Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

501–510 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#501

Earlier quoted context omitted.

I happen to know first hand that the thread is not going quite to dang's liking at the moment. I'm hoping it improves, but people are having a hard time sticking to the technical and security aspects.

[flagged]

The opposite. I had him frontpage it to give it a chance.

Re: U.S. national-security leaders included me in a group chat

#502
post #444
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

I don't use Signal, and am unfamiliar with the UI/UX. However, it seems more plausible to me that Jeffrey Goldberg is in someone's contact list from previous on-purpose leaks (to control narrative, etc, typical "anonymous sources say" stuff) - and was accidentally added to this group.

It could happen on Whatsapp. I've seen a lot of groups where everybody is an admin.

Re: U.S. national-security leaders included me in a group chat

#503

Earlier quoted context omitted.

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

[flagged]

The fact that nobody on the thread spoke up and said "we shouldn't be talking about this on Signal" worries me greatly.

One possible explanation is that it happens all the time.

Re: U.S. national-security leaders included me in a group chat

#504
post #445

Earlier quoted context omitted.

He knew the system well and seemed to do enough local testing to avoid major breakage but still. Why have a bunch of rules and policies that you do not follow yourself? Because these rules and policies are for people that are judged to need them by the person with the authority and responsibility for making the decision. Policies like these always have a cost and (hopefully) a benefit. Presumably this lead dev judged…

One of the main purposes of code review is to ensure that your code is understandable to other people. Good lead developers understand this. Bad ones find a way to push through their changes without review or get them rubber stamped, in my experience. Then you end up with big parts of the codebase that only the lead dev can work in productively.

the whole team has to review every single line of code to make sure everyone understands it? or is there a threshold like “we good if 7 out of 79 understand it?” almost 3 decades hacking and have never heard anyone saying that purpose of the code review (in the top 987 reasons teams may institute it) is to ensure your code is understandable by other people… wild :)

Re: U.S. national-security leaders included me in a group chat

#505

Earlier quoted context omitted.

I happen to know first hand that the thread is not going quite to dang's liking at the moment. I'm hoping it improves, but people are having a hard time sticking to the technical and security aspects.

[flagged]

It's a day old submission with a lot of flame war material going on. That it's still on the front page suggests it's being propped up.

Re: U.S. national-security leaders included me in a group chat

#506

Earlier quoted context omitted.

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

[flagged]

It is significantly more severe than the diplomatic cables and the other leaks that Assange and Manning each did a decade for.

Re: U.S. national-security leaders included me in a group chat

#507
post #387
post #77

If anything, I'm a bit surprised that Jeff Goldberg burned this source. If anything, I'd suspect that he'd keep the channel open as long as he could. Or, he's got other channels that work better. All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing. Like, very clearly, these people are going to get…

"If anything, I'd suspect that he'd keep the channel open as long as he could." The real story is that he was added to the channel, so it doesn't surprise me that he didn't try to lurk indefinitely. I'm guessing these things are also ad-hoc, so perhaps the well was already dry after the attack? But this is some truly amateur-hour shit. I've seen better communications discipline from volunteer open source projects tha…

> I've seen better communications discipline from volunteer open source projects than this.

Because those people are likely competent. The problem with hiring mostly yes-men/women is competence is secondary.

Re: U.S. national-security leaders included me in a group chat

#508
post #455
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

I'd go with b: They've been talking for a while about finding information leaks, and the messages themselves seem a bit staged. They probably did it intentionally with different people, with slightly different wording, and because of which version got published they just identified a leak.

A barium meal is for finding leakers within an organization. IF you send material to a journalist, unsolicited, and they report on it, what exactly have you established?

Like, do you think they did the same thing with multiple journalists in an attempt to see who would publish and who would keep their mouths shut?

Bear in mind, when you join a Signal group you don't see the conversation history from before you arrived, only the live updates that take place during the time you're a member. Also, anyone in the group can view the list of group members and receives notifications about people being added to/removed from/leaving the group.

Re: U.S. national-security leaders included me in a group chat

#509
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

>It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes.

It was Mike Waltz who invited Jeff Goldberg to connect on Signal. It seems inordinately unlikely that he would have been uninvolved if it was an intentional leak.

Re: U.S. national-security leaders included me in a group chat

#510
post #480

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

At least here in the UK our politicians delete all their messages on WhatsApp https://www.politico.eu/article/the-british-governments-disa... More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.

Are you able to share any of those security controls? How do you stop presumably well-intended Signal app users from conferencing? Are you talking about cellular signal blocking, or are you talking about avoiding public networks entirely in favor of Sensitive Compartmented Information Facilities (SCIFs)?
Post reply on HN