Live data from Hacker News

Protecting Against Leakers

schneier.com

21–30 of 56 posts

Re: Protecting Against Leakers

#21
Two points seemed to contradict eachother. The first was cutting classified sysadmin positions by 90%. the second was requiring doubling up for work on classified systems.

Does this mean that the sysadmins will each be responsible for 20x as much information or work? With such a workload how can the doubling up be effective?

I guess my rule is that when confronted with a crisis, organizations will usually react in such a way as to preserve or even exacerbate all pre-existing problems.

Re: Protecting Against Leakers

#22
post #12
post #7

> More surprising than Snowden's ability to get away with taking the information he downloaded is that there haven't been dozens more like him. Is an assumption on Schneier's part. For all we know there were dozens or more. They may not have released the data or they may have sold it to some foreign agency instead.

I assume he means specifically whistleblowers, not any traitor.

Your comment implies that whistle-blowers are a sub-category of traitors. Is that intentional?

Re: Protecting Against Leakers

#23
post #14

Part of Assange's philosophy is that secretive unjust organizations will operate less efficiently and become less effective as they lock down their internal flow of information in response to leaks. Looks like things are going according to plan.

If we take Schneier's example of the bank president and the ATM, you could easily argue that is a flawed philosophy. Every day I go to the ATM, money comes out. Like clockwork, very efficient.

Because bank's principal job has been running ATMs for 40 or 50 years and it is run-the-bank stuff. If you look at internet banking (and how out of date and clumbsy most of these systems are) you will see this effect. Change-the-bank stuff is what "suffers" from this.

Retail banks' ATM and overnight payments systems are often 25-year-old pieces of software and hardware.

Re: Protecting Against Leakers

#24
post #11

As a system administrator, he needed access to many of the agency's computer systems -- and he needed access to everything on those machines. He certainly did NOT need this access to administer systems. It still boggles my mind that the sensitive data on those systems was not encrypted so administrators could not read it. In any well-run IT organization, the DBAs cannot read the credit card numbers stored in the data…

This is actually easier said than done. One of the major concerns is you don't want some dude with a security clearance taking work home with him. So a lot of effort goes into things like selinux being used to control what programs can access files.

Here you have a fundamental conflict. A root user can reconfigure the controls to allow access (that is absolutely necessary from a practical perspective), and so you end up having to trust the sysadmins.

Or you could set up other systems that would read the files, decrypt them only within special programs. Now you have two problems..... Moreover the sysadmin might be able to pull passphrases as they are typed, keys as they are uploaded, etc. It is not that easy to manage.

In the end a determined sysadmin can get the information and there isn't really a way you can lock him or her out fully.

Re: Protecting Against Leakers

#25
post #19

Earlier quoted context omitted.

DBA's and system administrators can usually use their privileges to install tools or change settings in such a way that they gain access to the raw data. Whether it goes undetected or not is another matter. In the end someone or some process has access and a sysadmin / DBA could pretend to be that someone or that process. Once you have physical access to a box it is game-over, the only thing that might still trip you…

You can set things up so there's no way for any single to bypass logs or other audit controls. A trivial way is to have all logins go via an administration host which logs separately , and never give admin rights on that machine to people with admin on the protected systems.

Yep. That's the way to do it. But a surprising number of companies have things set up so that a single individual can get at whatever data he or she wants without any logs or with logs that can be tampered with. Typical reason in small companies: there is only one person with the required skills.

What is surprising is that even the NSA did not follow these practices after all if there is a place where such a system would make sense it would be there, and they certainly could not make the excuse that they're small.

Re: Protecting Against Leakers

#26
post #22
post #12

Earlier quoted context omitted.

I assume he means specifically whistleblowers, not any traitor.

Your comment implies that whistle-blowers are a sub-category of traitors. Is that intentional?

Is that what it implies? I would have missed that and read this as 'whistleblowers versus any kind of traitor'.

Re: Protecting Against Leakers

#27
post #7

> More surprising than Snowden's ability to get away with taking the information he downloaded is that there haven't been dozens more like him. Is an assumption on Schneier's part. For all we know there were dozens or more. They may not have released the data or they may have sold it to some foreign agency instead.

... or they may have sold it to some foreign agency instead.

Don't forget corporations and individuals. And of course blackmail. That could be very profitable, specially against powerful people, politicians...

Re: Protecting Against Leakers

#28
post #27
post #7

> More surprising than Snowden's ability to get away with taking the information he downloaded is that there haven't been dozens more like him. Is an assumption on Schneier's part. For all we know there were dozens or more. They may not have released the data or they may have sold it to some foreign agency instead.

... or they may have sold it to some foreign agency instead. Don't forget corporations and individuals. And of course blackmail. That could be very profitable, specially against powerful people, politicians...

Interesting angle. Makes you wonder if any politicians data was part of Snowden's haul. If so that opens up another can of worms.

If they didn't have segregated access (and it does not appear that they did) then that would have surely been too juicy to pass up. 20,000 documents is a lot.

This might also go some way to explaining the panic, if they don't know what he's got and he's had access to data like that then some people must really not be sleeping well right now.

Re: Protecting Against Leakers

#29
post #27

Earlier quoted context omitted.

... or they may have sold it to some foreign agency instead. Don't forget corporations and individuals. And of course blackmail. That could be very profitable, specially against powerful people, politicians...

Interesting angle. Makes you wonder if any politicians data was part of Snowden's haul. If so that opens up another can of worms. If they didn't have segregated access (and it does not appear that they did) then that would have surely been too juicy to pass up. 20,000 documents is a lot. This might also go some way to explaining the panic, if they don't know what he's got and he's had access to data like that then so…

Makes you wonder if any politicians data was part of Snowden's haul.

It's safe to assume that most (every?) politicians data is part of NSA's haul. Add journalists.

I find the debate about surveillance terribly naive. Politicians get corrupted as soon as there's no one closely looking.

Creating such a surveillance and secret-keeping mammoth is calling for massive corruption. And this thing has been running for years.

Re: Protecting Against Leakers

#30
post #29

Earlier quoted context omitted.

Interesting angle. Makes you wonder if any politicians data was part of Snowden's haul. If so that opens up another can of worms. If they didn't have segregated access (and it does not appear that they did) then that would have surely been too juicy to pass up. 20,000 documents is a lot. This might also go some way to explaining the panic, if they don't know what he's got and he's had access to data like that then so…

Makes you wonder if any politicians data was part of Snowden's haul. It's safe to assume that most (every?) politicians data is part of NSA's haul. Add journalists. I find the debate about surveillance terribly naive. Politicians get corrupted as soon as there's no one closely looking. Creating such a surveillance and secret-keeping mammoth is calling for massive corruption. And this thing has been running for years…

Yes, that the NSA has it is fairly obvious at this point but the question is whether or not Snowden took it. Is there any indication that he did?
Post reply on HN