Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

481–490 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#481

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

That’s one of the reasons I always worry about high level employees who “still write code”. It’s just too much opportunity for them to make bad choices and many ICs are afraid to speak up to avoid it.

Same goes for some “10x developers” who are fast because the rules don’t apply to them. Meanwhile the rules slow everyone else down (yea big surprise he is faster). And everyone else has to clean up after these guys when they get sloppy.

Re: U.S. national-security leaders included me in a group chat

#482
What are the odds that Goldberg was included in the Signal chat intentionally by a whistleblower? I.e., someone who had reservations about what was about to take place (either the bombing action itself, or the intentional avoidance of government recordkeeping) and so included him as a witness?

Re: U.S. national-security leaders included me in a group chat

#483
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

I believe they meant to contact Jamieson Greer (JG), and maybe Waltz had both of them listed by initials? That's the leading theory.

[deleted]

Re: U.S. national-security leaders included me in a group chat

#484

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

The most likely reason is convenience, not escaping record keeping.

It can certainly be both. Just like they have already tried to shield DOGE from FOIA transparency requests.

Re: U.S. national-security leaders included me in a group chat

#485

Earlier quoted context omitted.

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself? Because these rules and policies are for people that are judged to need them by the person with the authority and responsibility for making the decision. Policies like these always have a cost and (hopefully) a benefit. Presumably this lead dev judged…

As long as authority and responsibility land on the same person, I see no problem with it. If, however, a junior develop is responsible for making a change, but has no authority to make the change, then there is a problem.

Code reviews are often used as an excuse to disclaim responsibility when problems occur, and as a way to deny authority under the guise of mandatory review requests. They do also have many benefits for e.g. continuity of service, but those two drawbacks remain relevant today.

Re: U.S. national-security leaders included me in a group chat

#486
post #77

If anything, I'm a bit surprised that Jeff Goldberg burned this source. If anything, I'd suspect that he'd keep the channel open as long as he could. Or, he's got other channels that work better. All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing. Like, very clearly, these people are going to get…

I thought that at first, but the group was clearly temporary, intended for this particular military action. There was likely little value to staying, and as other comments note, a nonzero risk of (likely unsuccessful) prosecution.

Re: U.S. national-security leaders included me in a group chat

#487

Earlier quoted context omitted.

Why are you specifically calling out you are not suggesting punishment nor prosecution?

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

Why would we expect Patel and Bongino to investigate anything here? They were put there to investigate anyone else other than the current administration.

Why would any FBI agent take a risk on investigating anyone potentially in current or future administrations? They'll get fired later when the political winds change.

Re: U.S. national-security leaders included me in a group chat

#488

Earlier quoted context omitted.

Why are you specifically calling out you are not suggesting punishment nor prosecution?

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

[flagged]

Re: U.S. national-security leaders included me in a group chat

#489
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

It may or may not be bad security (I lean toward a rather than b), but it definitely violates record-keeping requirements. Deliberations of public officials might need to be classified, but they should definitely be recorded. If you're using disappearing messages to auto-erase records of conversations, it's a kind of fraud upon the public.

Re: U.S. national-security leaders included me in a group chat

#490
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

Using Signal is very very very intentional. They may have fat fingered an invite but that does not excuse the whole skirting-all-natsec-protocols.
Post reply on HN