Live data from Hacker News

Snowden impersonated NSA officials, sources say

investigations.nbcnews.com

41–50 of 78 posts

Re: Snowden impersonated NSA officials, sources say

#41
post #2

Was he brilliant? Or is that just a story -- "nobody else out of NSA's 20,000 employees is spying on people they shouldn't because they're just "great" not "brilliant", so don't worry!"

probably a quote from a non techie think Bob howards bosses from the laundry that sort of level of technical knowledge.

Re: Snowden impersonated NSA officials, sources say

#42
post #23
post #15

Earlier quoted context omitted.

Which I don't understand... they're claiming that we should trust them but they aren't (or shouldn't be [hiring]) the most brilliant people. So, how many other holes exist in their systems and oversight that are unknown because there aren't brilliant people finding them?

[deleted]

What are you referencing? The quote (from an NBC story):

> “Every day, they are learning how brilliant [Snowden] was,” said a former U.S. official with knowledge of the case. “This is why you don’t hire brilliant people for jobs like this. You hire smart people. Brilliant people get you in trouble.”

Re: Snowden impersonated NSA officials, sources say

#43

Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.

I see two possibilities, though I am not that well-versed in the software used at the NSA:

1. Administrator accounts were not confined (in the SELinux sense), so he was able to transition to whatever security context he needed/wanted.

2. He was able to set up the login credentials for other users. He could have created his own accounts with higher-level clearances, or set up his own smartcard for logging in to some other person's account, etc.

It may seem like poor design, but it is understandable why things might have been set up like that. In the first case, it is because the admins need to be able to solve problems that happen in a variety of security contexts / levels, and the overhead of defining a second set of policies governing the admins was just too high. In the second, it would be because someone has to be able to set up credentials and that there are a lot of systems for which credentials must be set up, making it hard to impose restrictions. There is also the matter of audit logs -- it might not be so bad to allow an admin to transition to whatever security level if each transition is logged.

I suspect that much of the NSA's computer security is devoted to ensuring that people do not accidentally leak classified information, and that preventing insider attacks is done at a higher level (the clearance process, random audits, etc.).

Re: Snowden impersonated NSA officials, sources say

#45
post #2

Was he brilliant? Or is that just a story -- "nobody else out of NSA's 20,000 employees is spying on people they shouldn't because they're just "great" not "brilliant", so don't worry!"

I know the article is only to report what is said and it might be taken out of context. However, I am disturbed by the kind of mentality around hiring "great" and "brilliant" employee's. I see no future with that kind of organizational thinking.

Re: Snowden impersonated NSA officials, sources say

#47
post #21

Spinning the story so if fits the "Snowden is a traitor" agenda. >> "You hire smart people. Brilliant people get you in trouble.” What does that even mean?

Brilliant people see through the propaganda that the government needs to feed its own employees. Brilliant people are harder to train to be a cog in the machine. The NSA needs people who are just intelligent enough to solve infrastructure / software / etc. problems, but not so smart that they start questioning the broader goals of the organization.

The army breaks down a soldier's individuality as part of a soldier's training. The NSA does not have that luxury (as far as I know), and Booz Allen Hamilton certainly does not.

Re: Snowden impersonated NSA officials, sources say

#48

The use of the word "impersonated" stinks to high heaven. There is a big difference between an admin logging in as someone else and someone "impersonating" someone on TV or over the phone. That would be like having secret documents in a drawer marked "John Smith," then saying that someone who opened that drawer and took some documents was "impersonating" John Smith. Then there's the bit about "hiring brilliant people…

There is no "root access" implied in this article. Read about RBAC to understand this.

If RBAC is supposed to guard against abuses, even by sysadmins, but was implemented in a way that sysadmins could get around it, and there were no effective mechanisms to prevent that, then it's all just "security theater."

If Snowden pointed this out to his bosses and was ignored, then he had a legitimate reason to blow the whistle.

Re: Snowden impersonated NSA officials, sources say

#49

I know I'll get downvoted for this. Please be a contributing community member of HN and state why. Have any of the NSA leaks told us anything we don't know? Haven't the majority of the leaks told our foreign enemies how to avoid being tracked more than anything? I have yet to see any serious abuse of the NSA's power. The fact that they know that low level employees were spying on potential love interests means that t…

"Have any of the NSA leaks told us anything we don't know?"

Anything we i.e. the readership of HN / Slashdot / Reddit / etc. do not know? Of course not. That accounts for about 2% of the population of the United States. The rest of America is still trying to get past the "but I am not even interesting, why would the NSA spy on me?" stage of life.

"Haven't the majority of the leaks told our foreign enemies how to avoid being tracked more than anything?"

How is that coherent with your first sentence? If the leaks did not tell us anything we do not already know, surely they are not telling our enemies anything they do not already know.

The reality is that foreign governments already know that the US is trying to spy on them. Terrorists know that too. That is why foreign governments use cryptography and other information security techniques. That is why terrorists deliver notes by courier.

"what if they actually have checks built into this system as they have claimed"

...this is a story about a low-level sysadmin who walked out of the very same organization with an untold number of classified documents. What checks do you think are built in, exactly?

"they know that low level employees were spying on potential love interests"

I think your question has been settled: no, effective checks on the NSA's power are not in place. Obama could not care less about some low level guy's love interests. Of course, those pesky journalists pointing out the ways he has lied, abused Presidential authority, etc., that's another story...

Re: Snowden impersonated NSA officials, sources say

#50
post #27

Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.

I'm highly skeptical of the reporting. He may have impersonated other accounts to cover his tracks but if he had physical access to a system or the user database of a system then he was "authorized" to see all of the data on that system. Or they are doing IT security worse in that office than it is usually done.

> they are doing IT security worse in that office than it is usually done

Two things that are undeniable:

1) They were doing IT security worse than the level which was actually needed

2) All the while, they were telling the world that effective mechanisms were in place which would prevent abuses.

So they weren't doing what they were supposed to and they were deceiving the public about it. Whether or not this was intentional is just secondary.

Post reply on HN