Live data from Hacker News

Today I Briefed Congress on the NSA

schneier.com

91–100 of 145 posts

Re: Today I Briefed Congress on the NSA

#91
post #12

It makes sense that you need TS/SSBI and the correct SAP read-in to be inside a given SCIF belonging to a SAP; otherwise one might leave a recording device or otherwise damage the integrity of the SCIF. Plus, the SCIF would need to be cleared of all sensitive materials before you entered. Clearing a SCIF, letting someone inside, then recertifying it would probably be the correct choice; It could be done, of course, b…

I'm not sure if you understand. Bruce knows the top secret information because he read it in the leaks. The government officials can lose their security clearance for admitting to discussing top secret things with him.

Not members of Congress.

Re: Today I Briefed Congress on the NSA

#92

Schneier links to a Wikipedia article about Sensitive Compartmented Information Facilities (SCIFs) and explains that he wanted to speak to the members of Congress in such a facility, but could not do so because he is denied access to such facilities as someone without the appropriate security clearances. And that puzzled me, and prompted me to read the Wikipedia article after reading Schneier's blog post submitted he…

The whole security clearance thing is rather over-rated. Many people are immediately disqualified during the background investigation because they missed a payment on something once, or changed jobs too often, or were arrested, yet never convicted of a crime. So the fact that someone does not qualify for a security clearance says very little about them as a person.

The security process in my experience is very much about how much of what they find you were forthcoming with and announced on the forms.

If you missed a payment there is a section of the background paperwork you fill out proving information on it. It is very likely you would be denied if you left that section blank and had a missed payment, or if you changed jobs, or addresses very often and did not list all of them with proper references so they could verify them. But you will be denied basically because you lied not because of the missed payment or address changes.

Re: Today I Briefed Congress on the NSA

#93
post #82

Earlier quoted context omitted.

Robert Gates put it eloquently: the US is in its own wars of choice, and not in any war that is forced upon it. So, what do you think about the secrets that would conceal the real reasons of the war that requests to be secret?

bosma was asking: "Are there any things that should be kept secret during the course of war?". The obvious answer that he's fishing for is "Yes. Stuff that's critical to OPSEC.". [0] This is a silly question to ask. AFAICT, Congress hasn't ever been briefed on the day-to-day of wartime activities. They are often lied to about our motivations for declaring war. That's obviously a very bad thing to do. [0] The funny th…

> That is to say, stuff that's sensitive OPSEC stuff can often be declassified in a matter of hours or weeks... because the actions described by the classified information have taken place and everyone knows that they took place.

Minor quibble - this isn't always true.

If a hacker knows two vulnerabilities to exploit, but only exploits one of them, he keeps an advantage by keeping the extent of his intelligence a secret. If he only knows of the one that was exploited, he's not benefitted by admitting a lack of intelligence.

Apply to enemy troop positions and competitor pricing strategies as appropriate.

Re: Today I Briefed Congress on the NSA

#94

Earlier quoted context omitted.

bosma was asking: "Are there any things that should be kept secret during the course of war?". The obvious answer that he's fishing for is "Yes. Stuff that's critical to OPSEC.". [0] This is a silly question to ask. AFAICT, Congress hasn't ever been briefed on the day-to-day of wartime activities. They are often lied to about our motivations for declaring war. That's obviously a very bad thing to do. [0] The funny th…

> That is to say, stuff that's sensitive OPSEC stuff can often be declassified in a matter of hours or weeks... because the actions described by the classified information have taken place and everyone knows that they took place. Minor quibble - this isn't always true. If a hacker knows two vulnerabilities to exploit, but only exploits one of them, he keeps an advantage by keeping the extent of his intelligence a sec…

> Minor quibble - this isn't always true.

I know. That's why I said "often can be declassified", rather than saying "always can be declassified". :)

Re: Today I Briefed Congress on the NSA

#95

Currently, the Intelligence Committees have special access to top secret information. Every member of Congress should have this.

With 535 of them not including staff, they really shouldn't. And clearance isn't enough, you also have to have a need to know. We just need a system of oversight that works well.

> they really shouldn't.

Please, elaborate.

