Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

401–410 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#401
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

> It was an intentional leak

I don't see how this would work. If you're the leaker, do you just add the journalist to the group yourself? How are you going to explain that? I think there are more anonymous ways to leak stuff than adding someone else to the group chat. Or does signal not show who added someone?

Re: U.S. national-security leaders included me in a group chat

#402

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

The example you give is about control - he wanted control over everyone else's inputs but trusted himself. Not a great look as a leader.

Re: U.S. national-security leaders included me in a group chat

#403
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

[deleted]

Re: U.S. national-security leaders included me in a group chat

#404

And these guys have been in power for only a few months, they're still finding out about their new tools. What will happen in the next 4 years? will they even leave power peacefully?

Trump has already been president and already demonstrated to us that he will not leave power peacefully. He's openly discussing serving a third term. I think it's highly unlikely that the transfer of power will happen peacefully unless

1) he dies in office (of natural causes)

Or

2) the republicans win in 2028 and a different republican president is sworn in.

Re: U.S. national-security leaders included me in a group chat

#405
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

I don't think using Signal is the biggest problem in terms of security, though it's against the rules to use something not explicitly approved.

The bigger security problem is that it was being run on devices that evidently weren't limited to secure communication tasks (such devices wouldn't have a journalist in their contacts). That suggests at least some people were using personal phones, which seems like a terrible idea.

Re: U.S. national-security leaders included me in a group chat

#406
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

With the level of disdain for Europe in the leak, it’s hard not to think b.

Re: U.S. national-security leaders included me in a group chat

#407
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

Can users in a group add/invite others in? My firth though was someone doing it on the sly, to leak deliberately.

Goldberg is not a fan of Trump

I did not believe there was any way this was done accidentally...

Re: U.S. national-security leaders included me in a group chat

#408
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA).

To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence agency in the world. It matters little if the information was encrypted in transit if the host device is compromised.

One would have to be a fool to not trust all of the classified tools and safeguards the US government uses only to then use a commercial app on commercial phones to communicate classified data in public while stateside and abroad. Just the fact that someone could accidentally add an unauthorized person to the chat is but one reason it was crazy for them to do this.

Re: U.S. national-security leaders included me in a group chat

#409
post #328
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

> Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... Is that so shocking? I watch often some forums on reddit related to combat footage, not frequently but enough to see various patterns. Before houthis started attacking shipping lanes, there were tons of videos of them kicking ass of Saudi military but way more often some su…

I think the poster was talking about the shock of the lapse in security, not the shock of houthi air strikes

Re: U.S. national-security leaders included me in a group chat

#410
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

> It was an intentional leak I don't see how this would work. If you're the leaker, do you just add the journalist to the group yourself? How are you going to explain that? I think there are more anonymous ways to leak stuff than adding someone else to the group chat. Or does signal not show who added someone?

I have not read this article, but I saw the headline this morning.

I am reading it now.

https://www.ibtimes.co.uk/signal-app-owned-china-it-safe-use...

Edit: nothing to see here.

"So, is Signal App owned by China? The answer is no... Signal is run by the Signal Foundation, a non-profit based in San Francisco... Amidst this controversy, it's crucial to remember that Signal's roots are firmly planted on American soil, dispelling any notion of Chinese ownership."

Post reply on HN