Live data from Hacker News

U.S. national-security leaders included me in a group chat

theatlantic.com

701–710 of 1001 posts

Re: U.S. national-security leaders included me in a group chat

#701

Earlier quoted context omitted.

Yes, this was one of the main points on infosec Mastodon today. While everyone is aware enough to be concerned with encryption over the wire, it's the endpoints that matter. Personal Android devices capable of running Signal are going to be some of the easiest to compromise for a sufficiently motivated attacker. I've seen n00b cops do it for drug gangs here. There's no question that Russia, China, et al. can do it ju…

Exactly. Signal on Android uses your phone PIN, for some insane reason.

It can be set differently.

Re: U.S. national-security leaders included me in a group chat

#702

Earlier quoted context omitted.

In the Trump Whitehouse, not only do you believe the rules don't apply to you, but actually the rules don't apply to you.

Use Signal, an encrypted platform from the CIA with a charismatic public persona: the horror! Use an unencrypted email server in a closet for years: that's nothing.

Years of investigations and congressional hearings is nothing?

Re: U.S. national-security leaders included me in a group chat

#703

Earlier quoted context omitted.

Why shouldn't punishment or prosecution be suggested. I've worked with classified information, and I would have been held accountable for my actions, why shouldn't they? I'm tired of this Too Important To Have Consequences business. It defeats the whole purpose of having qualifications, and security, and rules of any kind.

Do you honestly think that (a) Trump's Justice Department would prosecute any of these offenses, and (b) even if so, that Trump wouldn't just pardon anyone involved?

Yeah, there's no way anything is going to happen to these guys. I'm saying that's a great suggestion, and one that everyone should be able to agree on.

But yeah, I agree with you. Nothing is going to happen. Just like no one at the top has been held to any kind of a standard at all since maybe Nixon. Who knows, if he had just stuck it out maybe he would have gotten off too.

Re: U.S. national-security leaders included me in a group chat

#704
post #481

This hypocrisy reminds me of one of my former lead developers. He required everyone on the team to go through multi-person code reviews and pass an extensive CI suite before merging changes into our mainline. But him? Half that time he'd approve his own changes without review, the other half he would force-push and bypass the CI system entirely. He knew the system well and seemed to do enough local testing to avoid m…

That’s one of the reasons I always worry about high level employees who “still write code”. It’s just too much opportunity for them to make bad choices and many ICs are afraid to speak up to avoid it. Same goes for some “10x developers” who are fast because the rules don’t apply to them. Meanwhile the rules slow everyone else down (yea big surprise he is faster). And everyone else has to clean up after these guys whe…

My personal pet peeve is network admins that have unfettered Internet access from their workstation IP, but everyone else has to traverse half a dozen “security” appliances that break developer CLI tools and slow down everything else.

Re: U.S. national-security leaders included me in a group chat

#705
post #390

In my opinion there are at least two ways to interpret this: a) It's an unintentional opsec failure. Perhaps there was an address book collision with another intended user. Perhaps it was fat-fingered. This seems likely. b) It was an intentional leak. Perhaps overtly, perhaps covertly, by one or more of the channel members for unknown purposes. This seems less likely as there are better ways to leak with less blowbac…

None of your conjecture matters: it is blatantly illegal to use commercial apps to discuss classified information.

You can debate the seriousness of this sometimes. When it comes to impending military action though, revealing when and where US personnel will be conducting an operation in the future, there really is no debate. This is gravely serious.

Re: U.S. national-security leaders included me in a group chat

#706

Earlier quoted context omitted.

Why shouldn't punishment or prosecution be suggested. I've worked with classified information, and I would have been held accountable for my actions, why shouldn't they? I'm tired of this Too Important To Have Consequences business. It defeats the whole purpose of having qualifications, and security, and rules of any kind.

But have you considered that they are Billionaires and therefore can do whatever they want?

Like my dad always said, "money talks and shit walks".

Re: U.S. national-security leaders included me in a group chat

#707
post #141

Setting aside the obvious shock of the actual subject, I'm going to try the herculean task of bringing this back to being a HN-related topic... My guess is that there is someone named Jeffrey Goldberg in the NatSec team (or high up, it seems like a common combination of first and last name at least), and likely that they meant to add him, rather than the EDITOR IN CHIEF of the Atlantic of all people. Could this be a…

This sounds less like a Signal problem than an information organization problem. Signal can only show what's in its datastore (your contact list). I just checked on Android - if you try to add someone to a group chat, it shows their name and profile pic. One potential Signal-side wrinkle is that it allows you to add people to a group chat who are in another chat you're in, but who aren't in your contacts list. There…

> This sounds less like a Signal problem than an information organization problem. Signal can only show what's in its datastore (your contact list).

Signal's insistence on punting on the trust/identity problem is a Signal problem IMO, particularly when its advocates make such a fuss (when it suits them) about being a properly end-to-end cryptosystem and not just a toolbox of algorithms. Most of the systems it's competing with make at least some attempt at providing a chain of trust so you don't have to individually verify everyone you want to talk to.

Re: U.S. national-security leaders included me in a group chat

#709
post #664

Earlier quoted context omitted.

It's a pretty big false dichotomy to present "people directly opposed to their policy platforms " as the sole alternative to people "picked on the premise of just one qualification: they'd be Yes Man/Woman".

Yes, I was using a false dichotomy to highlight the absurdity of the statement. Every President surrounds themselves with people who are aligned with their policy platforms . For some reason, Trump is the one President where suddenly it's an issue.

> For some reason, Trump is the one President where suddenly it's an issue.

Because Trump is the first president whose hirelings

1. Used Signal to violate laws requiring retention of communication 2. Got caught by incompetently inviting a journalist to their high security chat?

Re: U.S. national-security leaders included me in a group chat

#710
The funny thing is I heard the head of the CIA testify today and say they use Signal because it is E2E encrypted. Are they that confident that no other country like China can crack those? I sure hope our intelligence officers are using better systems than effing Signal
Post reply on HN