Live data from Hacker News

“Typo leak” exposes millions of US military emails to Mali web operator

ft.com

71–75 of 75 posts

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#71
post #59

Earlier quoted context omitted.

With the attack on the USS Liberty, we know that alignment of interests is not always true.

The USS Liberty incident is so often used as a boogeyman to make Israel seem overtly malicious to the USA. Often forgotten is that the day before the incident, the Israeli air force accidentally bombed one of their own infantry columns.

Any state based on racism and supremacist ideology and found and controlled by persons who were explicitly terrorists (likud descends directly from irgun etc) is a threat to not just the US but all of human kind...

But you can't really say that about Israel because they'll use the default antisemitism attack, alongside various dogwhistles to encourage harassment, until you are silenced.

Ed: a typo right after posting

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#72
post #43

Earlier quoted context omitted.

The ICANN has no governance over ccTLDs, so not doable.

Except ICANN controls the root DNS servers no?

If I remember well the operations of the root DNS are delegated to other companies/organizations (Verisign for example).

I don't know how easy it would be to insert lies in the root DNS servers, without it being spotted, and without it triggering a potential war if it impacts ccTLDs.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#73

Earlier quoted context omitted.

They'd need every permutation of 2, 3 letters of m, i, l; and while we're at it, add the keys close-by on a qwerty layout. It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.

Maybe have thier email system do a check for a tld matching that and send a verification email before sending, just to make sure they aren't blocking legit email delivery? Because I can see some serious shortcomings in your proposal right off the bat...

It's not just a question of whether it makes a legit TLD; it's also whether military personnel should have any reason to send email there from a given system.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#74

Earlier quoted context omitted.

They'd need every permutation of 2, 3 letters of m, i, l; and while we're at it, add the keys close-by on a qwerty layout. It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.

Well, only the permutations which are also a valid domain, that narrows the field a lot and is also an easily obtainable list.

I'd future-proof it against coming TLD's up-front.

Re: “Typo leak” exposes millions of US military emails to Mali web operator

#75
post #63
post #44

The cause isn't just a "typo". Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`. Also, not only did they set up something specifically to capture the emails that they knew weren't intended for them (incidentally preventing the senders' own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content…

They aren’t being at all subtle about it, for example: ;; ANSWER SECTION: navy.ml. 300 IN MX 0 handle.catchemail.ml. army.ml. 300 IN MX 0 handle.catchemail.ml. Very unethical way to handle sensitive data.

Unethical? Why should Mali have an ethical duty to respect military or intelligence of a foreign country with no alliance that could easily be their enemy some day?
Post reply on HN