Live data from Hacker News

Russian Hackers Read Obama’s Unclassified Emails, Officials Say

nytimes.com

41–46 of 46 posts

Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say

#41
post #16

Earlier quoted context omitted.

These networks would be under the white house communications agency, a subset of the defense information systems agency which is not affiliated with NSA. Supposedly his blackberry is run through NSA (See, e.g., the fishbowl project), and was not implicated in this breach.

Point missed. It's not that it's the President's email that's vulnerable. It's that _all_ people's email is vulnerable. Some of those people are key to national security, many aren't. But they all deserve privacy and protection. And yes, one of NSA's mandates is to secure U.S. communications: "The Information Assurance mission confronts the formidable challenge of preventing foreign adversaries from gaining access to…

> And yes, one of NSA's mandates is to secure U.S. communications:

No, their mandates is to secure military and national security systems. From your own link, their responsibilities with respect to information assurance are (emphasis mine):

  - Act as the National Manager for National Security Systems as established in law and policy, and *in this capacity be responsible to the Secretary of Defense and to the Director, National Intelligence*

  - Prescribe security regulations covering operating practices, including the transmission, handling, and distribution of signals intelligence and communications security material *within and among the elements under control of the Director of the National Security Agency*
The legal definition of National Security System is[1]:

  (1) National security system.— In this section, the term “national security system” means a telecommunications or information system operated by the Federal Government, the function, operation, or use of which—
  (A) involves intelligence activities;
  (B) involves cryptologic activities related to national security;
  (C) involves command and control of military forces;
  (D) involves equipment that is an integral part of a weapon or weapons system; or
  (E) subject to paragraph (2), is critical to the direct fulfillment of military or intelligence missions.
  (2) Limitation.— Paragraph (1)(E) does not include a system to be used for routine administrative and business applications (including payroll, finance, logistics, and personnel management applications).
NIST has responsibility for providing guidance on securing unclassified government systems and commercial networks.[2] Like the parent commenter said, securing White House communications in particular falls under the purview of the White House Communications Agency, which is subordinate to DISA.[3]

Most of the efforts to bring the NSA and the rest of the intelligence agencies into the fold with regards to securing U.S. communications at large have been heavily protested: [4][5]

[1] https://www.law.cornell.edu/uscode/text/40/11103

[2] http://csrc.nist.gov/publications/nistbul/csl91-02.txt

[3] http://www.disa.mil/Careers/WHCA

[4] https://en.wikipedia.org/wiki/Cyber_Intelligence_Sharing_and...

[5] https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar...

Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say

#42
post #3

I am under the impression that attribution is a very difficult and often impossible process. If that is true, what is the point of including "Russian" in this headline? I would guess the most probable response would be something involving "fulfilling a narrative." Even if that is true, what makes "Russian" hackers more exciting then just "Hackers?" I am not trying to pose some profound question. I am genuinely confus…

> what makes "Russian" hackers more exciting then just "Hackers?" It's all about what ultimately happens to the information harvested. If it's some kids in mom's basement doing it for lulz, that's not very concerning. But, presumably, Russian hackers, even if not actual Russian government employees, would pass on useful information to their government. Even if non-classified, that could be very damaging to national s…

In the US (and a few other places in the world), the NSA has capabitilites that private hackers don't, because they get to place their equipment on the backbone. The Russian version of the NSA has no special access in the US, so what Russian government hackers can do, any private hacker can do. Any private hacker can damage national security just as much (or more) by selling the data to the highest bidder(s) or releasing it publicly.

Because of this, there is no difference for national security whether Russian government hackers did it, or anyone else. The only piece of useful info is that the systems were hacked and how they were hacked. The attribution is just for show (and as always in these cases, not very reliable either).

Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say

#43
post #16

Earlier quoted context omitted.

These networks would be under the white house communications agency, a subset of the defense information systems agency which is not affiliated with NSA. Supposedly his blackberry is run through NSA (See, e.g., the fishbowl project), and was not implicated in this breach.

Point missed. It's not that it's the President's email that's vulnerable. It's that _all_ people's email is vulnerable. Some of those people are key to national security, many aren't. But they all deserve privacy and protection. And yes, one of NSA's mandates is to secure U.S. communications: "The Information Assurance mission confronts the formidable challenge of preventing foreign adversaries from gaining access to…

You read my comment wrong. It wasn't making a point, it was stating a fact that there isn't just one agency responsible for network security in the Federal Government.

Your point is the more important one. The danger here is not the breach, since it was an unclassified system, but rather the universal surprise that it was possible. That demonstrates a dangerous level of ignorance in our society.

Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say

#44
post #43

Earlier quoted context omitted.

Point missed. It's not that it's the President's email that's vulnerable. It's that _all_ people's email is vulnerable. Some of those people are key to national security, many aren't. But they all deserve privacy and protection. And yes, one of NSA's mandates is to secure U.S. communications: "The Information Assurance mission confronts the formidable challenge of preventing foreign adversaries from gaining access to…

You read my comment wrong. It wasn't making a point, it was stating a fact that there isn't just one agency responsible for network security in the Federal Government. Your point is the more important one. The danger here is not the breach, since it was an unclassified system, but rather the universal surprise that it was possible. That demonstrates a dangerous level of ignorance in our society.

Fair enough, thanks.

Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say

#46
If only the government could create a honeypot network full of simulated traffic and meticulously faked communications designed to mislead the would-be snoopers... Then this article could be another step in the ruse.

That would probably too much money and effort, though.

Post reply on HN