Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

511–520 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#511
post #480

Earlier quoted context omitted.

At least here in the UK our politicians delete all their messages on WhatsApp https://www.politico.eu/article/the-british-governments-disa... More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.

Are you able to share any of those security controls? How do you stop presumably well-intended Signal app users from conferencing? Are you talking about cellular signal blocking, or are you talking about avoiding public networks entirely in favor of Sensitive Compartmented Information Facilities (SCIFs)?

Many layers of physical controls and regular audits mostly.

Re: U.S. national-security leaders included me in a group chat

#512
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

FWIW, Signal has been the de facto semi-informal chat app throughout the US intelligence community for many years. I first started using Signal several years ago because I needed it to chat with people in DC. European governments do the same but with WhatsApp.

stop lying

Re: U.S. national-security leaders included me in a group chat

#513
Steve Witkoff was on the chat while he was in Russia.

There’s a vulnerability in Signal where you can set up linked devices that replicate your signal messages. You can do this by just scanning a QRcode. This is known to be used by Russian hackers.

What are the chances the Russians duped Witkoff into scanning a QR code while he was in Moscow?

Re: U.S. national-security leaders included me in a group chat

#514
post #424

Earlier quoted context omitted.

Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.

I mean, the conversation included references to materials sent on 'the high side' (classified-material email systems). If they consider those systems secure, what's the point of using Signal instead?

I don't think it was a particularly good tactic, but if there was some motivation, it may have been more about political sabotage than foreign adversaries. I think that is the more interesting conversation, personally. What do you do if your political (domestic) antagonists control your comms? This question applies to all sides politically. Signal itself is promoted for "activist" use cases to protect comms from domestic antagonists. I'm presenting a similar dilemma. If one part of the government, (e.g., the military) controls secure comms, then another (e.g., the political) may have no choice but to opt-out. This problem is maybe better seen in the context of another country. It may be "too close" for us to see it clearly in the U.S. Other countries face this problem all the time, and Signal is used for the same reasons. I find it an interesting security problem.

Re: U.S. national-security leaders included me in a group chat

#515

Earlier quoted context omitted.

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

[flagged]

> There was no classified information on Clinton's server.

This is absolutely false, or as the kids call it, "misinformation".

A 3 second Google search confirms:

100 emails contained information that should have been deemed classified at the time they were sent, including 65 emails deemed "Secret" and 22 deemed "Top Secret". An additional 2,093 emails were retroactively designated confidential by the State Department.

The whole issue with her emails is she purposely never labeled anything so as to have plausible deniability.

Re: U.S. national-security leaders included me in a group chat

#516
post #445

Earlier quoted context omitted.

One of the main purposes of code review is to ensure that your code is understandable to other people. Good lead developers understand this. Bad ones find a way to push through their changes without review or get them rubber stamped, in my experience. Then you end up with big parts of the codebase that only the lead dev can work in productively.

the whole team has to review every single line of code to make sure everyone understands it? or is there a threshold like “we good if 7 out of 79 understand it?” almost 3 decades hacking and have never heard anyone saying that purpose of the code review (in the top 987 reasons teams may institute it) is to ensure your code is understandable by other people… wild :)

This page is literally the second result when you Google "benefits of code review":

https://www.browserstack.com/guide/code-review-benefits

> Code Review enhances the maintainability of the Code. It ensures that multiple people are aware about the code logic and functioning, which makes it easy to maintain in case the original author of the code is unavailable.

The fact that you've been "hacking" for three decades and never considered this isn't something to wear as a badge of honor. As for your absurd straw man about everyone on the team reviewing every line of code, I've never seen one organization that does that.

Re: U.S. national-security leaders included me in a group chat

#517
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

Can users in a group add/invite others in? My firth though was someone doing it on the sly, to leak deliberately.

If they have admin privileges. The person who creates a group has them by default, and can grant them to anyone else, admins can add, remove, and grant or revoke admin privileges and set group name/description parameters, and disappearing message configuration. Yes, you could have a group where the founder revokes admin privileges for themselves and then nobody can make changes to the group (although individual members can leave and delete the history on their own devices). Signal users can also delete their own messages.

Re: U.S. national-security leaders included me in a group chat

#518
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

FWIW, Signal has been the de facto semi-informal chat app throughout the US intelligence community for many years. I first started using Signal several years ago because I needed it to chat with people in DC. European governments do the same but with WhatsApp.

I've had a similar experience.

Re: U.S. national-security leaders included me in a group chat

#519

Earlier quoted context omitted.

Why are you specifically calling out you are not suggesting punishment nor prosecution?

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

18 USC 793(f) seems to apply here:

"Whoever, being entrusted with or having lawful possession or control of any document, writing ... through gross negligence permits the same to be removed from its proper place of custody or delivered to anyone in violation of his trust ... and fails to make prompt report of such loss, theft, abstraction, or destruction to his superior officer—

Shall be fined under this title or imprisoned not more than ten years, or both."

We can only guess about the "prompt reporting of the issue", but from what I've seen and heard I'm willing to put money on the fact that, no, this was not reported.

Re: U.S. national-security leaders included me in a group chat

#520
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

For a tech forum, this take is pretty darn close to once again giving bad/dumb actors benefit of the doubt backed up by zero.zero% technical logic by claiming they’re actually playing 4D OPSEC chess.

They replace “ideologically compromised SCIFs” with…… 18 separate iOS devices that I’m sure are on 18 separate OS/app versions and device postures and…

Got news for you - want to compromise e2e encryption and Signal? You do it via what they did. So no, they are not correct.

Post reply on HN