Live data from Hacker News

Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

wired.com

31–40 of 55 posts

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#31
post #27

There's evidence that US government counter-intelligence and information security are very poor: Snowden, Manning, the recent break-in at OPM, etc. In past generations, nuclear plans were stolen, the heads of both FBI and CIA counter-intelligence have been moles, a Navy sailor kept the Soviets updated on the locations of US submarines, etc. Here's a list I came across recently: http://www.wearethemighty.com/american-…

Why is secrecy clearly necessary for governments? You may be right, but it's far from clear.

Well, it offers a huge military advantage, so in the interests of waging war, it is very useful, if not necessary.

But I think the most common use of it is probably the fact that politics is a game of hypocrisy, and you can't play unfairly if you don't get to keep secrets.

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#33
post #12

NSA adopted two man rule for system administration only after Snowden leaks. Before Snowden anyone with similar access as Snowden could have copied the same data. What is the probability that at least one guy with same access as Snowden spied for China or Russia? I would say close to 1.0.

What is the probability of that guy being Snowden himself?

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#34
post #12

NSA adopted two man rule for system administration only after Snowden leaks. Before Snowden anyone with similar access as Snowden could have copied the same data. What is the probability that at least one guy with same access as Snowden spied for China or Russia? I would say close to 1.0.

"%50 of former employees admit to stealing confidential company data" [1]

Even with oaths and allegiences, the probability that Snowden is the only one to take advantage of the lax security in the NSA is 0.

[1] http://www.symantec.com/about/news/release/article.jsp?prid=...

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#35

There's evidence that US government counter-intelligence and information security are very poor: Snowden, Manning, the recent break-in at OPM, etc. In past generations, nuclear plans were stolen, the heads of both FBI and CIA counter-intelligence have been moles, a Navy sailor kept the Soviets updated on the locations of US submarines, etc. Here's a list I came across recently: http://www.wearethemighty.com/american-…

The heads of the FBI/CIA I know they both had senior officers go bad but do you have any proof of this?

Just to be clear, it wasn't the heads of the whole FBI and CIA; it was the heads of their counterintelligence divisions (or maybe their Soviet counterintelligence divisions - I don't know the org charts precisely), Aldrich Ames (CIA) and Robert Hanssen (FBI). Just do a search; there were arrests, trials, etc. - it is very well documented.

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#37

I once challenged Glenn Greenwald as to how he could be confident his copy of the documents hadn't been hacked. His answer wasn't terribly convincing. That said, it's also possible he got lucky. He lives in a fairly isolated farmhouse with a lot of dogs, so maybe it really is hard to do a black bag operation on him. And I'm not sure how even a nation state could do a purely internet-based attack on an air-gapped comp…

> That said, Laura Poitras in bustling Berlin or an entire major newspaper might be an easier target ...

That incident where British government officials destroyed the laptop containing The Guardian's copy of the documents makes more sense in light of this.

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#38
post #20

Earlier quoted context omitted.

Spying is a wash - what you're saying is true, but it's only half the equation. Sometimes that second guessing is what keeps the conflict from becoming hot. Spying can compromise a country's defense to the extent another country feels comfortable attacking. Also, if a weaker country can maintain the facade of strength it's less likely to be attacked. The most obvious example is when one country manages to uncover ano…

You need mutual spying, but if you have that, then the week country will know that it is 100% vulnerable to first strike, and surrender before it comes to that.

I'm not so sure you can count on a country to act in rational self-interest. Individual people aren't so good at that, and collectives can be less rational than individuals.

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#39
post #19

Assuming this is true "we have now seen our agents and assets being targeted”, there is another explanation why now - other than foreign agencies getting the documents Snowden took. The explanation is called protecting intelligence sources: Russia, China - or whoever had their spies inside NSA long before, can now act on the intelligence they got without triggering counterintelligence alarms.

Even then, targeting spies is counterproductive. The spy you know about is much less dangerous than spy that you don't know about.

If they hacked the NSA, I'd suspect most spies are known rather than unknown. There's a curious event where Russia expelled 30 UK diplomats from Moscow - and none of them were intelligence operatives (and this was no coincidence as 1/3rd of the staff were intelligence operatives) - it was just to send a message: "we know who your spies are"[1].

Edit: corrected number of diplomats & added citation

1. http://www.globalresearch.ca/five-reasons-the-mi6-story-is-a...

Re: Bruce Schneier: China and Russia Almost Definitely Have the Snowden Docs

#40
post #10

Bruce Schneier is falling into the trap of saying since computer security is hard, the NSA has certainly been compromised and we can assume these docs have been out there for a while. Yes, securing the endpoint is hard, especially given the non-hardened OS and applications we mostly use. However, you can't extrapolate from that to say with certainty what has and hasn't been exposed via security flaws. The USSR was mu…

> > The vulnerability is not Snowden; it’s everyone who has access to the files. > > First, the journalists working with the documents. > Bruce Schneier is falling into the trap of saying since computer security is hard, the NSA has certainly been compromised and we can assume these docs have been out there for a while. The NSA has been compromised. By Snowden. There's no assumption there, that's fact. Now, access to…

Yeah but the point is that the NSA is most likely much easier to compromise than the Snowden documents.
Post reply on HN