CIA Director John Brennan emails
wikileaks.org
wikileaks.org
How can these top government officials be so clueless about email security when they know first-hand how effective our own intelligence agencies are at reading everyone's email?
[1] It was a really dumb bypass, too: Client: The authN methods I support are: [empty list]. Server: Ok, let's just skip authN.
But that doesn't mean she actually had VNC or RPC software actually listening on those ports, or that the software that was listening (whatever it might be) was actually vulnerable. It might be more likely than not that it was vulnerable--I mean, that's why security people look for things like that to begin with--but false alarms aren't exactly uncommon, either and my customers have proven to me that there's no shortage of bizarre server configurations in the wild.
Server: I support the following auth methods ["password"]
Client: Cool, let's use "none"
Server: Okay.
I agree this all is testament to widespread cluelessness, but more on the software industry level...
PS: I also wonder how this worked in practice. I mean I would assume top officials spam rules where setup to ignore hillary@somerandomdomain.org due to spoofing if nothing else.
Quite interested, as I've been watching this one closely, especially with regards to retro-active changes allowing for an escape from previously committed illegalities.
I fully expect a presidential pardon to be the end-game on this one.
Hillary Clinton's use of private email not unusual, but still raises questions. http://www.latimes.com/nation/politics/politicsnow/la-pn-hil...
Other government officials, and Secretaries of State before her, had also used private email for official business, and experts agree that this is allowed by federal law in case of emergencies.[25][8][26] The State Department declined to answer questions about whether the private system was widely known within the agency or officially approved.[21] https://en.wikipedia.org/wiki/Hillary_Clinton_email_controve...
Even my public University's president used a personal account in order to avoid student activist groups getting his email.
Sarah Palin used personal email (I think also AOL, actually) in her tenure as governor of Alaska.
Everyone, on both sides of the aisle, and all the way up and down the hierarchy does it. Absolutely everyone. Probably everyone has at some point in time. Probably even Bernie Sanders.
If you want to find out who, start sending FOIA requests and see what comes back empty.
So that excuses it, right? When a bunch of people that don't matter do it, you're right, I don't give a shit. When it's our Secretary of State, one with access to all kinds of Top Secret material, I do however very much give a shit. If national security regulations don't apply to our top leadership, then what the fuck do we have them for?
The reason those laws are there is exactly for people like top leadership, because you and I aren't going to run across top secret documents in our day to day... UNLESS some asshat does something stupid like this.
Scope of damage is an important concept when it comes to government versus private sector. Scope of damage for private sector is a "Sony" - possibly implosion of the company, but it generally stops there. Government however is the safety of every citizen in the affected country.
HUGE differences on the damage scale.
Did I say that, `zer0defex`?
>When a bunch of people that don't matter do it, you're right, I don't give a shit.
Why not? Do you think that local government and other public servants should be able to hide corruption, suppression of dissent, or other unsavouryness behind personal email accounts?
>HUGE differences on the damage scale.
The only thing on the scale is that our entire political system is corrupt.
That said, the focus on Hillary is a function of right-wing media hacking, and I think it's important to note that EVERYONE DOES THIS, THE WHOLE SYSTEM IS FUCKED, etc..
Some of the laws in question here carry prison time:
http://www.npr.org/sections/itsallpolitics/2015/04/02/396823...
It's very common for senior execs to play all sorts of games with email. If you see folks carrying legacy Blackberry devices today, they are doing something similar.
No one has been able to convince me that the exchange servers run by state are inherently more secure than her private exchange server was.
The open ports are what one would normally expect to see open, based on what I'd read even.
Albeit, a very unquestioning & gullible one?
I understand commercial email accounts aren't secure. So I don't treat email as being secure.
Look at what you have here. A pair of half drafted generic position papers. A legal memo about a document review protocol (I carry stuff like that in my unlocked briefcase). And a couple of what appear to be public documents about torture. The most potentially embarrassing thing on there is his SF86. But a quick scan of it doesn't show anything embarrassing on there.
If he was sending actual sensitive information on an insecure email, that is a problem.
But it's your own information, you can do what you want with your copy.
Officials said hackers accessed not only personnel records
of current and former employees but also extensive information
about friends, relatives and others listed as references in
applications for security clearances for some of the most
sensitive jobs in government.
"It is a very big deal from a national security perspective
and from a counterintelligence perspective," FBI Director James
B. Comey said at a meeting with reporters Thursday at the FBI
headquarters. "It's a treasure trove of information about everybody
who has worked for, tried to work for, or works for the United
States government."
[1] https://www.washingtonpost.com/news/federal-eye/wp/2015/07/0...Not sure if CIA held SF86's are considered classified, but even if they are I suspect we won't see anyone, let alone a director, prosecuted for having a copy of their own "classified" employment questionnaires.
I cannot help but hear Tina Turner singing. "What's AOL got to do -- got to do with it? What's AOL, but a second-hand email..."
That aside, it is an indicator toward technology adoption. Despite "why fix it" attitudes, a CIA or NSA director should employ more modern email methods -- PGP or other encryption types notwithstanding. Although I'm not picturing a government top dog dialing up for email, what else am I supposed to first imagine when I hear "AOL" and a related governmental acronym? "We internet chat over AIM"?
