Live data from Hacker News

“Typo leak” exposes millions of US military emails to Mali web operator

ft.com

61–70 of 75 posts

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#61
post #59

Earlier quoted context omitted.

With the attack on the USS Liberty, we know that alignment of interests is not always true.

The USS Liberty incident is so often used as a boogeyman to make Israel seem overtly malicious to the USA. Often forgotten is that the day before the incident, the Israeli air force accidentally bombed one of their own infantry columns.

The surviving veterans of the ship don’t think the attack was an accident. This does not compare with the Air Force’s accidental fire on friendlies.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#62
post #39
post #31

Earlier quoted context omitted.

Now do .com, .org, and .net, which are all part of US.

No they're not.

From Wikipedia for .com:

> The domain was originally administered by the United States Department of Defense, but is today operated by Verisign, and remains under ultimate jurisdiction of U.S. law.

.edu holds US-centric requirements today. Not sure about .org, .net, etc.

[0] https://en.wikipedia.org/wiki/.com

[1] https://en.wikipedia.org/wiki/.edu

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#63
post #44

The cause isn't just a "typo". Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`. Also, not only did they set up something specifically to capture the emails that they knew weren't intended for them (incidentally preventing the senders' own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content…

They aren’t being at all subtle about it, for example:

    ;; ANSWER SECTION:
    navy.ml.    300 IN MX 0 handle.catchemail.ml.

    army.ml.    300 IN MX 0 handle.catchemail.ml.
Very unethical way to handle sensitive data.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#64

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They'd need every permutation of 2, 3 letters of m, i, l; and while we're at it, add the keys close-by on a qwerty layout. It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.

Well, only the permutations which are also a valid domain, that narrows the field a lot and is also an easily obtainable list.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#65
post #51

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They don’t even need to hijack the actual TLD. Just have an internal catch all that is defined on their internal DNS. Then the sender has to double confirm the addresses before it’d be passed through.

the problem is people sending emails to the wrong domain

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#66
post #51

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They don’t even need to hijack the actual TLD. Just have an internal catch all that is defined on their internal DNS. Then the sender has to double confirm the addresses before it’d be passed through.

Amazing that this common sense isn't what people think of first.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#67
post #51

Earlier quoted context omitted.

They don’t even need to hijack the actual TLD. Just have an internal catch all that is defined on their internal DNS. Then the sender has to double confirm the addresses before it’d be passed through.

the problem is people sending emails to the wrong domain

Yeah, you don't have to route those emails. I'm pretty sure the number of people sending emails to both .mil and .ml are a dozen people in the State Dept.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#68
post #51

Earlier quoted context omitted.

They don’t even need to hijack the actual TLD. Just have an internal catch all that is defined on their internal DNS. Then the sender has to double confirm the addresses before it’d be passed through.

the problem is people sending emails to the wrong domain

And if the senders are mostly within the US military and are thus resolving that domain through their infrastructure, changing the outgoing domain resolution configuration for the mail servers may be able to help with this.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#69

Earlier quoted context omitted.

the problem is people sending emails to the wrong domain

And if the senders are mostly within the US military and are thus resolving that domain through their infrastructure, changing the outgoing domain resolution configuration for the mail servers may be able to help with this.

[deleted]

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#70

Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same…

They'd need every permutation of 2, 3 letters of m, i, l; and while we're at it, add the keys close-by on a qwerty layout. It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.

Maybe have thier email system do a check for a tld matching that and send a verification email before sending, just to make sure they aren't blocking legit email delivery?

Because I can see some serious shortcomings in your proposal right off the bat...

Post reply on HN