One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…
This was covered in a recent kaspersky paper[1], which I found in [2], where it is termed "fourth-party collection". The pdf gives a more complete description on page 2 (I found the increasing level of separation between collector and reciever to be almost comical) [1] https://cdn.securelist.com/files/2017/10/Guerrero-Saade-Raiu... [2] https://news.ycombinator.com/item?id=15663985
We (US, Soviet Union, etc) had this figured out in the 60s when we were primarily using human intel. [1] Except the danger that now, instead of walking out with rolls of film covering a few thousand pages, someone can take everything they have access to in My only explanation is all those long-won counter-intelligence lessons were thrown out when the Young Turks showed up with their "we can do it all and more via software" ways. Because they delivered (and you've probably seen this in your org) they were excluded from having all the pain-in-the-ass rules applied to them.
It seems our intelligence agencies now look exactly like our commercial software -- more featureful, more agile, less secure, less stable.
[1] https://en.m.wikipedia.org/wiki/T._A._Robertson https://www.cia.gov/library/center-for-the-study-of-intellig... https://www.salon.com/2015/09/26/how_to_explain_the_kgbs_ama...