(Edit: Oops, Matthew Cole, not Jacob Appelbaum.)
[0]http://gawker.com/5861484/iran-and-hezbollah-caught-all-the-...
If the email content was not encrypted, it'd (most likely) be available in plain text somewhere along its route.
If the email content was encrypted, we wouldn't be reading it now.
I've been going through the details in http://newsroom.grasswire.com and I'm almost completely convinced this is all hot air.
The Iran doc is public, the bill is obviously public. The policy paper is not but it’s also a draft, unclear who even authored or commented on it.
They are all also from a time when Brennan didn't even work for the government.
There is no indication these documents came from a compromised email address, and even less indication that any of it matters other than to say "lol the CIA Director is an idiot." I get that it's a sexy story to say "leaked emails of CIA director," but this is really not a big deal.
Kidnapping and torturing people -- and fancying that you can use bizarre linguistic constructions to either prevent the world from finding out grittiest, literally pornographic details of what you've been up to; or to reduce your own culpability in said crimes -- should preclude you from serving as director of the CIA.
And secondarily, using a public-sector email service (independent of its authentication scheme, or the quality of its implementation) to conduct government business should further disqualify you, as well.
At least I imagined that Wikileaks would want to preserve their reputation as doing something for the public good but a childish move like this focused on a single individual (an enemy in their eyes) makes me question the organization's values going forward.
It seems like you're confusing them with some other organization that does responsible disclosure.
The Cablegate leaks were newsworthy and responsibly handled.
Syrian/Saudi diplomatic emails, Iraq/Afghanistan war documents, Trans-pacific Partnership reporting. These actions bring attention to large groups of people in power and hold governments accountable for their actions.
Publishing the emails from an AOL account of a CIA director doesn't quite fit that mould.
"He did nothing wrong, therefore he has nothing to hide".
Are you really questioning the fact that this was made public while NSA, CIA and other agencies have been wiping their asses with the Fourth Amendment of the US Constitution and the Article 8 of the Universal Declaration of Human Rights?
Running with the Chelsea Manning leak helped start a conversation about the ethics of drone warfare and the culpability of the US military in the deaths of civilians.
What kind of a wider conversation does leaking John Brennan's SF-86 create? Maybe there's some ancillary discussion about those in the security community not using secure channels but it mostly just feels like a cheap shot.
Does it necessarily have to create a conversation?
It, at the very least, destroys yet another time the "nothing to hide" argument and underlines both the fact that nobody is safe unless active measures are taken and that all this spying business is tainted with serious amateurism.
And if this is worthless to you, see it as a backlash. Our personal informations are intercepted on a daily basis and played with in a way that we have no control over. The average Joe, alone, can't fight back, Wikileaks is the collective answer.
It is in-line with Trevor Paglen's work [1] on demystifying spying activities: they're no super heroes, they're bound to physical, practical and logistical limitations (like we all are), we can fight them.
[1] (video) "Seeing The Secret State: Six Landscapes" https://www.youtube.com/watch?v=mF4vQA7eWgE
Russia is anti Saudi because of oil
Pay attention.
They're being co-opted:
http://www.bloombergview.com/articles/2015-10-16/saudi-arabi...
Snowden too. Some of the stuff he leaked was not in the public interest
There could be. There is a reason the government asks there questions because they get relevant information. Hypothetically there could be newsworthy stuff in there.
But there isn't anything actually in there. So it's shitty to leak it.
Assange himself explained the "non-linear effects of leaks on unjust systems of governance[1]".
His rationale is that illegitimate power requires conspiracy and conspiracy requires secrecy.
Therefore, by leaking information Assange makes secrecy so difficult that it cripples the organization's ability to communicate with itself and operate the conspiracy.
The more secretive or unjust an organization is, the more leaks
induce fear and paranoia in its leadership and planning coterie.
This must result in minimization of efficient internal communications
mechanisms (an increase in cognitive "secrecy tax") and consequent
system-wide cognitive decline resulting in decreased ability
to hold onto power as the environment demands adaption.
Hence in a world where leaking is easy, secretive or unjust
systems are nonlinearly hit relative to open, just systems.
Since unjust systems by their nature induce opponents, and in
many places barely have the upper hand, mass leaking leaves
them exquisitely vulnerable to those who seek to replace them with
more open forms of governance.
[1] http://cryptome.org/0002/ja-conspiracies.pdf [pdf]Assange is an archetypical agent of 5th-generation warfare, and Wikileaks is a perfect example of a Robbian superempowered group: http://globalguerrillas.typepad.com/globalguerrillas/2008/02...
And he's winning. He might die, in horrible agony, in an Argentinian embassy, but he'll take the CIA down with him.
What a time to be alive indeed.
* Theres a theory that WIKILEAKS has been a FSB front since 2010: *
https://www.reddit.com/r/conspiracy/comments/3pobtq/is_russi...
They haven't posted a SINGLE ANTI-Russian document since they threatened to leak documents in 2010
This is ONLY about Embarrassing the West.
