Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

441–450 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#441

Earlier quoted context omitted.

The fourt cases related to Watergate established that receiving classified information is not illegal, and affirmed 1A rights. I'd argue it's a exactly the same as a journalist overhearing this motley crew discussing the war plan in the halls of the White House without being aware there's a journalist nearby. I wouldn't bank on the current supreme court to uphold precedence, or the current administration persecuting…

The US Supreme Court hews close to precedent. The only two significant overturned decisions in the last decade are Roe v Wade, which regardless of your views on abortion was a poorly reasoned decision, which was really judicial legislation, that had to be essentially amended several times (whether abortion should be permitted is a separate question from whether Roe was good law, which it obviously wasn't) and Chevron…

> The SCOTUS doesn't split along ideological or party lines all the time.

It happens enough on cases that matter that it's farcical not to put (R) and (D) after the names of the justices, for clarity, when discussing them in the press.

Re: U.S. national-security leaders included me in a group chat

#442
post #424

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.

That doesn't really make sense. If they had strong reason to believe that the secure comms systems they were supposed to be using were compromised, using personal phones to communicate outside of SCIFs is very, very far from what any competent person who understands and is briefed on the threat environment would do. Note that none of the people involved are making that argument because it would make them look even more incompetent.

Re: U.S. national-security leaders included me in a group chat

#443
post #45

Reminds me of https://en.wikipedia.org/wiki/German_Taurus_leak „Among the topics the officials discussed in their conversation, conducted using standard commercial Cisco Webex video conferencing software, were the presence of UK and US military personnel in Ukraine and the potential use of Taurus missiles to blow up the Crimean Bridge.“

A thing using authorized channels that was spied on by a different state has practically nothing in common with this. (Yes, it probably shouldn't have been an authorized channel, but it was.)

Though the channel wasn’t cleared for the level of information that was discussed.

WebEx was cleared up to the equivalent of Restricted. The conversation likely reached the level of Secret or Top Secret.

Two of the generals were disciplined. (4-figure fine)

Re: U.S. national-security leaders included me in a group chat

#444
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

I don't use Signal, and am unfamiliar with the UI/UX.

However, it seems more plausible to me that Jeffrey Goldberg is in someone's contact list from previous on-purpose leaks (to control narrative, etc, typical "anonymous sources say" stuff) - and was accidentally added to this group.

Re: U.S. national-security leaders included me in a group chat

#445

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself? Because these rules and policies are for people that are judged to need them by the person with the authority and responsibility for making the decision. Policies like these always have a cost and (hopefully) a benefit. Presumably this lead dev judged…

One of the main purposes of code review is to ensure that your code is understandable to other people. Good lead developers understand this. Bad ones find a way to push through their changes without review or get them rubber stamped, in my experience. Then you end up with big parts of the codebase that only the lead dev can work in productively.

Re: U.S. national-security leaders included me in a group chat

#446
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

> Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors.

If you new that Signal was secretly a front by the CIA/NSA then you'd feel pretty comfortable using it.

Re: U.S. national-security leaders included me in a group chat

#447
Here's how Eisenhower dealt with a similar leak.[1]

General Henry Miller made public comments about the secret date of the Allied invasion of Normandy in May 1944. He was a personal friend of Eisenhower. Eisenhower demoted him and sent him back to the US in disgrace. He wasn't court-martialed.

[1] https://youtu.be/fD0IlFPTopA?t=269

Re: U.S. national-security leaders included me in a group chat

#448
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

They can bake any Tom Clancy style excuse they want. They broke the law and they're incompetent. Even if you want to ignore one, they still need to go. Making mistakes like this anywhere else would cost you your job.

Re: U.S. national-security leaders included me in a group chat

#449
post #422

Earlier quoted context omitted.

> Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors. Once upon a time, I was visited very forcefully by the FBI at 0600. They used a battering ram to gain access to my domicile. During the "interview" that took place later that morning, they requested some…

I think there is likely a difference between what the FBI does to someone they want info pretty badly from vs what does to someone that they have determined is a keystone to one of their national adversaries. If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you.

> If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you.

I've always thought the exact same thing. The harm was ~800m USD to a private company. Sounds big, but it's nothing compared to actual state sponsored anything.

Just to add some more (possibly useful) context from the encounter....

The FBI was not able to unlock many LUKS secured devices - at all. They had zero success over approx 30 days, and had to explore alternative methods to obtain key material.

The FBI was not able to decrypt blowfish2 (ie vim -x).

The FBI was not able to decrypt ccrypt secured files (ie aes256).

Re: U.S. national-security leaders included me in a group chat

#450
post #424

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.

The administration has not made this argument though. You have.

So why should we default to the position of not trusting those systems when every previous administration has used it without issus.

Post reply on HN