Live data from Hacker News

“Typo leak” exposes millions of US military emails to Mali web operator

ft.com

51–60 of 75 posts

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#51

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They don’t even need to hijack the actual TLD. Just have an internal catch all that is defined on their internal DNS. Then the sender has to double confirm the addresses before it’d be passed through.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#52
post #16

Conspiracy theory time: deliberate acts to provide Casus Belli for American invasion. Along the lines of Colin Powell's vial of anthrax at the UN or the "baby incubators" statements from a Kuwaiti princess a decade earlier. The article states "closely allied with Russia" and the current establishment desires to punish anyone who doesn't distance themselves from Russia. The emails might be nothing sensitive to the sta…

Why would the US want to invade Mali?

[dead]

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#53
The title gives the impression that one typo led to the leaking of millions of emails from the US military servers, which is not the case here.

- Presumably each typo led to one leak. "Typos leak emails" would be more appropriate in that case.

- Are they really "US military emails" if they originated from elsewhere and one of the intended recipients was on the '.mil' domain? Apparently "emails sent directly from the .mil domain to Malian addresses are blocked before they leave the .mil domain".

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#54

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

Any e-mails with PII or other information considered sensitive is supposed to be encrypted, which is at least one reason contractors get CACs and .mil e-mails of their own, so they're able to send encrypted e-mails.

Given what can be figured out by collecting thousands of hotel itineraries or whatever is actually being leaked here, it may just be the DoD needs to crack down and expand the definition of what is considered sensitive.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#55
post #50
post #46

Earlier quoted context omitted.

How about blocking outgoing mail to these domains? Let's assume there is no important e-mail business going on with Mali

It sounds like the DOD already does block emails to .ml because of this issue: > Lt. Cmdr Tim Gorman [...] said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”. I think the issue is people sending emails from personal accounts that the DOD cannot control.…

>travel agents as another source of the email

Sales and travel agents, an IT depts worse nightmare. People too busy to double check anything are the fault of emails delivering to the wrong recipient.

Colour me surprised.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#56
post #43

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

The ICANN has no governance over ccTLDs, so not doable.

Except ICANN controls the root DNS servers no?

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#57
post #28
post #15

Earlier quoted context omitted.

Israel conducts a large amount of spying on the USA and exports a large volume of military tech to China, but for domestic political reasons the DoD likes to ignore them as a threat.

Israel spies for its own interests, which, per US gov foreign policy, align with US interests. Similar to France and UK.

With the attack on the USS Liberty, we know that alignment of interests is not always true.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#58
post #46

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

How about blocking outgoing mail to these domains? Let's assume there is no important e-mail business going on with Mali

or just rewrite it. all .ml becomes .mil, and then have .mil run a relay if it was an actual email to .ml.

then make it part of any contract that if you do business for .mil, and you use microsoft/zoho/gsuite etc, that they automatically run a set of ".mil compliance settings" overlaid onto your tenant.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#59
post #28

Earlier quoted context omitted.

Israel spies for its own interests, which, per US gov foreign policy, align with US interests. Similar to France and UK.

With the attack on the USS Liberty, we know that alignment of interests is not always true.

The USS Liberty incident is so often used as a boogeyman to make Israel seem overtly malicious to the USA. Often forgotten is that the day before the incident, the Israeli air force accidentally bombed one of their own infantry columns.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#60
post #16

Conspiracy theory time: deliberate acts to provide Casus Belli for American invasion. Along the lines of Colin Powell's vial of anthrax at the UN or the "baby incubators" statements from a Kuwaiti princess a decade earlier. The article states "closely allied with Russia" and the current establishment desires to punish anyone who doesn't distance themselves from Russia. The emails might be nothing sensitive to the sta…

Why would the US want to invade Mali?

Mali's a Daesh hotbed.

Mali has been close to Russia politically, culturally, economically, and militarily since the 1960's.

Mali's welcomed Russian troops, including Wagner's, in the wake of the French pulling out.

"[The Russian involvement in Mali] signals a major expansion of Russia's military interests in Africa and a strategic setback for the West. The deployment of Russian military contractors signals a profound break with France and the West."

https://www.bbc.com/news/world-africa-58751423

https://www.reuters.com/world/africa/un-security-council-end...

https://www.chathamhouse.org/2021/12/russias-presence-mali-r...

https://en.wikipedia.org/wiki/Mali%E2%80%93Russia_relations

Post reply on HN