Live data from Hacker News

Did the Intercept bungle the NSA leak?

washingtonpost.com

201–210 of 245 posts

Re: Did the Intercept bungle the NSA leak?

#201

Earlier quoted context omitted.

Unless you are a whistleblower and feel that the public legitimately needs to know about something, because afterall this election affects our daily lives. We deserve to to know the truth about threats to democracy, especially when Presidential candidates are still claiming that voter data was rigged. Didn't Trump blame Hillary for him losing the popular vote, saying that it was her fault for hacking the election?

Was it really vital that this tidbit be leaked right now now? Mueller is currently performing an extremely detailed official investigation of this topic and has access to this and much more information, the resources to follow up, the motive to find the truth. Whistleblowing is warranted in cases where information pertinent to the public interest won't come out otherwise. Given Mueller's investigation, the responsibl…

- Mueller's is a criminal investigation. If he doesn't believe he can prove a criminal case, the public will never hear about it. Even if, for example, he had enough to prove that some specific Russian hacker changed the records of enough voting machines to change the outcome of the election: If that guy subsequently died, he wouldn't have a criminal case and the case would be dropped without further commentary.

- It's really not the government's job to decide what the public has an interest in knowing. The system is, for the most part, set up as "default public", and that's how it should be.

- The fact that information (may) come out eventually doesn't help if it requires action now. I believe it's quite obvious that the public debate about these hacks is happening now, and that this is information that is central to that debate. Let's say nothing happens to prevent future hacking, and we learn about this incident in three or five years: I have no trouble imagining FOX commentators dismissing it as "We had this fight in 2017, and now the democrats want to talk about it again?"

Re: Did the Intercept bungle the NSA leak?

#202
post #121

Earlier quoted context omitted.

What would constitute evidence in this context? To me, this statement which was: * made contemporaneously with the investigation * by experts * not intended for public consumption is evidence. It's not a formal proof, but it's evidence.

If somebody leaked internal FSB analysis docs claiming but offering no raw intelligence that Ukrainian government is full of US spies and Euromaidan was financed by Soros, would any mainstream media outlet take this kind of source as "evidence"?

The difference between these cases is that even considering everything that is wrong with US administration, it is just not comparable to the Russian. People (and institutions) have a track record, and there's no principle in logic that prevents me from using that record to evaluate their trustworthiness: What you call an ad hominem, I call bayesian reasoning.

For example: It was, until this administration, extremely rare for the US government (the executive, to be precise) to lie to US-based press. They'd deny to comment, or say something that was meaningless when examined closely, or tell you to ask X (who will deny to comment). But, contrary to common believe, it's extremely hard to find examples for them straight-up saying A when knowing that it's really B.

Re: Did the Intercept bungle the NSA leak?

#203

Earlier quoted context omitted.

Senator Mark Warner publicly commented today that this is not the full extent of Russian attacks. She has succeeded in opening national high-profile public discussion on another aspect of Russian attacks on our election.

I also publicly commented on the matter today. Doesn't make any difference, especially if there's no legal repercussions for lying.

The difference is that a Senator (who is vice chair of the Senate Intelligence Committee) is privy to more information than you are.

And lying can have very real consequences for politicians, even when it happens without breaking a law.

Re: Did the Intercept bungle the NSA leak?

#204
post #146
post #49

Earlier quoted context omitted.

It helps Americans by bringing them more truthful journalism, by allowing the reporters to report independently verified facts rather than hearsay

Exactly. I think it's also informative to look at how attribution was viewed in the past. We as a tech community used to almost pride ourselves on our skepticism, as can be seen in this Bruce Schneier post[0] on Stuxnet. In the post (written in 2010), he points out that attributing Stuxnet to the US Government is "almost entirely speculation", that ties to the Bushehr nuclear power plant were "rumors" at the time, an…

Isn't the Stuxnet story actually a good example of the tech community maybe taking their scepticism too far?

I'm also really sceptical of what, if anything, the government could provide as evidence that people would accept. If the evidence is technical, that doesn't only prevent non-technical people from evaluating it. It also means it's susceptible to being called "fake" when it isn't.

Say, for example, the NSA has log data from a bunch of switches across the world, and maybe the Russians also tapped into a few honeypots. All the NSA then has is IP addresses and other system logs–all of which could easily be faked.

Concerning your last point: Yes, we would treat the reverse different. And there's nothing wrong with judging some information by their record: If I read something on a website that open 6 pop-ups for porn, and that I have never seen before, I'm going to trust it less than the New York Times, which has, contrary to popular myth, an excellent track record of trying their best and making it public when they fail.

Re: Did the Intercept bungle the NSA leak?

#205

Earlier quoted context omitted.

I don't think The Intercept has much responsibility here at all. In my opinion, in their role as receivers of leaked information, they should verify the information provided to them and decide if it should be released to the public. Sure, they shouldn't reveal their source and The Intercept met that requirement by insuring that they themselves did not know the leaker's identity. Anyone who is thinking about leaking a…

I'm not doubting that the NSA would have figured out the source eventually, yellow dots or not, but I think it's a fair criticism to say the Intercept did not have to publish a picture of the document in full, instead of transcribing the contents.

It could still make a major difference when it comes to the question of what they can prove in court.

Re: Did the Intercept bungle the NSA leak?

#206

I wonder whether NSA uses syntactic watermarking[1], imperceptible changes to word order or sentence form, keyed to the user accessing a document. This, or other techniques of embedding a fingerprint in the text itself, would allow a leaker to be identified from just a transcription of the document. What is the right amount of fuzzing for a news organization to perform on leaked documents, to protect a source while p…

How would changes to word order or sentence form be imperceptible?

"Imperceptible without comparing to other versions of the same document"

Re: Did the Intercept bungle the NSA leak?

#207

Earlier quoted context omitted.

Yes, that's pretty standard fare for a corporate firewall/proxy. Most configurations don't log everything, just traffic matching particular patterns or hosts. But when it's the NSA, who knows how much they retain.

> pretty standard fare for a corporate firewall/proxy It is? So corporations install something that infects your laptop and updates the root certificate every time Chrome or Firefox updates? Sounds extreme to me. Something the NSA might be able to do, but hopefully not my company.

If you're running Windows, it's built into the OS using Group Policy. Very helpful when a company is running it's own internal CA/PKI.

Re: Did the Intercept bungle the NSA leak?

#209

Earlier quoted context omitted.

The search warrant says that the internal audit and (logged-in?) gmail account were the smoking gun. Page 11, paragraphs 14-16: https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f47... > 14. The U.S. Government Agency [NSA] examined the document shared by the News Outlet [The Intercept] and determined the pages of the intelligence reporting appeared to be folded and/or creased, suggesting they had been printed…

Rather revealing that the "Agency" was privy not only to the e-mail metadata but also the contents. Watching outbound SMTP from Gmail or just MiTM internal agency traffic?

Could be an ordinary search warrant. Supposedly the Intercept also told the govt. that the document was mailed with an Augusta postmark. The postmark + being the only person to print the document in that city seems like reasonable basis for a search warrant, but I'm not a lawyer.
Post reply on HN