Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

581–590 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#581

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

> Does Chinese intelligence know?

How likely is it that all 18 of those people were accessing from mobile operating systems with no known working exploit chain? I would say pretty unlikely.

Re: U.S. national-security leaders included me in a group chat

#582
post #422

Earlier quoted context omitted.

I think there is likely a difference between what the FBI does to someone they want info pretty badly from vs what does to someone that they have determined is a keystone to one of their national adversaries. If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you.

> If they did have some kind of collection capability around Signal, they likely would not have risked burning it on you. I've always thought the exact same thing. The harm was ~800m USD to a private company. Sounds big, but it's nothing compared to actual state sponsored anything. Just to add some more (possibly useful) context from the encounter.... The FBI was not able to unlock many LUKS secured devices - at all.…

I'm a nobody, but I imagine the feds or spooks would never use anything like that on someone they have physical access on. If the target is in their jurisdiction or a blacksite and it's that important, a lead pipe is easier.

IF they can decrypt stuff, they'll only use it when it's has an actual benefit beyond a conviction and the keys are truly inaccessible. (e.g., person is dead, the keys are in an enemy state HSM, etc.)

Re: U.S. national-security leaders included me in a group chat

#583

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

The problem is that most of those 18 people are just random folks picked on the premise of just one qualification: THey'd be Yes Man/Woman!! They aren't career professionals. I believe that explains the mess they've created and their incompetent approach to their duties.

It's still not too late to impeach that entire shack of clowns.

Re: U.S. national-security leaders included me in a group chat

#584
post #77

If anything, I'm a bit surprised that Jeff Goldberg burned this source. If anything, I'd suspect that he'd keep the channel open as long as he could. Or, he's got other channels that work better. All the same, I mean, wow. These guys are just morons here, there's really no other way around it. I'm trying to think of a charitable way to spin this and I've got nothing. Like, very clearly, these people are going to get…

This is the type of thing that can get you on jail or even (quietly) killed during a normal US administration. I'm not surprised Goldberg GTFO intermediately.

Re: U.S. national-security leaders included me in a group chat

#585

Earlier quoted context omitted.

Why are you specifically calling out you are not suggesting punishment nor prosecution?

Because I don't know whether either of those are appropriate. There aren't many comparable breaches to this one. The closest in modern times may be Hillary Clinton's email server being used for government business. In that case, the FBI investigated and declined to bring charges, under the expectation that a jury would be unlikely to render a guilty verdict. Okay, fine. But the FBI investigated and laid out the facts…

> The closest in modern times may be Hillary Clinton's email server being used for government business.

Wait, there's more!! https://www.pbs.org/newshour/politics/cummings-jared-kushner...

Re: U.S. national-security leaders included me in a group chat

#586

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

CISA explicitly promoted Signal for use by top level government officials. The fact that an outsider was invited to a conversation they didn't belong in is troubling, but basically nothing else about this seems to be outside of recommended policy.

The administration is also claiming that there was no confidential information in the conversation, which I think is certainly debatable, but the rest of the story seems overblown to me.

Re: U.S. national-security leaders included me in a group chat

#587
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

CISA explicitly promoted the use of signal by all top government officials.

Re: U.S. national-security leaders included me in a group chat

#588

And these guys have been in power for only a few months, they're still finding out about their new tools. What will happen in the next 4 years? will they even leave power peacefully?

Trump has already been president and already demonstrated to us that he will not leave power peacefully. He's openly discussing serving a third term. I think it's highly unlikely that the transfer of power will happen peacefully unless 1) he dies in office (of natural causes) Or 2) the republicans win in 2028 and a different republican president is sworn in.

The real test will be the midterms.

Re: U.S. national-security leaders included me in a group chat

#589
post #461

Earlier quoted context omitted.

No accountability or consequences for anyone is the motto of the Trump administration (or indeed Trump himself, who is a convicted felon).

First felon I know that has had no issues getting a job or getting a place to live. It's amazing how being a felon makes life so much more difficult for normies, yet actually improved his stature. It's embarrassing no matter which angle it is viewed.

It's all about the $$$.

Re: U.S. national-security leaders included me in a group chat

#590

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

CISA explicitly promoted the use of signal by all top government officials.

Where? They recommended it for members of the public as part of their general recommendation for end-to-end encryption but that’s a very different scenario than government employees who have official systems.
Post reply on HN