Live data from Hacker News

Protecting Against Leakers

schneier.com

31–40 of 56 posts

Re: Protecting Against Leakers

#31

If you are worried about leakers, you probably are doing somehing "bad" and you are aware of it. Why would anybody even consider giving such tips to `people which can be summed up as evil' is beyond me.

Consider sports teams. They have strategies and plans which they don't want leaked to their opponents. You'd be hard pressed to call them evil.

yes you are right, I have unconsiuosly narrowed my thinking here (considered only Prism related situations).

Re: Protecting Against Leakers

#33
post #22

Earlier quoted context omitted.

Your comment implies that whistle-blowers are a sub-category of traitors. Is that intentional?

Is that what it implies? I would have missed that and read this as 'whistleblowers versus any kind of traitor'.

Your interpretation is what I meant.

Re: Protecting Against Leakers

#34

I'm not happy hearing the unqualified statement "we need secrecy" being banded around without any opposition.

How about replacing it with 'privacy'? We all need privacy and politicians are not an exception.

Re: Protecting Against Leakers

#35
post #19

Earlier quoted context omitted.

DBA's and system administrators can usually use their privileges to install tools or change settings in such a way that they gain access to the raw data. Whether it goes undetected or not is another matter. In the end someone or some process has access and a sysadmin / DBA could pretend to be that someone or that process. Once you have physical access to a box it is game-over, the only thing that might still trip you…

You can set things up so there's no way for any single to bypass logs or other audit controls. A trivial way is to have all logins go via an administration host which logs separately , and never give admin rights on that machine to people with admin on the protected systems.

[deleted]

Re: Protecting Against Leakers

#36
post #33

Earlier quoted context omitted.

Is that what it implies? I would have missed that and read this as 'whistleblowers versus any kind of traitor'.

Your interpretation is what I meant.

I'm sorry about misinterpreting, it's just how I interpreted the comment. My bad.

Re: Protecting Against Leakers

#37
post #14

Part of Assange's philosophy is that secretive unjust organizations will operate less efficiently and become less effective as they lock down their internal flow of information in response to leaks. Looks like things are going according to plan.

From Julian Assange's old blog:

http://cryptome.org/0002/ja-conspiracies.pdf

http://web.archive.org/web/20071020051936/http://iq.org/#The...

----

Sun 31 Dec 2006 : The non linear effects of leaks on unjust systems of governance

You may want to read The Road to Hanoi or Conspiracy as Governance ; an obscure motivational document, almost useless in light of its decontextualization and perhaps even then. But if you read this latter document while thinking about how different structures of power are differentially affected by leaks (the defection of the inner to the outer) its motivations may become clearer.

The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive "secrecy tax") and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption.

Hence in a world where leaking is easy, secretive or unjust systems are nonlinearly hit relative to open, just systems. Since unjust systems, by their nature induce opponents, and in many places barely have the upper hand, mass leaking leaves them exquisitely vulnerable to those who seek to replace them with more open forms of governance.

Only revealed injustice can be answered; for man to do anything intelligent he has to know what's actually going on.

Re: Protecting Against Leakers

#38
post #27
post #7

> More surprising than Snowden's ability to get away with taking the information he downloaded is that there haven't been dozens more like him. Is an assumption on Schneier's part. For all we know there were dozens or more. They may not have released the data or they may have sold it to some foreign agency instead.

... or they may have sold it to some foreign agency instead. Don't forget corporations and individuals. And of course blackmail. That could be very profitable, specially against powerful people, politicians...

Front-running is the obvious (and most profitable) application.

Re: Protecting Against Leakers

#39
>Think of an employee as operating within a sphere of trust -- a set of assets and functions he or she has access to. Organizations act in their best interest by making that sphere as small as possible. The idea is that if someone turns out to be untrustworthy, he or she can only do so much damage. This is where the NSA failed with Snowden.

And if you read easily between the lines, this is where the NSA failed us as well.

Snowden's sphere of access was very large. He broke org procedure for the good of all Americans and net users on the planet. What is implied is that existing analysts in like positions have similar access, and can break org procedures for nefarious purposes (indeed, as they already have countless times according to reporting), and no amount of official gov't reassurances on "checks and balances" or "proper procedures" can wipe this fact away.

I wonder how many roles at the NSA have inflated spheres of trust, and about all the little and big ways their operators break org procedures all the time...and especially for what reasons...

Re: Protecting Against Leakers

#40
post #11

As a system administrator, he needed access to many of the agency's computer systems -- and he needed access to everything on those machines. He certainly did NOT need this access to administer systems. It still boggles my mind that the sensitive data on those systems was not encrypted so administrators could not read it. In any well-run IT organization, the DBAs cannot read the credit card numbers stored in the data…

It boggles my mind as well. I worked for a credit scoring company, and I must say they took their security really seriously (much more so than the NSA, it looks like).

They created separate positions, with deliberately and carefully separated permissions and often conflicting duties, so that one party watched over the other and ensured no overreaching, and no single person being able to access data unmonitored (as rdl exemplified). In all the time I worked there as a contractor, I never saw production data.

Looking over the Internet, it seems standard practice:

http://www.sans.edu/research/security-laboratory/article/it-...

And of course what Schneier says:

"The first is compartmentalization. Trust doesn't have to be all or nothing; it makes sense to give relevant workers only the access, capabilities and information they need to accomplish their assigned tasks. In the military, even if they have the requisite clearance, people are only told what they "need to know." The same policy occurs naturally in companies."

"Make sure a single person can't compromise an entire system. NSA Director General Keith Alexander has said he is doing this inside the agency by instituting what is called two-person control: There will always be two people performing system-administration tasks on highly classified computers."

Post reply on HN