Live data from Hacker News

Protecting Against Leakers

schneier.com

41–50 of 56 posts

Re: Protecting Against Leakers

#41
post #11

As a system administrator, he needed access to many of the agency's computer systems -- and he needed access to everything on those machines. He certainly did NOT need this access to administer systems. It still boggles my mind that the sensitive data on those systems was not encrypted so administrators could not read it. In any well-run IT organization, the DBAs cannot read the credit card numbers stored in the data…

This is actually easier said than done. One of the major concerns is you don't want some dude with a security clearance taking work home with him. So a lot of effort goes into things like selinux being used to control what programs can access files. Here you have a fundamental conflict. A root user can reconfigure the controls to allow access (that is absolutely necessary from a practical perspective), and so you end…

A determined sysadmin can certainly get the information, but can he do so undetected?

Re: Protecting Against Leakers

#42
post #14

Part of Assange's philosophy is that secretive unjust organizations will operate less efficiently and become less effective as they lock down their internal flow of information in response to leaks. Looks like things are going according to plan.

From Julian Assange's old blog: http://cryptome.org/0002/ja-conspiracies.pdf http://web.archive.org/web/20071020051936/http://iq.org/#The... ---- Sun 31 Dec 2006 : The non linear effects of leaks on unjust systems of governance You may want to read The Road to Hanoi or Conspiracy as Governance ; an obscure motivational document, almost useless in light of its decontextualization and perhaps even then. But if you read…

Hmm... a corollary might be that startups (insecure due to their very nature) have a huge edge with regards to standard institutions, precisely because they don't have to deal with security problems.

So, as they grow bigger, they become more inefficient and customers more unhappy (see: Paypal). I hope there are ways to mitigate this.

Re: Protecting Against Leakers

#43

Earlier quoted context omitted.

This is actually easier said than done. One of the major concerns is you don't want some dude with a security clearance taking work home with him. So a lot of effort goes into things like selinux being used to control what programs can access files. Here you have a fundamental conflict. A root user can reconfigure the controls to allow access (that is absolutely necessary from a practical perspective), and so you end…

A determined sysadmin can certainly get the information, but can he do so undetected?

A sufficiently careful one probably could for some time, especially if he was quite aware of what was checked and could work around such checks initially.

Re: Protecting Against Leakers

#44
I'm baffled. One the one hand, the NSA wants their employees to "uphold and defend the constitution". On the other hand, they want their employees to keep secrets.

(... It is possible for these two things to not be in conflict with each other...)

They want their employees to honor the commitments they've made. At the same time they're lying to congress and the FISC.

Dear NSA: Let me help you un-fuck your business: Stop requiring your employees to uphold and defend the constitution. Stop hiring people who believe that the NSA should be held accountable to the citizens and/or to the congress.

(Perhaps you should start by creating a cult of personality around a strong, charismatic leader. And for the signing-in ceremony, instead of swearing to "defend the constitution against all enemies, foreign and domestic", maybe they could just wipe their asses with a copy of the Bill of Rights.)

If you do this, you will never have another Edward Snowden again. I guarantee it.

Re: Protecting Against Leakers

#45
post #11

As a system administrator, he needed access to many of the agency's computer systems -- and he needed access to everything on those machines. He certainly did NOT need this access to administer systems. It still boggles my mind that the sensitive data on those systems was not encrypted so administrators could not read it. In any well-run IT organization, the DBAs cannot read the credit card numbers stored in the data…

It boggles my mind as well. I worked for a credit scoring company, and I must say they took their security really seriously (much more so than the NSA, it looks like). They created separate positions, with deliberately and carefully separated permissions and often conflicting duties, so that one party watched over the other and ensured no overreaching, and no single person being able to access data unmonitored (as rd…

Given that NSA internal controls seem to be less than commercial best practice in high security settings, and yet people (probably correctly) assume NSA is superior to known science in many areas, there are three reasonable scenarios:

1) NSA actually is fairly competent overall, and feigns incompetence as a way to let people bypass legal controls when "useful".

