Live data from Hacker News

Snowden impersonated NSA officials, sources say

investigations.nbcnews.com

11–20 of 78 posts

Re: Snowden impersonated NSA officials, sources say

#12

IMO the solution is not keeping the top cryptographers, security experts, et al. out of the agency that is supposed to protect the country from the top cryptographers and security experts from other countries. Seems like a flawed idea right from the start. You just need to make sure the people you hire are actually on your side.

I disagree, the solution is more likely not doing anything morally questionable because the pool of talented people without morals is significantly shallower than the pool with, in my experience.

Re: Snowden impersonated NSA officials, sources say

#15
post #3

If the NSA didn't guard against him using accounts with more clearance to download documents he wasn't supposed to have access to, I don't think Snowden's intelligence is what we should be worried about.

Which I don't understand... they're claiming that we should trust them but they aren't (or shouldn't be [hiring]) the most brilliant people. So, how many other holes exist in their systems and oversight that are unknown because there aren't brilliant people finding them?

Re: Snowden impersonated NSA officials, sources say

#16

Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.

That is the issue with technology and those in power who don't know how to use it. If a General or higher up is having an issue with classified data, it's not like he can just look at the error message and then go home for the day, he requires an IT team to help and maintain the systems.

A DBA can't do their job if they can't access the databases they manage/design/maintain.

Re: Snowden impersonated NSA officials, sources say

#18

IMO the solution is not keeping the top cryptographers, security experts, et al. out of the agency that is supposed to protect the country from the top cryptographers and security experts from other countries. Seems like a flawed idea right from the start. You just need to make sure the people you hire are actually on your side.

That may work in theory, but it's not always possible to know who's on your side. For an especially control-obsessed agency like the NSA that wants to know everything, this approach is completely unpalatable. Large institutions with sensitive information, whether public or private, generally don't know or trust their lower level employees (and a sysadmin is "lower level" in this context). They want solutions that prevent access by default. The NSA seems to have figured out that relying on sysadmins as a trusted party (a contracted trusted party, specifically) exposed a big hole in their ability to control things. It should have been obvious that contracting out a role that requires an extreme amount of trust was a bad idea, but large institutions often don't learn obvious lessons until someone makes them pay for their mistake.
Post reply on HN