Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

381–390 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#381

From people on Reddit: Something that blows my mind- but is fully true "Hell, I've been in fucking EVE Online alliances that had better opsec than this." "I'll raise you one: I've never been in any EVE alliance that didn't have better opsec than this." ..I noted Board Games(Secret Hitler, for example) require better opsec. So do card games- it's mindblowing to note this too... [Main comment by me - technical outlook]…

> From people on Reddit: Something that blows my mind- but is fully true "Hell, I've been in fucking EVE Online alliances that had better opsec than this." "I'll raise you one: I've never been in any EVE alliance that didn't have better opsec than this."

That is some seriously selective memory

https://old.reddit.com/r/Eve/comments/4cdmmc/wtf_is_going_on...

https://old.reddit.com/r/Eve/comments/4dvoj5/sma_diplosleade...

https://old.reddit.com/r/Eve/comments/4f3epd/a_different_kin...

And here's some more recent ones

https://old.reddit.com/r/Eve/comments/1f6t1vw/your_relays_ar...

https://old.reddit.com/r/Eve/comments/1g3p232/alcoholic_sata...

Major alliance infrastructure and security is probably better than most US corporations but doesn't come close to secure government systems, obviously

Re: U.S. national-security leaders included me in a group chat

#382

Amazing that with H.N.'s doctrinaire application of the exact original title rule, this is the title that the mods chose to editorialize.

Remember: every comment on here is implicitly directed to dang, and every link is implicitly approved of by dang.

This is really his website at this point. The rules are mainly just his tools for shaping the content of discussions and submissions to his liking.

A decade ago it was different. I mean, he was still way overbearing and biased, but I don’t think it really had the same power-steering effect on the shapes of discussions as it does today. Over time, this is where we’ve come to.

Re: U.S. national-security leaders included me in a group chat

#383

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

As one such developer, it is a powerful ability to be able to bypass restrictions meant to be used sparingly for a good reason

I rarely commit the same kind of code the full time professional developer do(when bypassing policies).

Typically it is stuff like urgent patch in prod that may not have coverage , or partial long running refactor which breaks existing tests but better to be able merge quickly than keep the branch constantly free of merge conflicts , or experimental exploratory new type of code(new lang , stack whatever )for which we have to yet evolve processes, part of what the lead is supposed to be exploring and so on.

Although In my experience junior leads more often than not abuse their privileges than use it well.

Re: U.S. national-security leaders included me in a group chat

#384

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

> Why have a bunch of rules and policies that you do not follow yourself?

If you can get away with it, why wouldn't you set things up this way? Rules for thee, not for me. You can't try to view power plays like this through the lenses of ethics or morality. The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them. You do this with media capture and twisted narratives, taking advantage of the erosion of rule of law as a respected concept among the public.

Re: U.S. national-security leaders included me in a group chat

#385

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

I’m not seeing the parallels.

Trump went on about Hillary’s mail and made it a big thing for political points, not because he was particularly caring or didn’t have infamously bad opsec when he got in.

You lead dev trusted himself more than the team. He was probably right.

Re: U.S. national-security leaders included me in a group chat

#386

Earlier quoted context omitted.

This is why you have a constitution, codified laws, judicial system, separation of powers, etc. We're just learning now none of these things are worth the paper they're written on.

It's just as useful and effective as the international law and order that was setup after WW2. So nada.

As long as you build an order around independence of countries and diplomacy (instead of, say, force) any organisation will only be as useful as countries are willing to follow and any structure can only be as good as the ones in charge are willing to go.

In consequences there are many flaws and a lot is stuck in post WW2 thinking, but I doubt there is a realistic chance of anything overall better.

The current U.S. administration tries to reshape things by disruption, we will see how this goes, but I doubt this will earn trust and buy-in from others. Thus not lead to a stable and "better" system. (While better, of course, is not globally objective, which again is key to the problem)

Re: U.S. national-security leaders included me in a group chat

#387
post #77

If anything, I'm a bit surprised that Jeff Goldberg burned this source. If anything, I'd suspect that he'd keep the channel open as long as he could. Or, he's got other channels that work better. All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing. Like, very clearly, these people are going to get…

"If anything, I'd suspect that he'd keep the channel open as long as he could."

The real story is that he was added to the channel, so it doesn't surprise me that he didn't try to lurk indefinitely. I'm guessing these things are also ad-hoc, so perhaps the well was already dry after the attack?

But this is some truly amateur-hour shit. I've seen better communications discipline from volunteer open source projects than this.

Re: U.S. national-security leaders included me in a group chat

#389
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

[dead]

Re: U.S. national-security leaders included me in a group chat

#390
In my opinion there are at least two ways to interpret this:

a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely.

b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowback risk.

Regarding using Signal in the first place. Yes, this seems like bad opsec, but it's possible that the current admin working groups don't trust the official secure channels and assume they are compromised and they are being spied upon by their own or foreign agencies. That seems very likely, given the circumstances. In which case, it is still a possible opsec failure, but perhaps a less bad risk than trusting operational security to known adverse agencies. This is the more interesting case, imho, since the assumption on here is largely that these types of coordination should be happening on official government channels. But "government" is not necessarily a unified collective working towards the same goals. If you have a strong suspicion that agents within your own team are acting against your goals, then of course, you have to consider communicating on alternative channels. Whether that's to evade legal restrictions or transparency, like with the Clinton email servers, or to evade sabotage, I'm not judging the ethics, just considering the necessity of truly secure communication.

Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors.

Post reply on HN