leaker was thinking. And in the end even this leak doesn't contain any evidence of anything that would even tie it to Russia, let alone GRU. On the internet no one knows you're a dog. So she will get 10 years in the slammer for nothing.

Senator Mark Warner publicly commented today that this is not the full extent of Russian attacks. She has succeeded in opening national high-profile public discussion on another aspect of Russian attacks on our election.

I also publicly commented on the matter today. Doesn't make any difference, especially if there's no legal repercussions for lying.

Re: Did the Intercept bungle the NSA leak?

#184

Earlier quoted context omitted.

Yes, but there were only six who printed it to begin with. I'm inclined to agree that the Intercept shouldn't have shared that information with the contractor, but it's not at all clear that the leaker wouldn't have been found anyway.

How does the FBI know it was printed? Because the Intercept told them. It could have been screenshots from a phone. It could have been downloaded from some hack. The number of people that viewed a document is going to be a superset of the number of people that viewed and printed a document. And if they're worried someone could access the report outside of their controls, then the set gets even larger. The Intercept o…

>How does the FBI know it was printed? Because the Intercept told them.

The images have clear fold lines in them.

Re: Did the Intercept bungle the NSA leak?

#185

What I find interesting is that the email from the Gmail account on the work computer was able to be intercepted and logged. What mechanism might they have used, an SSL proxy with a pre-loaded root certificate? How long is this data logged?

Yes, that's pretty standard fare for a corporate firewall/proxy. Most configurations don't log everything, just traffic matching particular patterns or hosts. But when it's the NSA, who knows how much they retain.

> pretty standard fare for a corporate firewall/proxy

It is? So corporations install something that infects your laptop and updates the root certificate every time Chrome or Firefox updates? Sounds extreme to me. Something the NSA might be able to do, but hopefully not my company.

Re: Did the Intercept bungle the NSA leak?

#186
post #168

Earlier quoted context omitted.

She had top secret clearance prior to being hired by Pluribus in February. She was formerly in the Air Force and apparently specialized in Middle Eastern languages. Apparently, top secret clearance is renewed every 5 years [0], so she may have had carte blanche to do what she wanted for a few years. [0] http://www.military.com/veteran-jobs/security-clearance-jobs...

I don't know how that works, but I'd be surprised if there were not a sort-of abbreviated check?

Why would there be? Pluribus doesn't issue security clearances, the customer agency (in this case the NSA) does. It would be up to the NSA to do any additional background checks/vetting/polygraphs regarding security clearance for any contractors. Working for a contractor/switching jobs is hardly suspicious activity, so the NSA would have no reason to investigate her. Likewise Pluribus had no reason to be suspicious, so the most they'd do beyond the standard corporate background check is call up the NSA to confirm her clearance was active. At the end of the day even the NSA doesn't have the resources to be constantly vetting 100,000+ employees and contractors.

Re: Did the Intercept bungle the NSA leak?

#187

Yes, TheIntercept did compromise their source, although she did compromise herself as well due to poor opsec. - TheIntercept failed to sanitize the documents before posting - They provided the govt (or rather a govt contractor) with further information, at least that the mail was posted in Augusta, Georgia. The former can be attributed to simple mistakes, but at least the latter is gross negligence of the highest ord…

But it also begs the obvious question, has TheIntercept been compromised by one of the alphabet agencies? Could it have been intentional on TheIntercept's part but done in a way that gives them plausible deniability? Does seem interesting that TheIntercept isn't treated like Wikileaks for essentially doing the same thing, especially seeing how they're a domestic organization.

Re: Did the Intercept bungle the NSA leak?

#188

Earlier quoted context omitted.

> That would be unbelievably stupid. It's not like in DOJ anyone cares if she "did the right thing" A jury (with nullification power), in principal, might (as might the electorate who choose Presidents who have pardon and clemency power); if you aren't going to flee to avoid capture and aren't confident of your ability to evade the counterintelligence services in the long term, compromising your ability in the short…

You sound like someone who's never been on a jury. Jury gets very exact instructions from the judge before it makes a decision. In these instructions judge interprets the law in a way that the jury will understand. She doesn't tell them how to vote, but in a clear cut case like this one someone who has been selected for impartiality will almost certainly make an accusatory decision. Jury is not a get out of jail free…

> You sound like someone who's never been on a jury

I've not only been on juries, but studied them. Nullification is a thing. It's quite rare and unlikely in the specific circumstance at issue, but that's already factored into the discussion in the grandparent post.

Re: Did the Intercept bungle the NSA leak?

#189
post #181

Earlier quoted context omitted.

It's embarrassing how much some people seem to forget about rationality and skepticism when thinking about this issue. The leaked info contains a few more specifics about the hand waving from a few months ago, but no actual evidence. What's worse is how the wording of the leaked document and press coverage (including that of The Intercept) interleaves simple assertions of fact into the narrative which do not support…

I'll re-pose the question I asked above: what would constitute evidence in this context?

There is no supporting evidence for the assertion that it was "Russia" or about the nature of the "hacking groups".

There is also no consideration of the possibility of false attribution of the above.

Suppose I see that an enemy wears size 10.5 Adidas sneakers. If I buy an identical pair and leave muddy footprints with them near a crime scene, does the presence of the footprints implicate my adversary?

In the case of hacking, our assessment must include a notion of how easy it would be for a nation or group to be falsely implicated.

Separately, there must be a discussion of motive apart from specific evidence. But what we're seeing is a blurring together of various tiny pieces of data, analysis, guesswork, etc., into a narrative.

Within intelligence circles such narratives are meant to be used to allow higher order analysis to proceed in the absence of low level proof.

This is useful in the same way that imagining Travis Kalanick as a misogynist is useful in assessing the question of how such a trait might have impacted corporate culture, but it does not follow that it's true just because one lower-level incident occurred, etc.

Re: Did the Intercept bungle the NSA leak?

#190

I wonder whether NSA uses syntactic watermarking[1], imperceptible changes to word order or sentence form, keyed to the user accessing a document. This, or other techniques of embedding a fingerprint in the text itself, would allow a leaker to be identified from just a transcription of the document. What is the right amount of fuzzing for a news organization to perform on leaked documents, to protect a source while p…

Considering the NSA is an intelligence agency, arbitrarily changing info in intel documents could have serious potential repercussions. I'm thinking they wouldn't unless it was part of a counter-intelligence operation.
Post reply on HN