At first I was skeptical, now i'm fully convinced that Assange and crew are TOTAL useful idiots.
I live in the western world, so that's what I care about.
Any PR victory Moscow can prop against the US hegemony is a win to them.
This is straight out of the Cold War PR battle.
Your comments looks like straight out of the Cold War PR battle.
If I was going to be a whisteblower, or a leaker of state and corporate secrets I would do it for my own country and the countries it was allied with.
What is so difficult to understand about that?
...linking to a post on /r/conspiracy.
There are also a theories, in the very same sub, that drinking is own urine is better the chemotherapy [0], that China has floating cities in parallel universe [1] and that Ahmed Mohammed is a "clock bomb hoaxer" [2].
Please keep on improving our discussion with wonderful sources like /r/conspiracy.
[0] https://www.reddit.com/r/conspiracy/comments/3pp1z3/woman_wi...
[1] https://www.reddit.com/r/conspiracy/comments/3psibh/another_...
[2] https://www.reddit.com/r/conspiracy/comments/3psun2/ahmed_th...
What a time to be alive.
It go so bad we had to ask all the people that printed it if they could bring their copies back when they were done, so we could have a lending library of the Starr report.
My point is, you're right, it's a great time to be alive -- you don't have to tell anyone about your interest in these things. :) (although on the flip side there was a pretty good watercooler discussion of the report at the computer center)
> placing hoods or sacks over the head of the individual or using duct tape over the individual’s eyes;
So using other kind of tape is totally ok (for example).
Of course he knows about the Hillary situation. Since this is the CIA, would it be entirely tinfoil mad-hat of me to suggest that this was an intentional honeypot left out, knowing it would get hacked and the ensuing leak coverage would reinvigorate the debate over Hillary's misuse of private email for official business?
Brennan doesn't exactly strike me as the kind of guy who plays for the Democratic team.
I'm not totally buying that he's really this incompetent, but dragging down Clinton seems a bit far-fetched as a reason this was intentional.
Petraeus and Broadwell used fake names to create free webmail
accounts exchanging messages without encryption tools.
The FBI, using electronic metadata that pinpointed the times,
places and IP addresses, identified Paula Broadwell as the source.
[1] https://en.wikipedia.org/wiki/Petraeus_scandal[0] http://www.nytimes.com/2015/04/24/us/david-petraeus-to-be-se...
So far there is no indication that he's using his personal email as a government work email. In fact, all these emails are from times when he had no government email.
Clinton side stepped her official email to use an off the books private server in an official capacity.
https://www.reddit.com/r/conspiracy/comments/3pobtq/is_russi...
They haven't posted a SINGLE ANTI-Russian document since they threatened to leak documents in 2010
In 2010, they claimed to have a massive cache of information.
Then guess what?
Moscow sent very subtle but real threats towards them.
And their tune hasn't been the same SINCE.
Its well outlined in the link.
The original post was removed. You might want to check that.
The USGovt would never admit this because it might backfire as merely attacking a leaker, whose leaks are legitimate.
But the fact is, Wikileaks has to be judged on what they're not leaking.
And really, don't you think the US gov would push that narrative across all the US media if it learned it was true? I mean, they've been pushing the "Snowden is a Russian spy" story already - and that's not even true.
The USGovt has to be sensitive to the fact that the leaks are real information. But its far more nuanced to prove that WIKILEAKS is just pushing an anti-USA/NATO view.
Look at the Saudi Arabia leaks in light of the fact they're in a price war with Russia right now.
You won't see an Iranian leak on WIKILEAKS..and you haven't.
What about this one: "Assorted plans and papers from the Iranian Ammunition Industries Group, 2009" https://wikileaks.org/wiki/Assorted_plans_and_papers_from_th...
Old people + technology = failure. Really common pattern. We like to believe people in positions of power know what they are doing, but sometimes the facade cracks and we see they are just regular old crazy people.
But, it's more like inconvenience + people + technology = policy violations. In one company I worked at a new CEO was installed (the old one was faulty; turned out the new one was still faulty) and he told people to forward all their company email accounts to their personal gmail accounts because he just liked the gmail interface better.
edit: _gasp_ it's like online people read comments while wearing hair trigger hostility goggles and don't use their contextually aware kindness beanies. go figure!
But please, keep your ridiculous ageism going.
I didn't say "every old person is dumb and invalid and will rot in their living rooms out of stupidity." But, an average 4 year old can use an iPhone better than an average 63 year old.
I worked with an expert on NAND Flash. The guy is brilliant. Knew how the whole process flow works--from substrate to cap layer--off the top of his head. It doesn't need to be said that fabricating semiconductor devices makes setting up an email server look like childs play. Yet, he used a @aol.com account.
Brennan was the daily briefer to Clinton. He was Saudi Arabia station chief. He's definitely a talented guy who knows a TON of stuff you haven't the faintest clue about.
True, but so is young people + technology. Young people tend not to be Secretary of State or Director of the CIA though.
Seems better to censor by deleting unwanted content with prejudice instead of waffling and breaking context.
Eventually we might build more software support for this.
Very proud of my alma mater.