Earlier quoted context omitted.
At least here in the UK our politicians delete all their messages on WhatsApp https://www.politico.eu/article/the-british-governments-disa... More seriously, having worked in an undisclosed defence company, we were told that we would be prosecuted if we did this. There were many many security controls in place that prevented this from happening on top of the threat.
Are you able to share any of those security controls? How do you stop presumably well-intended Signal app users from conferencing? Are you talking about cellular signal blocking, or are you talking about avoiding public networks entirely in favor of Sensitive Compartmented Information Facilities (SCIFs)?
U.S. national-security leaders included me in a group chat
511–520 of 1001 posts
Re: U.S. national-security leaders included me in a group chat
#512In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
FWIW, Signal has been the de facto semi-informal chat app throughout the US intelligence community for many years. I first started using Signal several years ago because I needed it to chat with people in DC. European governments do the same but with WhatsApp.
Re: U.S. national-security leaders included me in a group chat
#513There’s a vulnerability in Signal where you can set up linked devices that replicate your signal messages. You can do this by just scanning a QRcode. This is known to be used by Russian hackers.
What are the chances the Russians duped Witkoff into scanning a QR code while he was in Moscow?
Re: U.S. national-security leaders included me in a group chat
#514Earlier quoted context omitted.
Sure, those are the reasons for, but would be interesting for you to address the salient point of not trusting those government systems. I'm sure you can make the counterargument.
I mean, the conversation included references to materials sent on 'the high side' (classified-material email systems). If they consider those systems secure, what's the point of using Signal instead?
Re: U.S. national-security leaders included me in a group chat
#515Earlier quoted context omitted.
Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…
[flagged]
This is absolutely false, or as the kids call it, "misinformation".
A 3 second Google search confirms:
100 emails contained information that should have been deemed classified at the time they were sent, including 65 emails deemed "Secret" and 22 deemed "Top Secret". An additional 2,093 emails were retroactively designated confidential by the State Department.
The whole issue with her emails is she purposely never labeled anything so as to have plausible deniability.
Re: U.S. national-security leaders included me in a group chat
#516Earlier quoted context omitted.
One of the main purposes of code review is to ensure that your code is understandable to other people. Good lead developers understand this. Bad ones find a way to push through their changes without review or get them rubber stamped, in my experience. Then you end up with big parts of the codebase that only the lead dev can work in productively.
the whole team has to review every single line of code to make sure everyone understands it? or is there a threshold like “we good if 7 out of 79 understand it?” almost 3 decades hacking and have never heard anyone saying that purpose of the code review (in the top 987 reasons teams may institute it) is to ensure your code is understandable by other people… wild :)
https://www.browserstack.com/guide/code-review-benefits
> Code Review enhances the maintainability of the Code. It ensures that multiple people are aware about the code logic and functioning, which makes it easy to maintain in case the original author of the code is unavailable.
The fact that you've been "hacking" for three decades and never considered this isn't something to wear as a badge of honor. As for your absurd straw man about everyone on the team reviewing every line of code, I've never seen one organization that does that.
Re: U.S. national-security leaders included me in a group chat
#517Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…
Can users in a group add/invite others in? My firth though was someone doing it on the sly, to leak deliberately.
Re: U.S. national-security leaders included me in a group chat
#518In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
FWIW, Signal has been the de facto semi-informal chat app throughout the US intelligence community for many years. I first started using Signal several years ago because I needed it to chat with people in DC. European governments do the same but with WhatsApp.
Re: U.S. national-security leaders included me in a group chat
#519Earlier quoted context omitted.
Why are you specifically calling out you are not suggesting punishment nor prosecution?
Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…
"Whoever, being entrusted with or having lawful possession or control of any document, writing ... through gross negligence permits the same to be removed from its proper place of custody or delivered to anyone in violation of his trust ... and fails to make prompt report of such loss, theft, abstraction, or destruction to his superior officer—
Shall be fined under this title or imprisoned not more than ten years, or both."
We can only guess about the "prompt reporting of the issue", but from what I've seen and heard I'm willing to put money on the fact that, no, this was not reported.
Re: U.S. national-security leaders included me in a group chat
#520In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…
They replace “ideologically compromised SCIFs” with…… 18 separate iOS devices that I’m sure are on 18 separate OS/app versions and device postures and…
Got news for you - want to compromise e2e encryption and Signal? You do it via what they did. So no, they are not correct.