Live data from Hacker News

“Typo leak” exposes millions of US military emails to Mali web operator

ft.com

31–40 of 75 posts

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#31

Earlier quoted context omitted.

Weird because the USA top level domain is supposed to be .us, with that being one of the first country code top level domains.

It's my understanding that .gov and .mil were brought over from when those were independent networks, pre-internet.

Now do .com, .org, and .net, which are all part of US.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#33

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

The average business has no idea how to install a blocker like that.

The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs.

Or continue not caring about spying on random unclassified information.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#37
post #16

Conspiracy theory time: deliberate acts to provide Casus Belli for American invasion. Along the lines of Colin Powell's vial of anthrax at the UN or the "baby incubators" statements from a Kuwaiti princess a decade earlier. The article states "closely allied with Russia" and the current establishment desires to punish anyone who doesn't distance themselves from Russia. The emails might be nothing sensitive to the sta…

Why would the US want to invade Mali?

[deleted]

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#38
post #33

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

The average business has no idea how to install a blocker like that. The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs. Or continue not caring about spying on random unclassified information.

The average business uses G Suite or MS Office, and I'm sure that they could find the right setting if their government contract were dependent on it. That's a heck of a lot easier to pull off than migrating >1.4 million military personnel to a new email address.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#39
post #31

Earlier quoted context omitted.

It's my understanding that .gov and .mil were brought over from when those were independent networks, pre-internet.

Now do .com, .org, and .net, which are all part of US.

No they're not.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#40
post #33

Earlier quoted context omitted.

The average business has no idea how to install a blocker like that. The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs. Or continue not caring about spying on random unclassified information.

The average business uses G Suite or MS Office, and I'm sure that they could find the right setting if their government contract were dependent on it. That's a heck of a lot easier to pull off than migrating >1.4 million military personnel to a new email address.

Hey, a new job for Clippy! "It looks like you're writing an email to a Mali address. Did you actually want to use a .mil address?". Especially Malians will welcome this feature...
Post reply on HN