Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

471–480 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#471

Earlier quoted context omitted.

Entirely possible. Which is why Government services for 'chat' explicitly don't allow contacts to appear who aren't already in the government. You've also no doubt seen email as it appears in Government inboxes with the big red banner "Came from outside, don't trust this" kinds of things will all the links disabled. Two things that are really troublesome. The first, as Josh Marshall of TPM points out, "No one on that…

> Most pundits feel like this administration is trying to keep things out of FOIA and discoverability reach which has its own problems. I don't think we need to ponder so hard about this. This administration is headed by a man who kept stolen TS/SCI national secrets in a bathroom at his house. A fish rots from the head.

Keeps*. He took them back some weeks ago

Re: U.S. national-security leaders included me in a group chat

#472
post #424

Earlier quoted context omitted.

Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.

That doesn't really make sense. If they had strong reason to believe that the secure comms systems they were supposed to be using were compromised, using personal phones to communicate outside of SCIFs is very, very far from what any competent person who understands and is briefed on the threat environment would do. Note that none of the people involved are making that argument because it would make them look even mo…

Not arguing it was the best choice. But, I'm curious, if you were in the position where you had strong reasons to believe the official secure channels available to you were compromised by your political opponents who were leaking information received via those channels to undermine your policy initiatives, and needed to act and coordinate nonetheless, what would you do?

Re: U.S. national-security leaders included me in a group chat

#473
post #455
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

I'd go with b: They've been talking for a while about finding information leaks, and the messages themselves seem a bit staged. They probably did it intentionally with different people, with slightly different wording, and because of which version got published they just identified a leak.

[deleted]

Re: U.S. national-security leaders included me in a group chat

#474
post #80

304 votes, 75 comments 3 hours after posting and this is already being thrown all the way back to 134 rank on the front page with some 2-3 day old posts. This is very clearly hacker news: a case of opsec slipup in easily the worst fashion coming straight from the SecDef (or one representing the SecDef). A shame it is probably getting flamed and downvoted over partisan reasons, although I know there are many conservat…

People often flag politics-related posts because the comments are invariably of low quality. The interesting discussion is generally about technical issues, but that is usually overwhelmed by political opinions. This happens on both sides of the spectrum.

There are lots of other places to discuss politics.

Re: U.S. national-security leaders included me in a group chat

#475
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

> Is that trust in Signal justified? It suggests members at the highest security clearances believe Signal is not compromised. Are they correct? In any case, clearly there are more ways to fail opsec than backdoors. If you new that Signal was secretly a front by the CIA/NSA then you'd feel pretty comfortable using it.

Secretly? Surely you're not suggesting people on Signal Foundation's board are intelligence assets? Surely, you're joking. That could never, ever, ever be the case. Why would you say such things.

Re: U.S. national-security leaders included me in a group chat

#476
post #422

Earlier quoted context omitted.

I think there is likely a difference between what the FBI does to someone they want info pretty badly from vs what does to someone that they have determined is a keystone to one of their national adversaries. If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you.

> If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you. I've always thought the exact same thing. The harm was ~800m USD to a private company. Sounds big, but it's nothing compared to actual state sponsored anything. Just to add some more (possibly useful) context from the encounter.... The FBI was not able to unlock many LUKS secured devices - at all.…

Wtf were you up to :rubschin:

Re: U.S. national-security leaders included me in a group chat

#477
post #444
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

I don't use Signal, and am unfamiliar with the UI/UX. However, it seems more plausible to me that Jeffrey Goldberg is in someone's contact list from previous on-purpose leaks (to control narrative, etc, typical "anonymous sources say" stuff) - and was accidentally added to this group.

When adding people to a chat, it shows the contact list from the device, with avatars. It is also possible to manually enter a phone number or username.

It's very likely that senior government officials have a phone with journalists saved in the contacts. It's easy to imagine why there are rules against using the same phone for secret war stuff, yet here we are.

Re: U.S. national-security leaders included me in a group chat

#478

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

Why are you specifically calling out you are not suggesting punishment nor prosecution?

Because I don't know whether either of those are appropriate.

There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict.

Okay, fine. But the FBI investigated and laid out the facts.

My fear is that the current administration sees this as a PR problem. No, this was an operational failure. We should feel lucky that merely an American journalist was added by mistake.

We should expect the FBI to investigate this, too. But I worry the facts are too inconvenient for even that level of accountability.

Re: U.S. national-security leaders included me in a group chat

#479
post #414

Earlier quoted context omitted.

Some layer of ACL and better controls over group membership and message visibility. In this case, if it were an inadvertent added member, then there could be a group/role level restrictions on channels that restrict members from a pool of approved members depending on the security context. Classic security stuff, really. I'm sure others could think of more interesting use cases, but preventing mistaken group adds fee…

Yeah, that's what I thought you meant. This situation is what MAC and specifically MLS are actually for, so that exactly this doesn't happen. There must be mobile devices and texting apps that actually support that but as far as I understand it Android is very far from being able to implement that kind of policy (despite heavy use of SELinux). It's actually weird we don't see this in the corporate world either. These…

A stupid simple way to do it would be to use control groups as security pools. If you are not a member some master control group, then you can't be added to related spawned "child" groups. Better than what is there now, which is nothing. Would have to be client level controls, maybe a smart contract could govern, but could Signal build on the current abstractions by having groups be members of groups and inherit the same "phonebook" as the group they are a member of. Just spitballing.

Re: U.S. national-security leaders included me in a group chat

#480

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

At least here in the UK our politicians delete all their messages on WhatsApp https://www.politico.eu/article/the-british-governments-disa...

More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.

Post reply on HN