Teen says he hacked CIA director's AOL account
nypost.com
nypost.com
I'm not just saying this to be a jerk - this should be grounds for immediate termination of his employment. This is clearly a guy who shows poor judgement with respect to the management of sensitive material.
Also, from the article:
"[The] problem with these older-generation guys is that they don’t know anything about cybersecurity, and as you can see, it can be problematic.”
On the contrary - these "older-generation guys" cut their teeth in an environment where we were going head-to-head with the KGB on a daily basis. These guys have a solid understanding and awareness of basic information security procedures, as well as a strong understanding of adversary capabilities. I don't buy it.
My guess is that to many people in power, the benefits of using these web services seem to outweigh the disadvantages because they just don't understand the disadvantages. "It's OK - I set a great password!" There's simply nobody powerful enough to monitor what they're doing, independent enough to want to do something about it, and respected enough for people to listen.
We need independent bodies that act as national 'IT departments' and can refuse requests from the very highest powers, in much the same way that any other Head of IT can fire someone for gross misconduct because they were downloading torrents on their company laptop.
Unfortunately today we have people in these branches of government who either won't do their duty because they are terrible at their jobs or because there is a silent quid-pro-quo where these sorts of people look the other way for each other.
More specifically, his security clearance should be revoked, or modified such that he's not allowed to use a computer without being supervised by a competent person; which ought to have the effect that he's basically disqualified from working for the CIA, or speaking about anything related to information security.
Maybe we need a secret service for tech that's outside the command structure of these agencies.
However, the fact its expected levels of incompetence :/
I am guessing this kid wiggled his way into a 10+ year old AOL account containing data that was never deleted. We all probably have emails and contacts sitting in a forgotten AOL account.
CNN is reporting he posted his SSN on Twitter.
There was a time when we all had noisy modems and AOL accounts.
CIA Director John Brennan’s private account held sensitive files — including his 47-page application for top-secret security clearance — until he recently learned that it had been infiltrated, the hacker told The Post. Other emails stored in Brennan’s non-government account contained the Social Security numbers and personal information of more than a dozen top American intelligence officials
Storing confidential material in an AOL account would be a crime, just like giving the same material to Wikileaks.
Brennan's PII, job history, etc. is certainly valuable information, but clearance application paperwork itself is unclassified.
Stories like these make me shudder thinking about the times I may have, at some point, included a document with personal information in an email, such as to a prospective landlord for verification. Even if I were able to keep my email account reasonably secure...I'm pretty sure all the recipients of my email aren't as wary, or regularly delete old received emails with attachments that they've collected over the _decade_.
Although in Mr. Brennan's case, he doesn't have that same excuse. It may have been reasonably safe (for a layperson in IT) to send his application file over aol.com's servers, but not to keep a copy of it in his Sent box. Even a novice at cybersecurity should realize the problem of keeping digital files around on an online server...it's not much different than keeping files in a file cabinet and expecting that file cabinet never to be compromised.
I always insist on encryption for these sorts of things. I'm fairly certain that for everyone I've asked about an encrypted channel to deliver data, I've always been the first person to even ask. This includes hospitals, agencies who do background checks, etc. It's incredibly disturbing that no one else is insisting that their sensitive documents not just sit unencrypted in all these random in and out boxes.
The director is presumably in charge of executing specific missions and a long term vision for human spying. She/he does this by directing people who manage people who manage people (etc.). I don't think a technical/engineering background is presumed or necessary for such a role.
That said, an understanding of the basic structures and failure modes of information security in the digital world as it pertains to HUMINT does seem highly relevant (and necessary) for crafting and executing a modern vision/mission.
Definitely, but one should know his/her limitations, and that one in particular should also never speak about infosec. Brennan fails on both of those accounts.
A quick crosscheck of the names and emails brings up:
* The current Senior Director for the North Africa and Yemen National Security Council for the White House
* The former Former Deputy Assistant Secretary of Defense, for the US Department of Defense
* A retired 3-star general and former Deputy National Security Advisor to the President
It says something sad about our cybersecurity preparedness that the director of the CIA is keeping this info in an aol.com account.
What about the twitter account in the article? I am assuming that is what you meant?
Like seriously, it is like begging to be apprehended.
I guess you are right. I clicked the twitter name on the post and he has indeed posted the documents and is daring them. Just unreal.
Walking by... head pops up... "dude... dude... (trying no to snicker too hard) ... this lady's cup holder is broken..." ... me respondign "cup holder?" ... "yeah, the cd drive.. she thinks it's a cup holder" ...
Such a brief interaction, but really funny none the less... My funniest call was someone calling to back up their master's thesis work, because they were concerned about the power during the storm... was almost 6 minutes into the call when he said the power was out (desktop computer). It's really hard to be professional when faced with certain levels of stupid.
"I get emails all the time from people who say they were -that- tech support guy that got -that- call about the cup holder. While we're on the subject of what people want in their email client, I want my email client to lock all those people in a room and force them to duke it out until there really is only -that one guy-."
These are probably the three most stupid tech things I've seen... I also saw a computer that was shot once, I am pretty sure that's happened a few times.
Also, what is a NY Post story doing here?
NY Post was the first to break the news and it is all over the news- CNN, Fox, etc.. Can't find the link to them but here it is herehttp://www.computerworld.com/article/2994451/cybercrime-hack...