How can these top government officials be so clueless about email security when they know first-hand how effective our own intelligence agencies are at reading everyone's email?
How can these top government officials be so clueless about email security when they know first-hand how effective our own intelligence agencies are at reading everyone's email?
I understand commercial email accounts aren't secure. So I don't treat email as being secure.
Look at what you have here. A pair of half drafted generic position papers. A legal memo about a document review protocol (I carry stuff like that in my unlocked briefcase). And a couple of what appear to be public documents about torture. The most potentially embarrassing thing on there is his SF86. But a quick scan of it doesn't show anything embarrassing on there.
If he was sending actual sensitive information on an insecure email, that is a problem.
But it's your own information, you can do what you want with your copy.
Officials said hackers accessed not only personnel records
of current and former employees but also extensive information
about friends, relatives and others listed as references in
applications for security clearances for some of the most
sensitive jobs in government.
"It is a very big deal from a national security perspective
and from a counterintelligence perspective," FBI Director James
B. Comey said at a meeting with reporters Thursday at the FBI
headquarters. "It's a treasure trove of information about everybody
who has worked for, tried to work for, or works for the United
States government."
[1] https://www.washingtonpost.com/news/federal-eye/wp/2015/07/0...Not sure if CIA held SF86's are considered classified, but even if they are I suspect we won't see anyone, let alone a director, prosecuted for having a copy of their own "classified" employment questionnaires.
I cannot help but hear Tina Turner singing. "What's AOL got to do -- got to do with it? What's AOL, but a second-hand email..."
That aside, it is an indicator toward technology adoption. Despite "why fix it" attitudes, a CIA or NSA director should employ more modern email methods -- PGP or other encryption types notwithstanding. Although I'm not picturing a government top dog dialing up for email, what else am I supposed to first imagine when I hear "AOL" and a related governmental acronym? "We internet chat over AIM"?
Albeit, a very unquestioning & gullible one?
[1] It was a really dumb bypass, too: Client: The authN methods I support are: [empty list]. Server: Ok, let's just skip authN.
But that doesn't mean she actually had VNC or RPC software actually listening on those ports, or that the software that was listening (whatever it might be) was actually vulnerable. It might be more likely than not that it was vulnerable--I mean, that's why security people look for things like that to begin with--but false alarms aren't exactly uncommon, either and my customers have proven to me that there's no shortage of bizarre server configurations in the wild.
Server: I support the following auth methods ["password"]
Client: Cool, let's use "none"
Server: Okay.
I agree this all is testament to widespread cluelessness, but more on the software industry level...
PS: I also wonder how this worked in practice. I mean I would assume top officials spam rules where setup to ignore hillary@somerandomdomain.org due to spoofing if nothing else.
Quite interested, as I've been watching this one closely, especially with regards to retro-active changes allowing for an escape from previously committed illegalities.
I fully expect a presidential pardon to be the end-game on this one.
Hillary Clinton's use of private email not unusual, but still raises questions. http://www.latimes.com/nation/politics/politicsnow/la-pn-hil...
Other government officials, and Secretaries of State before her, had also used private email for official business, and experts agree that this is allowed by federal law in case of emergencies.[25][8][26] The State Department declined to answer questions about whether the private system was widely known within the agency or officially approved.[21] https://en.wikipedia.org/wiki/Hillary_Clinton_email_controve...
Even my public University's president used a personal account in order to avoid student activist groups getting his email.
Sarah Palin used personal email (I think also AOL, actually) in her tenure as governor of Alaska.
Everyone, on both sides of the aisle, and all the way up and down the hierarchy does it. Absolutely everyone. Probably everyone has at some point in time. Probably even Bernie Sanders.
If you want to find out who, start sending FOIA requests and see what comes back empty.
So that excuses it, right? When a bunch of people that don't matter do it, you're right, I don't give a shit. When it's our Secretary of State, one with access to all kinds of Top Secret material, I do however very much give a shit. If national security regulations don't apply to our top leadership, then what the fuck do we have them for?
The reason those laws are there is exactly for people like top leadership, because you and I aren't going to run across top secret documents in our day to day... UNLESS some asshat does something stupid like this.
Scope of damage is an important concept when it comes to government versus private sector. Scope of damage for private sector is a "Sony" - possibly implosion of the company, but it generally stops there. Government however is the safety of every citizen in the affected country.
HUGE differences on the damage scale.
Did I say that, `zer0defex`?
>When a bunch of people that don't matter do it, you're right, I don't give a shit.
Why not? Do you think that local government and other public servants should be able to hide corruption, suppression of dissent, or other unsavouryness behind personal email accounts?
>HUGE differences on the damage scale.
The only thing on the scale is that our entire political system is corrupt.
That said, the focus on Hillary is a function of right-wing media hacking, and I think it's important to note that EVERYONE DOES THIS, THE WHOLE SYSTEM IS FUCKED, etc..
Some of the laws in question here carry prison time:
http://www.npr.org/sections/itsallpolitics/2015/04/02/396823...
It's very common for senior execs to play all sorts of games with email. If you see folks carrying legacy Blackberry devices today, they are doing something similar.
No one has been able to convince me that the exchange servers run by state are inherently more secure than her private exchange server was.
The open ports are what one would normally expect to see open, based on what I'd read even.
(Edit: Oops, Matthew Cole, not Jacob Appelbaum.)
[0]http://gawker.com/5861484/iran-and-hezbollah-caught-all-the-...
I've been going through the details in http://newsroom.grasswire.com and I'm almost completely convinced this is all hot air.
The Iran doc is public, the bill is obviously public. The policy paper is not but it’s also a draft, unclear who even authored or commented on it.
They are all also from a time when Brennan didn't even work for the government.
There is no indication these documents came from a compromised email address, and even less indication that any of it matters other than to say "lol the CIA Director is an idiot." I get that it's a sexy story to say "leaked emails of CIA director," but this is really not a big deal.
If the email content was not encrypted, it'd (most likely) be available in plain text somewhere along its route.
If the email content was encrypted, we wouldn't be reading it now.
Kidnapping and torturing people -- and fancying that you can use bizarre linguistic constructions to either prevent the world from finding out grittiest, literally pornographic details of what you've been up to; or to reduce your own culpability in said crimes -- should preclude you from serving as director of the CIA.
And secondarily, using a public-sector email service (independent of its authentication scheme, or the quality of its implementation) to conduct government business should further disqualify you, as well.