US Intelligence director’s personal e-mail, phone hacked
arstechnica.com
arstechnica.com
Why do you think President Clinton setup a private email server in the first place? The law was signed just before his presidency and he was advised of this.
Why is it that sealed arrest records are not actually sealed?
But you don't want that stuff sitting in a court record that anyone can walk in off the street and ask to see. So part of the record get sealed - not available to the public. It's still available to the judge, and to the (outside) counsel for the other side, and to the appeals judge if things go that far.
And only certain details get protected. One side has to ask for it, and the other side can protest, and the judge has to weigh the protection for the side that wants it sealed against the interest of the public to know what went on. More, a redacted version is (usually?) released eventually.
Why there isn't a proper threshold cryptosystem and chain of custody of keys for sealed records? Well, that's a different question. The answer is probably along the lines of "the justice system doesn't get tech" or "the people who could demand this don't know about it or don't care enough" or even "thus far the implementation has worked ok...".
That said, someone in the military looked over the case and oked your friend. Someone knew. A judge cannot force the army to take someone they don't want, nor hide information from them. The army is also not a dumping ground for criminals. Someone saw value in your friend, something that the military could use. He probably did well. Most young recruits from such alternative enlistment paths work out great.
If you could care less then that means you must already have some level of care.
If you couldn't care less then your current level of care could not be any lower which effectively means that you don't care.
Then it turns out the only real guard is "What high school did you go to?" and "Who was your favourite teacher?"
Assuming senior intelligence folks practice good tradecraft is a little like assuming that the CEO of a software company is a gun programmer. Often not true, and sometimes for good reason.
When you're powerful (or rich) enough to be on the winning side of the political and justice systems, your independent and individual security is much less of a priority. The system will take care of you.
Scooter Libby was disbarred. Edward Snowden is stuck in Russia.
The competence of politicians with technology has always been abysmal.
This assumes that companies do a great job of preventing hacks. They don't.
Brian Kreb's paypal account was hacked last month[1].
http://krebsonsecurity.com/2015/12/2016-reality-lazy-authent...
2) At that point, the competence of the provider isn't the problem.
That's still hacking.
Hacking to my understanding is exploring a system of rules, learning them inside and out and using those rules in expected and unexpected ways to control the system to your own desired effect, which may be constructive or destructive in nature.
I grew up during a time when individuals were doing this with the phone system and computers and other technologies and this included understanding and utilizing social dynamics and interaction to achieve a desired effect, usually gaining access to information that could be leveraged towards further hacking.
And I also take issue with term hacking meaning guessing the password or obtaining it with social engineering or con art.
Actually having to deal with people would most certainly not be considered hacking, under my definition.
Has your bank been hacked?
1. Issue iPhone with finger scanner for MFA for all important access. This works so easy that it would be hard for someone to screw it up.
2. Setup home networks to always use secure tunnels ( custom routers with openvpn settings, Etc).
3. MFA all accounts.
The key is to make it so easy to do things the right way that it's hard to mess it up.
Honestly, do you think these people really care if their Facebook gets hacked or the chain letters passed around by their family members get leaked?
For the really important stuff, they don't even cell remote access. You have to do everything at a secure location.
Since when?
I agree it should be the policy, but it's not. Evidenced by Hillary Clinton's scandal[1], as well as the recent Director of the CIA[2]. In neither case (so far) has the individual been punished. In Hillary's case, the State Department is even siding with her use of private email for official business (including recently discovered classified documents with the header deleted [3]).
[1] http://www.businessinsider.com/fbi-hillary-clinton-email-inv...
[2] http://fortune.com/2015/10/22/cia-aol-email-hack/
[3] http://hotair.com/archives/2016/01/11/hillary-by-ordering-id...
Before you roll out any tech fix, you need a policy fix:
"If you use you personal accounts for any official business, you will be terminated and held criminally liable."
EDIT: If someone from the USDS sees this, perhaps mention it to the US CTO and POTUS. I hear executive orders are a big thing for the next 12 months.
https://www.schneier.com/blog/archives/2015/10/stealing_fing...
http://www.theguardian.com/technology/2014/dec/30/hacker-fak...
For example, on an iPhone 5s and beyond, the fingerprint doesn't decrypt the phone, it unlocks the secure enclave which decrypts the phone.
https://technet.microsoft.com/en-us/library/cc512578.aspx
Also, AFAIK, you cannot be compelled at this point to provide a PIN/password (short of the rubber hose) but someone can just use your finger to unlock a phone. Yes, tradeoffs but the convenience factor is not worth it IMO.
Yes. Lets use a closed platform controlled by a single private entity to ensure the safety of all sensitive government data.
Or how about not. Open-source must be a requirement, and then (sadly) Android is the only option.
That said, it does support full disk encryption and use of finger-scanners too, so it's not like you would lose security capabilities.
Sure. I bet this isn't actually their work.