In other words, "don't think that because Hillary can get away with it, you can, too."
In other words, "don't think that because Hillary can get away with it, you can, too."
It means: Although we recommend against criminal prosecution, we're not saying that this won't warrant some kind of sanctions. But this document is discussion criminal prosecution only, so we're not going to comment on or make a decision about what those sanctions might be.
I suspect they're saying that because those sanctions would come from other organizations and are not a part of the FBI's purview.
They are not saying "Hillary gets away with it, but you won't!"
In other words, politicians don't have the same career consequences for these types of things due to the transience of their postings.
I have not read the law that discusses whether a person in this situation is eligible to be stripped of clearance.
Should be interesting whether she is cleared for the security briefings while running for President, though.
I don't think short of impeachment, there is any mechanism to prosecute a President, or is there?
Seems like that's reinforced by this line as well (emphasis mine):
>> Although there is evidence of potential violations of the statutes regarding the handling of classified information, our judgment is that no reasonable prosecutor would bring such a case. Prosecutors necessarily weigh a number of factors before bringing charges. There are obvious considerations, like the strength of the evidence, especially regarding intent. Responsible decisions also consider the context of a person’s actions, and how similar situations have been handled in the past.
Has there been anything like this before? If I work for the government and forward confidential and secret emails through to a server I'm running myself I imagine I'd have criminal proceedings against me.
not even close. he had a personal aol account he used to test internet connections abroad. he had separate classified and personal lines going into his office, connected to separate devices.
[1] http://www.nytimes.com/2016/02/05/us/politics/state-dept-cla...
[2] http://mediamatters.org/blog/2016/03/07/state-dept-concludes...
[3] http://www.politifact.com/truth-o-meter/statements/2016/mar/...
he personally reviewed them and said he has no idea why they are marked classified, and they shouldnt be.
sounds like politics to me.
And if you vote for HRC, you're endorsing this POV. Though, at this point I'm willing to believe that at least half the country has no problem with it.
Bill Clinton got a blowjob and lied about it.
George W. Bush invaded a country that had nothing to do with 9/11 and created a 13 year mess that has culminated with the creation of ISIS.
Hillary Clinton mishandled some classified e-mails.
Bill looks kinda odd in this list. i like the guy, he lived good life.
I also think that +50% of voters electing her president should override that concern if she wins this election. But that's not because I think the law shouldn't apply to her, its because I think the president needs access to classified material.
Being elected POTUS automatically gives you the highest ranking clearance, end of discussion. You could have been a convicted felon with your security clearance stripped and no chance of getting it back, the moment you become POTUS all of that becomes irrelevant for your term.
Of course, this won't make much of a difference to her partisan detractors. Haters gonna hate, and the email scandal is not so much reason as excuse for most of the people who already oppose her. But if she is elected, of course she'll get full presidential security clearance. To do otherwise is stupid.
What matters most to me is that we make changes in both policy and process so this doesn't happen again - policy in that it becomes crystal clear that private email for public business is unacceptable, and process so that the "If you can do your job, we're not doing ours" vibe of the info security world doesn't make the Secretary of State (or anyone else) feel like they can't do their job properly using the official channels.
Certainly so. I'm not sure the same is true of the idea that someone with a proven record of such a careless attitude toward security should be denied the presidency on that basis. That seems like a discussion worth having, although, given the modern political climate in the United States, not one likely to actually occur in any way that's even marginally useful to anyone.
There is no technical reason that a privately administrated email server would be inherently less secure than a government-administrated server (there are good arguments that it's likely to be more secure). However, a private email server is likely to be far more user-friendly and free of "security theater" constraints. Speaking from experience, the usual approach of government and other large organizations to "security" is to throw user experience out the window, forcing ugly/retro "proven" tech on users, requiring complicated and difficult administrative steps to use the system, slow approval and ticketing processes, etc.
The primary job of the Secretary of State is to communicate. Any time wasted on arbitrary tech hoop-jumping, any restrictions on how that communication happens, is keeping the SoS from doing their job. Can you imagine if we were in the middle of a political crisis and suddenly the Secretary of State is on hold with tech support while dealing with a forced password reset or something equally stupid? American lives at risk, and Lotus Notes is the only way to communicate? Etc. See the issue here?
