Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

391–400 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#391
post #377

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

Or not even the device: The other reason we have SCIFs is they provide a secure location. These personal devices could have been in use anywhere, including places where they were subject to observation. Including but not limited to Moscow. :)

Another excellent point.

Re: U.S. national-security leaders included me in a group chat

#392
post #374

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

It seems one of the people (and thus the phone) was actually in Moscow during the chat!

That counts as a friendly country these days =(

Re: U.S. national-security leaders included me in a group chat

#394

Earlier quoted context omitted.

> Sounds like he received the message purposefully and pretends it was an mistake? Why would he have been added to the group? For what purpose would the current National Security Advisor have to bring in an outsider to discussions that ended up involving almost certainly classified data? > 2h is a lot but not that much time He was added to the group two days (13 March) before the strikes (15 March), not two hours.

My guess is as a honeypot: see who would publish this alleged "leak" and give the administration justification to "open an investigation" on them.

[dead]

Re: U.S. national-security leaders included me in a group chat

#396
post #124

seems like a UI design failure

UI could be considered failure if we were talking about casual gossip. Particular UI shouldn't be the issue because the App was not supposed to be used for this. These should be professionals. Issue was between keyboard and chair.

Re: U.S. national-security leaders included me in a group chat

#397

Amazing that with H.N.'s doctrinaire application of the exact original title rule, this is the title that the mods chose to editorialize.

Remember: every comment on here is implicitly directed to dang, and every link is implicitly approved of by dang. This is really his website at this point. The rules are mainly just his tools for shaping the content of discussions and submissions to his liking. A decade ago it was different. I mean, he was still way overbearing and biased, but I don’t think it really had the same power-steering effect on the shapes o…

I happen to know first hand that the thread is not going quite to dang's liking at the moment. I'm hoping it improves, but people are having a hard time sticking to the technical and security aspects.

Re: U.S. national-security leaders included me in a group chat

#398
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

Entirely possible. Which is why Government services for 'chat' explicitly don't allow contacts to appear who aren't already in the government. You've also no doubt seen email as it appears in Government inboxes with the big red banner "Came from outside, don't trust this" kinds of things will all the links disabled.

Two things that are really troublesome. The first, as Josh Marshall of TPM points out, "No one on that chat asked 'Why are we doing this on Signal?'" which suggests that it isn't the first time Signal was used for 'off books' stuff and that perhaps there are many such conversations. The second is that the conversation was set up while one of the participants was in the Kremlin waiting to talk to Putin. So either 'Kremlin Free WiFi' or the local cell tower providing connectivity?

Most pundits feel like this administration is trying to keep things out of FOIA and discoverability reach which has its own problems.

So yes, tools for Government communications don't have this problem, hell even Microsoft Teams on their US cloud get better protection than this.

Re: U.S. national-security leaders included me in a group chat

#400
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

Option (a) 100%.

This is an abysmal mistake on the big stage for a bunch of new people on the job. That it is the intelligence community makes it feel so much worse.

Post reply on HN