Live data from Hacker News

Child tweets gibberish from US nuclear-agency account

bbc.com

191–200 of 220 posts

Re: Child tweets gibberish from US nuclear-agency account

#191
post #158
post #118

Earlier quoted context omitted.

What if the child were a little older and typed something related to launching missiles as a joke?

Nothing would happen. Hawaii sent out an alert to every single cellphone in the state that an ICBM was imminently approaching Honolulu a few years back, and no one outside of Hawaii remembers that anymore today.

[deleted]

Re: Child tweets gibberish from US nuclear-agency account

#192

Earlier quoted context omitted.

Oh please. This is a social media manager who’s working from home that we’re talking about here. On the basis of these facts alone I can be relatively confident that the U.S. nuclear posture wasn’t seriously in jeopardy.

This is a genuine question, I'm really curious. What if the kid typed something that implies "US is firing nukes to {insert random non-Western country}". What is the probability of something like that escalating?

Before 2016, probably nothing would have happened. After 2016 when the Commander in Chief only communicated by tweet, then people probably look at tweets in a slightly different mindset

Re: Child tweets gibberish from US nuclear-agency account

#193

Earlier quoted context omitted.

I think you mis-stated that last line: > Leave US Strategic Command Launch Portal open for child to launch missiles against Ontario, Canada: "Canada: Totally okay, these things happen."

I was 50/49.9/.1 the correction would be Canada being okay with Ontario being nuked, or the target changing to Quebec and Canada still being okay with it. https://en.m.wikipedia.org/wiki/Quebec_sovereignty_movement Quebec is the Texas of Canada, if I recall correctly. There was a third, though unlikely option of the target switching to Alberta, but it turning out to be okay, because it just happened to coincide with…

I guess that’s one way to explain to Alberta the eventual consequences of its rat policies.

Re: Child tweets gibberish from US nuclear-agency account

#194
post #158
post #118

Earlier quoted context omitted.

What if the child were a little older and typed something related to launching missiles as a joke?

Nothing would happen. Hawaii sent out an alert to every single cellphone in the state that an ICBM was imminently approaching Honolulu a few years back, and no one outside of Hawaii remembers that anymore today.

Please don't discount the people in Hawaii that experienced this event.

We lived on O'ahu when it happened and the topic still comes up occasionally. At the time, it was quite traumatic for myself, my wife, and our kids. I spoke to a large number of people who were still in a state of shock in the following week. At least one person died of a heart attack.

Errant tweets or text messages like this from positions of authority have the potential to have very real and major effects on people's lives. Don't downplay the power they hold.

Re: Child tweets gibberish from US nuclear-agency account

#195
post #158
post #118

Earlier quoted context omitted.

What if the child were a little older and typed something related to launching missiles as a joke?

Nothing would happen. Hawaii sent out an alert to every single cellphone in the state that an ICBM was imminently approaching Honolulu a few years back, and no one outside of Hawaii remembers that anymore today.

And the Hawaii incident was over an official alert system which hit far more than cell phones: https://en.m.wikipedia.org/wiki/2018_Hawaii_false_missile_al...

This Twitter incident is a complete joke in comparison. While you should certainly be judicious if you're in any sort of significant communications role, I really don't care what's on USSTRATCOM's Twitter. I didn't even know they had a Twitter nor would I consider the information there more than a frequently updated newsletter. Give the employee a break, it's really not that big of a deal.

Re: Child tweets gibberish from US nuclear-agency account

#196

I don't see how this is as big a deal as people make it out to be. The person in charge of this account probably has nothing to do with anything that remotely matters. You wouldn't worry about your 401k if the asset manager's twitter account posted some gibberish.

I do some work for gov website that is more or less a PR blog. Although you can't do anything to the systems that this agency deals with via the back end to this website, the scope of abuses that someone could engage in if they had these credentials is quite broad, ranging from "Agency XYZ endorses PQR" to "Agency XYZ will begin action against LMN". Or, if you can't see the implications of that ability, consider that…

"My fellow Americans, I'm pleased to tell you today that I've signed legislation that will outlaw Russia forever. We begin bombing in five minutes."

https://en.wikipedia.org/wiki/We_begin_bombing_in_five_minut...

Re: Child tweets gibberish from US nuclear-agency account

#197

Earlier quoted context omitted.

How so? In my experience you are prompted to use it, and you can click and use standard credentials if desired. I deployed WHfB at our $LARGE_ENTERPRISE and opted against using BT RSSI as a trusted signal because it's just too unpredictable. Probably because the Windows space is much more varied, but an RSSI that'd work for one device at ~8' away would fail to lock another when two cube rows away. Meaning, we knew us…

I enabled Hello on my VM Windows 10 Enterprise and then was unable to connect via Remote Desktop from my Mac - so it didn't have single sign-on but it wouldn't fall back to anything I could use. So I disabled it and now it's happy.

Thanks. I'll test this in the morning. AFAIK it works for us, but I don't know for sure.

Which RDP client were you using? And did you disable the password provider (leaving just the WHfB factors)?

And you had full Windows Hello for Business? (This one: https://docs.microsoft.com/en-us/windows/security/identity-p...)

Or, were you using standard Hello? (The two are similarly named, but are quite different under the covers.)

Re: Child tweets gibberish from US nuclear-agency account

#198
post #158
post #118

Earlier quoted context omitted.

What if the child were a little older and typed something related to launching missiles as a joke?

Nothing would happen. Hawaii sent out an alert to every single cellphone in the state that an ICBM was imminently approaching Honolulu a few years back, and no one outside of Hawaii remembers that anymore today.

I remember it. IIRC, the GUI has a button for "CATASTROPHIC EVENT" right next to the one for "Buckle up for safety" or something like that.

Re: Child tweets gibberish from US nuclear-agency account

#199

Earlier quoted context omitted.

Oh please. This is a social media manager who’s working from home that we’re talking about here. On the basis of these facts alone I can be relatively confident that the U.S. nuclear posture wasn’t seriously in jeopardy.

On the other hand, if the child had been a little bit older and thought it would be funny to tweet, "we have launched a nuclear strike on North Korea," or something, I'd imagine that we might be looking at this differently. I don't blame the social media person, but I am pretty surprised that the US Strategic Command allows their Twitter account to be operated from an insecure location.

That would've been hilarious. And also uneventful. North Korea wouldn't start flinging nukes over a Tweet.

Re: Child tweets gibberish from US nuclear-agency account

#200
post #148

The responsible agency is rightfully embarrassed by this oversight, and has now taken stringent measures to ensure something like this never happens again - Henceforth, all tweets can only ever be sent from a remote-desktop server that has to be hosted in a security-clearance-5 site - In order to access the remote-desktop, 2 government employees, who both have 10+ years of government experience, will need to jointly…

The room where the tweeting designated computer is located is painted with anti wifi paint. No communication devices are allowed in the room and is protected by armed guards disguised as plants. Submitting the tweet requires turning two keys at the same time, the keys are reissued every 24 hours. The password to unlock the computer is written with invisible ink in a microfilm contained inside a spy coin in a fake boo…

And the mandatory password for the account will be permanently locked to “00000000”.
Post reply on HN