Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

431–440 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#431

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

> Why have a bunch of rules and policies that you do not follow yourself? If you can get away with it, why wouldn't you set things up this way? Rules for thee, not for me. You can't try to view power plays like this through the lenses of ethics or morality. The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them. You do this with media capture…

That’s the definition of authoritarianism.

Re: U.S. national-security leaders included me in a group chat

#432

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

I agree with all of this, my only quibble is that I would bet there have already been costs associated with this idiocy. Hostile powers knew going in that this would be an incompetently run administration and I'm sure were looking at gaining access to personal devices out of the gate. It's possible that a great many highly sensitive conversations have already been read by adversaries. I also expect that similar sloppiness like adding the wrong person to a Signal chat has already happened without being reported on.

Re: U.S. national-security leaders included me in a group chat

#433

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

> Why have a bunch of rules and policies that you do not follow yourself? If you can get away with it, why wouldn't you set things up this way? Rules for thee, not for me. You can't try to view power plays like this through the lenses of ethics or morality. The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them. You do this with media capture…

> If you can get away with it, why wouldn't you set things up this way?

Ethics and morality.

> You can't try to view power plays like this through the lenses of ethics or morality.

Yes, you can, that's the entire point of ethics and morality.

> The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them.

Well, yes, that's the point of the specific actions being discussed; that doesn't make it impossible to look at them through a lens of ethics and morality, it just makes them look bad through such a lens.

Re: U.S. national-security leaders included me in a group chat

#434
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

"it's possible that the current admin working groups don't trust the official secure channels and assume they are compromised and they are being spied upon by their own or foreign agencies"

Jesus Christ, this is dumb. Using a civilian app with civilian phones is literally the best way to get spied on, by either "your own" or foreign agencies. These people are going to get us all killed in a nuclear first strike.

Re: U.S. national-security leaders included me in a group chat

#435
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

Entirely possible. Which is why Government services for 'chat' explicitly don't allow contacts to appear who aren't already in the government. You've also no doubt seen email as it appears in Government inboxes with the big red banner "Came from outside, don't trust this" kinds of things will all the links disabled. Two things that are really troublesome. The first, as Josh Marshall of TPM points out, "No one on that…

> Most pundits feel like this administration is trying to keep things out of FOIA and discoverability reach which has its own problems.

I don't think we need to ponder so hard about this.

This administration is headed by a man who kept stolen TS/SCI national secrets in a bathroom at his house.

A fish rots from the head.

Re: U.S. national-security leaders included me in a group chat

#436

And these guys have been in power for only a few months, they're still finding out about their new tools. What will happen in the next 4 years? will they even leave power peacefully?

Trump has already been president and already demonstrated to us that he will not leave power peacefully. He's openly discussing serving a third term. I think it's highly unlikely that the transfer of power will happen peacefully unless 1) he dies in office (of natural causes) Or 2) the republicans win in 2028 and a different republican president is sworn in.

There are more options than this.

Re: U.S. national-security leaders included me in a group chat

#437
post #424

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.

If the CIA and NSA (let alone Russian and Chinese intelligence) are illegally spying on you, your civilian phone is toast. You shouldn't be ordering DoorDash on the thing.

Re: U.S. national-security leaders included me in a group chat

#438
post #432

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

I agree with all of this, my only quibble is that I would bet there have already been costs associated with this idiocy. Hostile powers knew going in that this would be an incompetently run administration and I'm sure were looking at gaining access to personal devices out of the gate. It's possible that a great many highly sensitive conversations have already been read by adversaries. I also expect that similar slopp…

Yes, this was one of the main points on infosec Mastodon today. While everyone is aware enough to be concerned with encryption over the wire, it's the endpoints that matter. Personal Android devices capable of running Signal are going to be some of the easiest to compromise for a sufficiently motivated attacker. I've seen n00b cops do it for drug gangs here. There's no question that Russia, China, et al. can do it just as well and we have as good as much as confirmation that that's what's going on in at least Tulsi Gabbard's case.

Re: U.S. national-security leaders included me in a group chat

#439

Earlier quoted context omitted.

> Why have a bunch of rules and policies that you do not follow yourself? If you can get away with it, why wouldn't you set things up this way? Rules for thee, not for me. You can't try to view power plays like this through the lenses of ethics or morality. The point is to use rules to bind and punish your enemies and to make sure that only your friends can get away with breaking them. You do this with media capture…

I think it's more likely a trust issue. He didn't trust the other devs to push things directly, but ofc he trusts himself. I do this with somethings myself. But I also do the inverse, where I don't want to trust myself so I setup a bunch of checks and tests to save my future self from my present self I think when you're the 'architect' or know the full stack very well, to where you fully repl/grok it and occasionally…

That's a real difference when something is your final responsibility too (as team lead or an architect). You think of it differently, you predict and anticipate changes better. It's like taking care of your kid vs your kids friend.

Re: U.S. national-security leaders included me in a group chat

#440
post #182

How can we know this group chat was really comprised of government officials and not some bored teenagers? Signal allows you to set your profile name to anything you like.

Watch the Senate Intelligence Committee hearing from earlier today. You can hear one of the participants in that chat acknowledge that he's in it and it's real in response to the questions of committee members. This is not in question, at all.

The natural and insider language of the chat, and (especially) the perfect timing of the strikes with the planning in the tread, also make it extremely unlikely this was anything but a genuine conversation, even without confirmation. The alternative is a combination of a very-prepared fraudster with either their own source of privileged information (to get the timing right) or else an incredible coincidence such that their entirely fake and uninformed planning matched the timing set out in the real planning. That it was genuine is far, far more likely than either of those (one of which raises its own, different security concerns, anyway)
Post reply on HN