Re: Today I Briefed Congress on the NSA

#96

Schneier links to a Wikipedia article about Sensitive Compartmented Information Facilities (SCIFs) and explains that he wanted to speak to the members of Congress in such a facility, but could not do so because he is denied access to such facilities as someone without the appropriate security clearances. And that puzzled me, and prompted me to read the Wikipedia article after reading Schneier's blog post submitted he…

The whole security clearance thing is rather over-rated. Many people are immediately disqualified during the background investigation because they missed a payment on something once, or changed jobs too often, or were arrested, yet never convicted of a crime. So the fact that someone does not qualify for a security clearance says very little about them as a person.

Fun fact: you can actually read the transcript of rulings on clearance decisions for DoD contractors: http://www.dod.mil/dodgc/doha/industrial/2013.html

It's true that many people are denied because of their finances, but it's not as cut and dry as you might think.

You also have to wonder what some of these people were thinking. That the DoD wouldn't notice you're on probation and a drug user?

Re: Today I Briefed Congress on the NSA

#97
post #86

Earlier quoted context omitted.

Of course they have to.. Schneier is monitored everywhere he goes!

By who, by the people that he is talking to? I sure hope the people he is talking to are 'monitoring' him while he talks to them. It would be a waste of time if they didn't pay attention.

If the NSA are about to take a big hit in Congress because some Congress members were educated on the actual reality, having advance notions of the nature of the enlightenment of those Congress members would help the NSA prepare a position policy for handling the issue.

Do you not understand that there is nothing honorable about this agency, and this infrastructure? At all? The system is entirely corrupt, corruptible, and absolutely functional as a tool for political power. This is not the time to be milquetoast on the devices we are discovering are being used, indiscriminately, with World-changing powers, by people who were not authorized to do so by the democracy that allowed them the luxury of doing such things, for a living.

These people have constructed their own private search engine - consisting of EVERYONE ELSES DATA. Anyone who cares about the society our children will inherit, must act to promote the destruction of this heinous info-apparat! Before, indeed: it is too late.

There are but 3 small tigers in between the free democratic society and totalitarian fascist state, and those tigers are made of paper, electrons, and gasoline ..

Re: Today I Briefed Congress on the NSA

#98
post #55

Schneier links to a Wikipedia article about Sensitive Compartmented Information Facilities (SCIFs) and explains that he wanted to speak to the members of Congress in such a facility, but could not do so because he is denied access to such facilities as someone without the appropriate security clearances. And that puzzled me, and prompted me to read the Wikipedia article after reading Schneier's blog post submitted he…

There are standard processes in pretty much every government organization for escorting uncleared personnel into a SCIF. The fact that they chose not to in this case might indicate that they aren't taking this seriously.

Or that one wasn't open. Schedule tetris for Congresspeople and a SCIF might be a hard problem.

Re: Today I Briefed Congress on the NSA

#99
post #66
post #15

On his blog Schneier comments that this meeting was kept small on purpose. I wanted to see who was present at this meeting so I looked up some of their information. Not hard to find, but here you go. I plan on emailing each of them and thanking them for consulting someone the tech industry considers a Security SME. Rep. Logfren (Democratic) http://lofgren.house.gov/biography/ Wikipedia - http://en.wikipedia.org/wiki/…

(If you use Facebook) I recommend following Rep. Amash as he explains every one of his votes in a status update. It's a great way to stay informed, and he actually approaches his decisions with sensible reasoning you'll enjoy (regardless of your political leanings).

https://www.facebook.com/repjustinamash

Re: Today I Briefed Congress on the NSA

#100
post #22

Earlier quoted context omitted.

I think you missed the part where he had the conversation anyway, in a regular room. The procedures for handling classified information, especially SCI and ECI, are there to protect from foreign intelligence services. i.e. people doing exactly the shit NSA is accused/documented of doing to foreign governments.

I think you missed the point that I asked: why is there no secure facilities specifically for the purpose of citizen/representative conversation? Is it only the privileged elite military class that get the fun toys? I think it is ..

SCIF are not only military in nature. Plenty of DOE sites have them, national labs, federal buildings, etc.
Post reply on HN