Earlier quoted context omitted.
Entirely possible. Which is why Government services for 'chat' explicitly don't allow contacts to appear who aren't already in the government. You've also no doubt seen email as it appears in Government inboxes with the big red banner "Came from outside, don't trust this" kinds of things will all the links disabled. Two things that are really troublesome. The first, as Josh Marshall of TPM points out, "No one on that…
> Most pundits feel like this administration is trying to keep things out of FOIA and discoverability reach which has its own problems. I don't think we need to ponder so hard about this. This administration is headed by a man who kept stolen TS/SCI national secrets in a bathroom at his house. A fish rots from the head.
U.S. national-security leaders included me in a group chat
471–480 of 1001 posts
Re: U.S. national-security leaders included me in a group chat
#472Earlier quoted context omitted.
Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.
That doesn't really make sense. If they had strong reason to believe that the secure comms systems they were supposed to be using were compromised, using personal phones to communicate outside of SCIFs is very, very far from what any competent person who understands and is briefed on the threat environment would do. Note that none of the people involved are making that argument because it would make them look even mo…
Re: U.S. national-security leaders included me in a group chat
#473In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
I'd go with b: They've been talking for a while about finding information leaks, and the messages themselves seem a bit staged. They probably did it intentionally with different people, with slightly different wording, and because of which version got published they just identified a leak.
Re: U.S. national-security leaders included me in a group chat
#474304 votes, 75 comments 3 hours after posting and this is already being thrown all the way back to 134 rank on the front page with some 2-3 day old posts. This is very clearly hacker news: a case of opsec slipup in easily the worst fashion coming straight from the SecDef (or one representing the SecDef). A shame it is probably getting flamed and downvoted over partisan reasons, although I know there are many conservat…
There are lots of other places to discuss politics.
Re: U.S. national-security leaders included me in a group chat
#475In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
> Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors. If you new that Signal was secretly a front by the CIA/NSA then you'd feel pretty comfortable using it.
Re: U.S. national-security leaders included me in a group chat
#476Earlier quoted context omitted.
I think there is likely a difference between what the FBI does to someone they want info pretty badly from vs what does to someone that they have determined is a keystone to one of their national adversaries. If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you.
> If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you. I've always thought the exact same thing. The harm was ~800m USD to a private company. Sounds big, but it's nothing compared to actual state sponsored anything. Just to add some more (possibly useful) context from the encounter.... The FBI was not able to unlock many LUKS secured devices - at all.…
Re: U.S. national-security leaders included me in a group chat
#477Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…
I don't use Signal, and am unfamiliar with the UI/UX. However, it seems more plausible to me that Jeffrey Goldberg is in someone's contact list from previous on-purpose leaks (to control narrative, etc, typical "anonymous sources say" stuff) - and was accidentally added to this group.
It's very likely that senior government officials have a phone with journalists saved in the contacts. It's easy to imagine why there are rules against using the same phone for secret war stuff, yet here we are.
Re: U.S. national-security leaders included me in a group chat
#478I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…
Why are you specifically calling out you are not suggesting punishment nor prosecution?
There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict.
Okay, fine. But the FBI investigated and laid out the facts.
My fear is that the current administration sees this as a PR problem. No, this was an operational failure. We should feel lucky that merely an American journalist was added by mistake.
We should expect the FBI to investigate this, too. But I worry the facts are too inconvenient for even that level of accountability.
Re: U.S. national-security leaders included me in a group chat
#479Earlier quoted context omitted.
Some layer of ACL and better controls over group membership and message visibility. In this case, if it were an inadvertent added member, then there could be a group/role level restrictions on channels that restrict members from a pool of approved members depending on the security context. Classic security stuff, really. I'm sure others could think of more interesting use cases, but preventing mistaken group adds fee…
Yeah, that's what I thought you meant. This situation is what MAC and specifically MLS are actually for, so that exactly this doesn't happen. There must be mobile devices and texting apps that actually support that but as far as I understand it Android is very far from being able to implement that kind of policy (despite heavy use of SELinux). It's actually weird we don't see this in the corporate world either. These…
Re: U.S. national-security leaders included me in a group chat
#480I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…
More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.