Live data from Hacker News

“Typo leak” exposes millions of US military emails to Mali web operator

ft.com

41–50 of 75 posts

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#41
post #40

Earlier quoted context omitted.

The average business uses G Suite or MS Office, and I'm sure that they could find the right setting if their government contract were dependent on it. That's a heck of a lot easier to pull off than migrating >1.4 million military personnel to a new email address.

Hey, a new job for Clippy! "It looks like you're writing an email to a Mali address. Did you actually want to use a .mil address?". Especially Malians will welcome this feature...

Hah! I was talking about a server-side setting, but this is a pretty funny idea.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#42
post #33

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

The average business has no idea how to install a blocker like that. The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs. Or continue not caring about spying on random unclassified information.

That's really understanding companies. If you can get a military contact, you can hire a person who can figure out email filters. It's not the only, or even hardest hoop you'd need to jump through.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#43

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

The ICANN has no governance over ccTLDs, so not doable.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#44
The cause isn't just a "typo". Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`.

Also, not only did they set up something specifically to capture the emails that they knew weren't intended for them (incidentally preventing the senders' own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content of some of the diverted emails that they knew were sensitive and not intended for them.

I can't tell from the article whether they've finally disabled this diversion of the emails. Nor whether they had a plan to scrub all copies of the emails before it's out of their control, maybe offering US diplomats/officials a deadline to get a copy if they want it

Also, if they're now acting in good faith, and interfacing with US officials, I wonder who leaked this situation to the press, and why.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#45

If those emails weren't encrypted, they weren't secret.

Ok thanks.

But let's be real...There's a difference between having unsecured packages on your doorstep and sending packages to another address entirely.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#46

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

How about blocking outgoing mail to these domains? Let's assume there is no important e-mail business going on with Mali

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#47
post #28
post #15

Earlier quoted context omitted.

Israel conducts a large amount of spying on the USA and exports a large volume of military tech to China, but for domestic political reasons the DoD likes to ignore them as a threat.

Israel spies for its own interests, which, per US gov foreign policy, align with US interests. Similar to France and UK.

Israel’s interests wrt the US are complicated.

Israeli politicians campaign in the US. There’s a lot of mutual personal, commercial and government interests between the two countries that often are out of alignment with official positions.

France also has a complicated relationship and does more adversarial spying.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#48
post #44

The cause isn't just a "typo". Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`. Also, not only did they set up something specifically to capture the emails that they knew weren't intended for them (incidentally preventing the senders' own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content…

It's impossible to know but I imagine a press leak (and further coverage by cable news and other traditional print media outlets) is the only way that members of Congress would actually care enough to hold members of the military and Department of Defense accountable so that they'll eventually find a way to resolve the issue.

Whether that'll take the form of a software engineering solution or a "social engineering" solution - in the form of Congressional hearings and the like - remains to be seen.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#49

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They'd need every permutation of 2, 3 letters of m, i, l; and while we're at it, add the keys close-by on a qwerty layout.

It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#50
post #46

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

How about blocking outgoing mail to these domains? Let's assume there is no important e-mail business going on with Mali

It sounds like the DOD already does block emails to .ml because of this issue:

> Lt. Cmdr Tim Gorman [...] said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”.

I think the issue is people sending emails from personal accounts that the DOD cannot control. The article also mentions travel agents as another source of the email.

Post reply on HN