Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

411–420 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#411

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself?

Because these rules and policies are for people that are judged to need them by the person with the authority and responsibility for making the decision.

Policies like these always have a cost and (hopefully) a benefit. Presumably this lead dev judged that the cost vs benefit didn't make sense for themselves but did for others. It's entirely possible they were correct.

Re: U.S. national-security leaders included me in a group chat

#412
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

> Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors.

Once upon a time, I was visited very forcefully by the FBI at 0600. They used a battering ram to gain access to my domicile.

During the "interview" that took place later that morning, they requested some information from me. I told them that the information was contained in Signal conversations between two recipients, and the messages in question have "disappearing messages" turned on. tldr; the messages are no longer available.

Relevant parts of conversation that followed:

me: "Do you have signal?"

agent: "I have it on my phone if that's what you mean."

me: "No, do you HAVE it - as in, do you have access to messages sent between other parties?"

agent: "If we do, I am unaware of it, and we certainly don't 'have it' with regard to this matter."

Take that for what it's worth.... my takeaway was that they(the FBI at least) have not compromised Signal. This was late in 2019 for context.

The other takeaway...be careful who you trust. That all happened because I trusted someone I shouldn't have.

Re: U.S. national-security leaders included me in a group chat

#413
post #80

304 votes, 75 comments 3 hours after posting and this is already being thrown all the way back to 134 rank on the front page with some 2-3 day old posts. This is very clearly hacker news: a case of opsec slipup in easily the worst fashion coming straight from the SecDef (or one representing the SecDef). A shame it is probably getting flamed and downvoted over partisan reasons, although I know there are many conservat…

this site has some governors in place to prevent a flood of low quality engagement. If things rise too fast, they get pushed down a little and cool off and rise back up. No great conspiracy as I found this thread at the top of HN a day later.

Re: U.S. national-security leaders included me in a group chat

#414
post #395

It would be interesting and valuable to have additional security controls in Signal group chats. It's frustrating that the platform is so feature limited.

Can you expand on what you'd like to see?

Some layer of ACL and better controls over group membership and message visibility. In this case, if it were an inadvertent added member, then there could be a group/role level restrictions on channels that restrict members from a pool of approved members depending on the security context. Classic security stuff, really. I'm sure others could think of more interesting use cases, but preventing mistaken group adds feels like low-hanging fruit.

Re: U.S. national-security leaders included me in a group chat

#415
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

This sounds less like a Signal problem than an information organization problem. Signal can only show what's in its datastore (your contact list). I just checked on Android - if you try to add someone to a group chat, it shows their name and profile pic. One potential Signal-side wrinkle is that it allows you to add people to a group chat who are in another chat you're in, but who aren't in your contacts list. There…

Then it's a good thing there's not an Abdul-Malik al-Houthi in the administration, as they might have included the wrong person on the private group chat.

Re: U.S. national-security leaders included me in a group chat

#416

This would be unbelievable in a normal administration. The combination of flagrant lawbreaking and incompetence is just so characteristic of these clowns. No, nothing in the Clinton email scandal comes close to cabinet secretaries accidentally real-time texting imminent war plans to journalists using a non-governmental system with auto-deleting messages.

Could you please stop using HN primarily for political battle? That's not allowed here, regardless of what politics you're for or against.

https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...

https://news.ycombinator.com/newsguidelines.html

(This is not a comment on the current story, or any story.)

Re: U.S. national-security leaders included me in a group chat

#417

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

> Why have a bunch of rules and policies that you do not follow yourself? If you can get away with it, why wouldn't you set things up this way? Rules for thee, not for me. You can't try to view power plays like this through the lenses of ethics or morality. The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them. You do this with media capture…

I think it's more likely a trust issue. He didn't trust the other devs to push things directly, but ofc he trusts himself. I do this with somethings myself. But I also do the inverse, where I don't want to trust myself so I setup a bunch of checks and tests to save my future self from my present self

I think when you're the 'architect' or know the full stack very well, to where you fully repl/grok it and occasionally need to do hot patch type work, the former approach is nice. But, my brain has limited memory and time erodes quickly, so I also know when to rely on the latter approach and I try to do it as much as possible

Re: U.S. national-security leaders included me in a group chat

#419

Earlier quoted context omitted.

SO much for 'the most transparent administration in history', not that I bought into that claim in the first place. Seems like a violation of multiple public record-keeping laws.

But they are extremely transparent. All of their actions are clearly in furtherance of corruption, stealing, and helping Russia (and China) destroy the United States. Unfortunately we also live in the time with the largest mass media consumption (social media), all but guaranteeing their followers keep rationalizing their actions with a litany of talking points rather than understanding straightforward criticism said…

I think 'blatant is a better word to describe this than transparent. Not keeping records of government business makes accountability (political or legal) impossible. But yes, I basically agree with your view.

Re: U.S. national-security leaders included me in a group chat

#420
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

The most likely reason is convenience, not escaping record keeping.
Post reply on HN