>> "You hire smart people. Brilliant people get you in trouble.”
What does that even mean?
21–30 of 78 posts
>> "You hire smart people. Brilliant people get you in trouble.”
What does that even mean?
That would be like having secret documents in a drawer marked "John Smith," then saying that someone who opened that drawer and took some documents was "impersonating" John Smith.
Then there's the bit about "hiring brilliant people." What's so brilliant about someone with root access having access to everything? Nothing. That's what root access enables. It's not a case of Snowden's brilliance. It's a case of the NSA's administrative incompetence: there should be auditing in place.
EDIT: So there was RBAC in place. Evidently, the implementation was botched. Amounts to the same thing: "security theater." This actually bolsters Snowden's case that whistleblowing was justified.
If the NSA didn't guard against him using accounts with more clearance to download documents he wasn't supposed to have access to, I don't think Snowden's intelligence is what we should be worried about.
Which I don't understand... they're claiming that we should trust them but they aren't (or shouldn't be [hiring]) the most brilliant people. So, how many other holes exist in their systems and oversight that are unknown because there aren't brilliant people finding them?
Are they talking about su?
> NSA Director Keith Alexander told the House Permanent Select Committee on Intelligence that Snowden fabricated digital keys that gave him access to areas way above his clearance as a low-level contractor and systems administrator. [1]
[1] http://www.businessinsider.com/edward-snowden-copied-a-lot-o...
Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.
If the NSA didn't guard against him using accounts with more clearance to download documents he wasn't supposed to have access to, I don't think Snowden's intelligence is what we should be worried about.
Which I don't understand... they're claiming that we should trust them but they aren't (or shouldn't be [hiring]) the most brilliant people. So, how many other holes exist in their systems and oversight that are unknown because there aren't brilliant people finding them?
Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.
Are they talking about su?
I think it might be a little more complex than that, but in essence, yes. In these types of environments you will have certificates (browser based or otherwise), he could have fabricated digital keys or stolen these from some type of key store, and then used them on his behalf. > NSA Director Keith Alexander told the House Permanent Select Committee on Intelligence that Snowden fabricated digital keys that gave him a…
Have any of the NSA leaks told us anything we don't know? Haven't the majority of the leaks told our foreign enemies how to avoid being tracked more than anything? I have yet to see any serious abuse of the NSA's power. The fact that they know that low level employees were spying on potential love interests means that they have a system in place to track such abuses. Leaking those kind of emails can be spun to state the opposite, when those emails are direct evidence that such abuses are tracked and presumably punished.
I've seen articles that have said "what if they use this power to subvert political dissidents" Well, what if they actually have checks built into this system as they have claimed and this new information proves? Such rumor spinning gets us nowhere as a society. Wouldn't that make Snowden a spy with his own self interests at heart, not the interests of the American people? Leaking piece-meal like he has is in his interests, not ours.
http://en.wikipedia.org/wiki/2013_mass_surveillance_disclosu...
Look at the scope of these systems. The fact that no abuses have come up (locally) is quite telling, imho. When this same type of hardware is in the hands of countries like China, we see these abuses. Is China seeing something we don't and just not telling us? I highly doubt it.
The use of the word "impersonated" stinks to high heaven. There is a big difference between an admin logging in as someone else and someone "impersonating" someone on TV or over the phone. That would be like having secret documents in a drawer marked "John Smith," then saying that someone who opened that drawer and took some documents was "impersonating" John Smith. Then there's the bit about "hiring brilliant people…