Earlier quoted context omitted.
The Intercept scanned the document and posted high quality versions of them online. They were of such quality that the embedded dots modern printers add to each page were readily available: http://blog.erratasec.com/2017/06/how-intercept-outed-realit... It pointed to the exact printer being used and the exact time and date the document was printed. They didn't need her email to figure out it was her, but I'm sure tha…
In the vast majority of cases, the watermark data wouldn't point anywhere interesting. Maybe the serial number would point to a public library or a warehouse where the printer was stored prior to sale. Certainly The Intercept had no way of knowing that the serial number would correspond to an office printer at the NSA or one of their contractors. I don't think we should expect news outlets to scour every printed docu…
Did the Intercept bungle the NSA leak?
191–200 of 245 posts
Re: Did the Intercept bungle the NSA leak?
#192Earlier quoted context omitted.
In the vast majority of cases, the watermark data wouldn't point anywhere interesting. Maybe the serial number would point to a public library or a warehouse where the printer was stored prior to sale. Certainly The Intercept had no way of knowing that the serial number would correspond to an office printer at the NSA or one of their contractors. I don't think we should expect news outlets to scour every printed docu…
Actually the Intercept should have known. Margaret Thatcher used water marking to find which Ministry was leaking stories in the 80s. It's standard practice to retype documents before sharing, set up well thought out, secure amnesty boxes, etc.
My first thought is that even blogs like AndroidPolice protect their sources better than The Intercept does here - they go as far as re-creating screenshots or renders of phone leaks.
The Intercept's lack of care is astounding. There wasn't any reason they needed to publish the fact that they received printed copies, let alone the actual scans.
Re: Did the Intercept bungle the NSA leak?
#193Earlier quoted context omitted.
I don't know how that works, but I'd be surprised if there were not a sort-of abbreviated check?
Why would there be? Pluribus doesn't issue security clearances, the customer agency (in this case the NSA) does. It would be up to the NSA to do any additional background checks/vetting/polygraphs regarding security clearance for any contractors. Working for a contractor/switching jobs is hardly suspicious activity, so the NSA would have no reason to investigate her. Likewise Pluribus had no reason to be suspicious,…
Re: Did the Intercept bungle the NSA leak?
#194Earlier quoted context omitted.
She had top secret clearance prior to being hired by Pluribus in February. She was formerly in the Air Force and apparently specialized in Middle Eastern languages. Apparently, top secret clearance is renewed every 5 years [0], so she may have had carte blanche to do what she wanted for a few years. [0] http://www.military.com/veteran-jobs/security-clearance-jobs...
I don't know how that works, but I'd be surprised if there were not a sort-of abbreviated check?
For social media activity, someone would likely have to report you for anyone to take action.
I for one think its pretty reasonable, it sucks working for the government enough already, if we put people under 24x7 surveillance just for trying to serve their country they will go from having very few talented/ethical people working for them to absolutely none.
Re: Did the Intercept bungle the NSA leak?
#195Earlier quoted context omitted.
I'll re-pose the question I asked above: what would constitute evidence in this context?
There is no supporting evidence for the assertion that it was "Russia" or about the nature of the "hacking groups". There is also no consideration of the possibility of false attribution of the above. Suppose I see that an enemy wears size 10.5 Adidas sneakers. If I buy an identical pair and leave muddy footprints with them near a crime scene, does the presence of the footprints implicate my adversary? In the case of…
> Separately, there must be a discussion of motive apart from specific evidence. But what we're seeing is a blurring together of various tiny pieces of data, analysis, guesswork, etc., into a narrative.
Do you believe that the intelligence community has failed to consider these fairly obvious principles when producing their reports?
It seems you've constructed a belief system by which you can never be convinced of Russia's involvement. This is what I was getting at with my question above (which you didn't really answer).
Re: Did the Intercept bungle the NSA leak?
#196Earlier quoted context omitted.
Yes, that's pretty standard fare for a corporate firewall/proxy. Most configurations don't log everything, just traffic matching particular patterns or hosts. But when it's the NSA, who knows how much they retain.
> pretty standard fare for a corporate firewall/proxy It is? So corporations install something that infects your laptop and updates the root certificate every time Chrome or Firefox updates? Sounds extreme to me. Something the NSA might be able to do, but hopefully not my company.
Re: Did the Intercept bungle the NSA leak?
#197Earlier quoted context omitted.