2) NSA is actually incompetent overall, and people like tptacek who say they're wildly beyond the open world are wrong. They obviously have a huge budget and legal protection (legal or illegal) to do whatever they want, but a lot of what someone would want to do is something even I could pull off given the NSA's level of resources.

3) NSA has really fucked up priorities, and for some reason (limited resources, cynical political calculations, expediency, etc.) put all of their effort into offense and none into defense, not even from their #1 threat (insiders). Maybe they also put too much faith in the vetting process and external shell and less on protections within the chewy center. This was pretty common in the commercial world 10-15 years ago (when "use a firewall and AV filters" was the leading security advice). If NSA actually went backward from the 1980s when they strongly believed on internal controls to actually cross over and be inferior to the commercial world, we're kind of screwed.

Re: Protecting Against Leakers

#46
post #44

I'm baffled. One the one hand, the NSA wants their employees to "uphold and defend the constitution". On the other hand, they want their employees to keep secrets. (... It is possible for these two things to not be in conflict with each other...) They want their employees to honor the commitments they've made. At the same time they're lying to congress and the FISC. Dear NSA: Let me help you un-fuck your business: St…

Apparently they employ pre-brainwashed employees (Mormons).

Edit: okay, that was offensive to Mormons, but they do apparently employ a lot of them. If one group is overrepresented, so will their views (which might diverge from the rest of the population).

Re: Protecting Against Leakers

#47
post #45

Earlier quoted context omitted.

It boggles my mind as well. I worked for a credit scoring company, and I must say they took their security really seriously (much more so than the NSA, it looks like). They created separate positions, with deliberately and carefully separated permissions and often conflicting duties, so that one party watched over the other and ensured no overreaching, and no single person being able to access data unmonitored (as rd…

Given that NSA internal controls seem to be less than commercial best practice in high security settings, and yet people (probably correctly) assume NSA is superior to known science in many areas, there are three reasonable scenarios: 1) NSA actually is fairly competent overall, and feigns incompetence as a way to let people bypass legal controls when "useful". 2) NSA is actually incompetent overall, and people like…

I present a 4th scenario:

These systems are on 'known good networks' staffed by people who have some of the most extensive vetting you can get.

These are the folks who invented (or funded the development of) RBAC and the like. SELinux came out of NSA, for example. The tech exists, but it's a hastle to work with. If you've got fully-cleared, all-known-good actors, why bother?

It's not like it's on the internet, or accessible in some fashion.

Re: Protecting Against Leakers

#48

Two points seemed to contradict eachother. The first was cutting classified sysadmin positions by 90%. the second was requiring doubling up for work on classified systems. Does this mean that the sysadmins will each be responsible for 20x as much information or work? With such a workload how can the doubling up be effective? I guess my rule is that when confronted with a crisis, organizations will usually react in su…

Or cut the need for sysadmins to 5% and fire all but 10% of them.

Re: Protecting Against Leakers

#50
post #47
post #45

Earlier quoted context omitted.

Given that NSA internal controls seem to be less than commercial best practice in high security settings, and yet people (probably correctly) assume NSA is superior to known science in many areas, there are three reasonable scenarios: 1) NSA actually is fairly competent overall, and feigns incompetence as a way to let people bypass legal controls when "useful". 2) NSA is actually incompetent overall, and people like…

I present a 4th scenario: These systems are on 'known good networks' staffed by people who have some of the most extensive vetting you can get. These are the folks who invented (or funded the development of) RBAC and the like. SELinux came out of NSA, for example. The tech exists, but it's a hastle to work with. If you've got fully-cleared, all-known-good actors, why bother? It's not like it's on the internet, or acc…

"Maybe they also put too much faith in the vetting process and external shell and less on protections within the chewy center."

They put a lot of effort into screening staff, but they're also the most attractive target for well-funded adversaries (Russia, China, etc.).

The only stuff I've ever seen come out of NSA and actually used by anyone in government that hasn't been crap has been hardware. SELinux, etc. are a sideshow. Their OS protections as deployed elsewhere in government are primarily COTS or were developed by external contractors (HBSS, etc.), and are actually shittier in a lot of ways than best commercial practice.

Post reply on HN