Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

631–640 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#631
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

This leak proves that the trust in Signal is not justified. Yes, their crypto didn’t fail, but the system did. If you’re having a classified conversation electronically, you really want the system to check that the participants are supposed to be privy to this information. If some rando is in the chat, there should be a big, loud “some rando is in the chat, don’t share any secrets” alert.

Obviously, Signal is not meant for this sort of thing, so it has no reason for such a feature. It’s not a failing of Signal, but it’s not fit for this purpose.

Re: U.S. national-security leaders included me in a group chat

#632

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

> if this practice were to continue

My prediction is, given the way the narrative is shifting to digging in their heels and insisting they did nothing wrong, the lesson they are learning from all this is that they should have hid their activity better. Nothing will happen to them, they will continue with impunity, and they'll just be more careful about not inviting outsiders. I suspect this isn't the last leaked top-secret group chat we'll see.

Re: U.S. national-security leaders included me in a group chat

#633

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

Heck, one of my co-workers at a FAANG freaked out when he realized that he had used his personal phone to take a picture of a meeting blackboard instead of his corp phone. He spent the afternoon trying to figure out how to scrub the photo.

There is a great thread on r/army where people are listing out all the Military careers destroyed by minor mistakes that pale in comparison to this.

Re: U.S. national-security leaders included me in a group chat

#634
post #432

Without commenting on the (important) political or reputational considerations here, I want to talk a bit about the operational risk presented by this practice. There is a somewhat sizable "So what? Signal is e2e encrypted. Nothing bad happened and you're all overreacting." narrative floating around. (not so much in this thread, but in the general discourse) If this operation was planned in Signal, then so were count…

I agree with all of this, my only quibble is that I would bet there have already been costs associated with this idiocy. Hostile powers knew going in that this would be an incompetently run administration and I'm sure were looking at gaining access to personal devices out of the gate. It's possible that a great many highly sensitive conversations have already been read by adversaries. I also expect that similar slopp…

I suspect we won't know the true damage until all these people are gone, kind of like how Apollo 13 didn't know the true damage to the service module until they jettisoned it.

Re: U.S. national-security leaders included me in a group chat

#635

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

Was any classified information shared on Signal?

[flagged]

Re: U.S. national-security leaders included me in a group chat

#636

Earlier quoted context omitted.

“People have gone to jail for 1/100th of what – even 1/1,000th of what Hillary Clinton did.” -Hegseth “How is it Hillary Clinton can delete 33,000 government emails on a private server yet President Trump gets indicted for having documents he could declassify?” - Waltz “Nobody is above the law. Not even Hillary Clinton – even though she thinks she is,” -Rubio

I always ask MAGA people why Clinton wasn't prosecuted by the Trump administration over this, and have never received a clear reply, if I got a reply at all.

[deleted]

Re: U.S. national-security leaders included me in a group chat

#637

I began my career in a classified environment working on government satellite programs. In my first week on the job, I was told, explicitly, that if I shared Classified or Controlled Unclassified information over unapproved channels, I would be reprimanded—likely fired, or less likely, prosecuted. It was also made clear that safeguarding the nation's secrets from the carelessness of others was my responsibility, too.…

I have read that one of them (thanks to sibling commenter, yes, Witkoff) was traveling in Russia while on this group chat, and that the chat disclosed the identity of an intelligence officer.

Re: U.S. national-security leaders included me in a group chat

#640

Earlier quoted context omitted.

Using Signal in this case is wrong and foolish full stop, and the extremely likely reason they did so is so they could escape standard government record keeping compliance (NARA). To start with, classified information is ONLY supposed to viewed in a SCIF. Secondly, it should never be loaded onto private devices. The private phones of national security leadership would be prime targets for every hostile intelligence a…

The most likely reason is convenience, not escaping record keeping.

Avoiding FOIA requests is the reason every secretary of state since Collin Powell uses private email to conduct business.
Post reply on HN