Unless you are a whistleblower and feel that the public legitimately needs to know about something, because afterall this election affects our daily lives. We deserve to to know the truth about threats to democracy, especially when Presidential candidates are still claiming that voter data was rigged. Didn't Trump blame Hillary for him losing the popular vote, saying that it was her fault for hacking the election?
Was it really vital that this tidbit be leaked right now now? Mueller is currently performing an extremely detailed official investigation of this topic and has access to this and much more information, the resources to follow up, the motive to find the truth. Whistleblowing is warranted in cases where information pertinent to the public interest won't come out otherwise. Given Mueller's investigation, the responsibl…
Re: Did the Intercept bungle the NSA leak?
#198Earlier quoted context omitted.
Why would there be? Pluribus doesn't issue security clearances, the customer agency (in this case the NSA) does. It would be up to the NSA to do any additional background checks/vetting/polygraphs regarding security clearance for any contractors. Working for a contractor/switching jobs is hardly suspicious activity, so the NSA would have no reason to investigate her. Likewise Pluribus had no reason to be suspicious,…
How about applying machine learning towards vetting social media wrt people with TS and >TS clearance?
Re: Did the Intercept bungle the NSA leak?
#199Earlier quoted context omitted.
There is no supporting evidence for the assertion that it was "Russia" or about the nature of the "hacking groups". There is also no consideration of the possibility of false attribution of the above. Suppose I see that an enemy wears size 10.5 Adidas sneakers. If I buy an identical pair and leave muddy footprints with them near a crime scene, does the presence of the footprints implicate my adversary? In the case of…
> In the case of hacking, our assessment must include a notion of how easy it would be for a nation or group to be falsely implicated. > Separately, there must be a discussion of motive apart from specific evidence. But what we're seeing is a blurring together of various tiny pieces of data, analysis, guesswork, etc., into a narrative. Do you believe that the intelligence community has failed to consider these fairly…
No, but I think that those spreading these kinds of reports are intentionally masking the way that they are meant to be used in intelligence circles. This happened during the buildup to the Iraq war also.
My point is that the reports make those leaps intentionally in order to support higher order analysis. They are not meant to be taken as a distillation of all of the available intel.
> you can never be convinced of Russia's involvement
Not at all. But your use of the word "involvement" is a great example of insinuation. What does "involvement" mean in this case? I'll take a stab at it:
- Russia is a geopolitical adversary to the US (check)
- Russia and the US are engaged in a proxy war on several fronts and have been for decades (check)
- Russia and the US both undertake various mischief campaigns against each other and have since the cold war (check)
- Russia and the US both have at least two distinct offensive and defensive capabilities... one being cyber "warfare" and another being cyber "mischief". (check and check)
I agree on all of the above. I think many of the people who are up in arms about the Russia story did not believe the above until quite recently, yet it has been the case for a long time.
The appropriate analysis is to consider whether Russia actually thought it would impact the outcome of the US election, or if it intended to merely create mischief and chaos/mistrust. Clearly the latter is true per the history between the two nations and is consistent with the ongoing mischief campaign.
A deliberate effort to hack election machines, trigger power failures in hospitals, or any variety of more severe attacks crosses the line from "cyber mischief" into "cyber warfare".
What we're seeing is the anti-Russia hawks seizing upon the mischief and trying to make it seem like a cause for war. Don't forget that many have been vehemently trying to get the US to use force against Russia for quite some time.
Thus, the key evidence that is needed to escalate Russia's "involvement" from routine mischief and turn it into something akin to "warfare" is the hard evidence of intent to harm infrastructure.
While spear phishing voting machine companies may signal intent to conduct a Stuxnet style attack on US electronic voting machines, is spear phishing really a nation-state level attack approach?
Clearly, unless "The Russians" had far better predictive models than American statisticians, it would have been utterly foolish to undertake an attack that would personally tick off the sure-thing presidential candidate.
So I think that proof entails both a clear delineation of what sort of behavior/mischief is actually abnormal or asymmetric, and the notion of what constitutes proof of intent to escalate.
Re: Did the Intercept bungle the NSA leak?
#200Earlier quoted context omitted.
The Intercept scanned the document and posted high quality versions of them online. They were of such quality that the embedded dots modern printers add to each page were readily available: http://blog.erratasec.com/2017/06/how-intercept-outed-realit... It pointed to the exact printer being used and the exact time and date the document was printed. They didn't need her email to figure out it was her, but I'm sure tha…
Pretty sure she sent the document which means she made the mistake of sending high resolution scans.