Live data from Hacker News

Iran-linked hackers breach FBI director's personal email

reuters.com

401–410 of 591 posts

Re: Iran-linked hackers breach FBI director's personal email

#401

Earlier quoted context omitted.

Read the article he wasn't the director of the FBI: "The stolen emails appear to date from around 2011 to 2022"

Are you suggesting that he was targeted before he became the director of the FBI? That seems unlikely. Once he became an obvious target surely the FBI should have secured his past, present and future communications. But I have no idea what protocols there are for such things, I'm just going off common sense, a notoriously sketchy starting point in the crazy world of the current US administration.

He was well known in the first Trump admin.

Re: Iran-linked hackers breach FBI director's personal email

#402
post #188

Earlier quoted context omitted.

He's had over a year to enable it.

woah but even I haven't heard about that gmail feature...? maybe google doesn't advertise about this much?

If only the Director of the FBI had access to some sort of investigative team, maybe more than one, maybe even enough that they use a collective term for it, something like, I don't know: bureau?

Re: Iran-linked hackers breach FBI director's personal email

#403
post #53

Earlier quoted context omitted.

> his personal email should be pretty uninteresting except for stuff like HIPAA, amazon purchases, communications with friends / family. (good for HUMINT) But other than that, there shouldn't be anything in there which should make the news. It'll be interesting to see whether or not that bears out. Aren't these the same people who apparently used Signal with a journalist in the chat, and had military conversations in…

> Aren't these the same people who apparently used Signal with a journalist in the chat, and had military conversations in that very chat? Signal is one of the most secure communication platforms out there, but it is obviously not immune to human error or social engineering.

> Signal is one of the most secure communication platforms out there

That might be true amongst the communication platforms available for the average Joe. It is definietly not the most secure communication platform available for someone high ranking in the USA government.

> it is obviously not immune to human error or social engineering

Nothing is immune. But there are systems more and systems less prone to these issues.

Re: Iran-linked hackers breach FBI director's personal email

#404

Earlier quoted context omitted.

I'd rather he worry about securing government secrets, not spend one second worrying about "personal photographs of Patel sniffing and smoking cigars, riding in an antique convertible, and making a face while taking a picture of himself in the mirror with a large bottle of rum".

Obviously government secrets need to be properly secured, but the personal info/photos of a top official can often be used for blackmail or for determining close friends that could be used to compromise Patel.

There's so much speculation about how this hack could conceivably be damaging, but so little evidence that it actually contained anything damaging.

Re: Iran-linked hackers breach FBI director's personal email

#406
post #188

Earlier quoted context omitted.

He's had over a year to enable it.

woah but even I haven't heard about that gmail feature...? maybe google doesn't advertise about this much?

"Even you"?

Are you someone who would be inclined to look into something like that?

Re: Iran-linked hackers breach FBI director's personal email

#407

Earlier quoted context omitted.

Obviously government secrets need to be properly secured, but the personal info/photos of a top official can often be used for blackmail or for determining close friends that could be used to compromise Patel.

There's so much speculation about how this hack could conceivably be damaging, but so little evidence that it actually contained anything damaging.

Security through luck?

The reality is that officials are targetted by various states looking to get some leverage, so not properly securing an email account is a serious failing unless it's part of a wider honeypot scheme. Personally, I'm not convinced that the current U.S. administration is competent enough to plan ahead and implement honeypots.

Re: Iran-linked hackers breach FBI director's personal email

#408
I'd feel obliged to add some "but, her emails..." reference.

But it feels million years away.

It's interesting to wonder how you get out of a spiral of incompetence and border-line (to be polite) corrumption at the highest level.

Putting those people in charge was quick ; sure, a future administration could put them out quickly enough ; but how long will there be decently skilled people willing to take those positions ? How long until the only ones who want to put their toes in the swamp are those who really enjoy the mud ?

Put differently: can a liberal democracy organize a "just" version of a purge ?

Re: Iran-linked hackers breach FBI director's personal email

#409
post #188

Earlier quoted context omitted.

He's had over a year to enable it.

woah but even I haven't heard about that gmail feature...? maybe google doesn't advertise about this much?

They absolutely advertised it when it was released and every journalist knows about it.

Kashmir Patel went out of his way to bypass security protocols for onboarding his political hires (for the US’s premiere domestic intelligence service!). If he wanted to be secure, all he had to do was not get in the way of the FBI’s natural processes.

Also, this wouldn’t have happened if POTUS had hired someone with relevant FBI experience instead of a political hack.

Re: Iran-linked hackers breach FBI director's personal email

#410
post #188

Earlier quoted context omitted.

He's had over a year to enable it.

Why would he, when he wasn't director of the FBI then?

You’re right. He was merely [checks notes]:

  - Chief of Staff to the United States Secretary of Defense (2020-2021)
  - Principal Deputy Director of National Intelligence (2020)
Not a big deal. No need for OpSec in those positions.
Post reply on HN