To really resolve the problem, they would need a relentlessly service-oriented approach for whomever is responsible for email at the State Department. It would have to be as friction-free an experience for the user as possible, within the boundaries of security.
Until then, every Secretary of State is going to put their ability to communicate quickly and easily with the most important and powerful people in the world ahead of the kinds of technical wank that the average HN user thinks is important.
There are technical reasons that SIPR and JWICS communications are more secure than a private server. Mostly related to air-gaps and physical key infrastructures.
Secondly, the correspondence in review is internal and not so much related to the external communication role of the SoS. In this specific circumstance, the SoS chose to forgo the security apparatus for internal classified communication for something more user friendly.
*baring some sort of store and forward.
> the kinds of technical wank that the average HN user thinks is important
includes whether or not the details of diplomatic communications at the highest level of our government are trivially available even to middle-tier private actors, to say nothing of potentially hostile states. Call it "technical wank" if you like, but information security exists for a reason, too. Can you imagine if we were in the middle of a political crisis and suddenly most of the Secretary of State's electronic communication is freely accessible to the same people with whom he's trying to negotiate an outcome favorable to the United States? See the issue here?
I totally get what you're saying with regard to user friendliness being a primary concern at this level, and I agree with it. I don't agree that the proper response to UX concerns, however difficult, is simply to throw security to the winds in the cause of easing communication - because security is a primary concern at this level, too.
Moreover, the security of individual emails depends on the security of the recipient as well as that of the sender. Sensitive/classified emails sent to officials of non-US governments are subject to whatever security they might have. The only solution to this leak vector is to completely ban email as a means of communication - which gets right back to the core requirement that the Secretary of State must be able to communicate quickly and efficiently.
I'm not arguing to "throw security to the winds", and I don't think that's what was done here. Again, I'm asserting there's no reason to believe an email server administrated by the State Department would be any more secure than an email server administrated by skilled private admins.
You're also conflating the responsibilities of State Department personnel with regard to information classified by the government they've sworn to serve, and the responsibilities of other nations' diplomatic personnel with regard to information originating in the government of a state foreign to them.
Neither seems especially conducive to a useful discussion of the matter at hand.
More to the point, shadow IT exists for a reason. Taken out of the context of the State Department and the political sphere, this was classic shadow IT. I've used shadow IT, and I've provided shadow IT, because I've worked a lot in large, sluggish bureaucracies, and that's How Things Get Done sometimes. "Security" becomes a catch-all excuse for laziness and cowardice.
If she felt like she could do her job with the existing State Department tools, she wouldn't have set up a shadow IT operation, period. It's not like she's completely ignorant of either operational security or political ramifications. To do this, she must have felt thoroughly hampered by the existing system.
Sticking around at the expense of her oath of office doesn't seem to have worked out all that poorly for her, since she's still apparently a serious contender for the presidency. Should she end up in it, one hopes she'll take that oath a little more seriously than she did the last one.
I'd say she won.
https://www.washingtonpost.com/news/checkpoint/wp/2016/01/27...
I found that one, but I was looking for a case with an Army General had lost his clearance but kept his job...
I'm not sure what clearance the Sec. State gets, but as President she wouldn't need any clearance as the power to classify material stems from her office.
It pretty much boils down to contact FBI CI (https://www.fbi.gov/about-us/investigate/counterintelligence) or the CI agents on base (if it happened on a military instillation.
For instance, you can know any two of the following and it might only be FOUO (for official use only):
When a military deployment will happen
Where it will be to
Who will be going
But all three, together, are considered classified. (Trivial case, usually not this small a data set, but this is the concept.)The result is that someone gets apparently safe information from several sources. They put this into a briefing, or talk about it at the bar. The accumulated information is now considered Confidential (or higher), but was developed entirely from non-Confidential (or higher) sources.
>>Where it will be to
>>Who will be going
Having all three aggregated is not classified, but it is critical information (AR530-1, para 1-5, section b(2) [1]). An entire deploying unit is given those 3 bits on information, but the entire unit rarely is 100% on security clearances. EXAMPLE: when 2BCT,25ID deployed in 2004 the entire unit was told when they were deploying and for how long, where they were going, and who units/personnel were going; everyone including that fresh 18y/o 11B PVT that graduated BCT 1 week prior were told.
But yes I agree with you on the first statement about information aggregation.
Unlikely. You would lose your job for sure, but typically for a criminal prosecution to result there has to be an element of willful unauthorized disclosure of classified info, or very high impact of the disclosure of classified info.
In practice this means that the people who get prosecuted have almost always been people intentionally sharing secrets with foreign entities (spying).
I only know of one case where charges were brought against someone who was not doing that. It was when the feds retaliated against Thomas Drake for whistleblowing against the NSA. Even then the charges got dropped.
He took photos of a sub he was stationed on, apparently just for his own use, with no intention of "spying" He's going to jail for a few years.
https://www.google.com/search?safe=strict&q=kristian+saucier
or flag it NSFW - when I clicked it, SafeSearch bounced me to the one I just posted. I'm actually at work, so don't intend to investigate, but my guess is "Kristen Saucier" is a different person in a different line of work.
Be that as it may, cases like Saucier's are fairly rare. It happens, but it's the exception rather than the rule.
Also, it's not like it was secret at the time. Refuge in audacity may seem like an odd defense, but for stuff like this it's actually relevant. I mean if they did try and prosecute it would come off as completely politically motivated.
PS: If you disagree feel free to comment why.
Simple. Because politicians transfer from the legislative branch to the executive branch. They (generally) don't entered the armed forces. If they did, I'm sure they'd make sure they have equal protections there as well.
Who approves this nonsense? This statement, his bald-faced lies to Congress during the Apple unlock testimony. We (as in, We, the People) need a housecleaning at the FBI and we need it fast.
We have always had a two-tiered justice system and advocates working against it, but if it becomes accepted as fact like this, how can the public keep faith?
Edit: Please, nobody misconstrue what I wrote as me supporting either party. I personally think, given the two candidates we have to choose from, that the U.S. is in a world of hurt.
In some sense mooted by her not being at State at the moment. On the other hand, could be interesting to walk into the presidency having security clearance issues. (Not to say that that would necessarily be a big deal.)
Yeah, the whole statement had bits like that thrown in and its a terrifying example of corruption simply because its basically an admission:
A) Clinton gets special treatment because she is politically popular.
B) She stands a good chance of being President solely because A shields her from any criminal charges that would be leveled against someone without A.
A shouldn't happen and the fact it leads to B is horrifying because its clear the political class, wealthy class will always receive special treatment unless there is a landslide rebellion that blocks her from the Presidency.
Taking out a major-party presidential candidate during the general election season is going to have very unfortunate implications for the way US politics works. Just imagine in 2020, when President Trump decides to have his re-election opponent investigated and orders an indictment during the general election season. Except that in 2020, it will be a targeted removal and not simply a coincidence. I don't want to live in that world, and indicting Clinton now will lead to that world.
> Taking out a major-party presidential candidate during the general election season is going to have very unfortunate implications for the way US politics works. Just imagine in 2020, when President Trump decides to have his re-election opponent investigated and orders an indictment during the general election season. Except that in 2020, it will be a targeted removal and not simply a coincidence. I don't want to live in that world, and indicting Clinton now will lead to that world.
Bullshit. You just have someone else run for the Democrats.
The General isn't until after the Convention (which hasn't happened and wouldn't until 7/25, fyi) and they could have just said someone being indict'd was too much risk and they'd have to go with someone else.
I think this represents ignorance on the way the system actually works. (i.e. She isn't officially a general election candidate until the Convention, merely the presumptive nominee until that point. )
But this is politics through and through, so I flagged the article in any case.
Obviously if you are of .gov employ, you should not do this.
I do have my own email server, cloud server, etc hosted on DO and don't work for the government. But I have two phones, one for work and one for personal and do not mix work/personal data.
Relevant mail-in-a-box link https://mailinabox.email/