90-year-old Cryptanalytic Efforts Must Stay Secret, says NSA
nsarchive.wordpress.com
nsarchive.wordpress.com
If, for example, the censored paragraph was "a US agent placed within the Soviet Communist Party participated in the design of Soviet ciphers and deliberately weakened them", and that agent continued working in the USSR for several decades, then it could only be declassified if everything that agent had ever been involved with was no longer sensitive.
It's the NSA. It's espionage.
These things tend to be classified by default.
So, I'm not suspicious it's some arbitrary thing, like the type of ham sandwiches agent Boy Scout was eating.
"Classified by default" is semantically equivalent to "knee-jerk reaction". Nobody is claiming it's arbitrary. The claim is instead that it's systematic, and stupidly so to the point where it may well be the type of ham sandwiches agent Boy Scout was eating. Wouldn't be the first time...
It's "classified by default" out of concern for a certain principle, ergo the act of classification is applied in a knee-jerk (i.e. thoughtless, reflexive) manner.
Semantic argument is semantic.
As a concept, it's similar to policies in corporate offices where doors are locked and guests can only walk in through a reception, accompanied by a trusted employee. Yes, you're applying a process that is unnecessary in 95 % of cases, but still it's one of the "best practices" in the business.
The process is as follows:
1) Rational, principled decision: "when in doubt, classify"
2) Conservative application: "I'll just classify everything to avoid 'misses'"
3) Everything gets classified because nobody ever got fired for classifying
Treat it as a signal detection problem. There's obvious incentive to avoid "misses" (i.e. not classifying things that should be classified) so people produce many false alarms (i.e. classifying things that should be public knowledge).
This hi-lights a problem with current doctrine: "classify by default" has unintended consequences, namely a creeping increase in non-transparency.
Further, and returning to the original point: since reflexive classification happens as a result of official doctrine, the two are semantically equivalent and this discussion is officially running around in circles.
Also, just because the originator may be dead, it doesn't mean the work won't have knock on effects.
And finding a hole in security for old material may trigger a search through all newer ciphers - something I'm sure they don't want.
There are plenty of reasons, correct or not, why they may wish to keep this a secret.
That said, there's plenty of reason to believe that some of the things they're still withholding are nonsense.
Seems plausible enough to me.
It's a stretch, but there could be a chain of events that they want to remain hidden. They don't want to hide what happened 90 years ago, they want to hide who did it and what else he may have done in the future or had an effect on.
Except, in the government's case, they are imagining scenarios for me, and my family, and my friends, etc. Their job is to protect us, not speculate wildly FOR us. We didn't elect them to do that, and it's not their job.
If someone is sitting there speaking for my speculations, I'd sure as shit like to know they aren't going to be doing it more than generationally. That's terribly concerning.
My point is that since there are readily imaginable scenarios where it would be necessary to keep this classified, we shouldn't be sitting here accusing them of keeping secrets just for the sake of keeping secrets. The fact that we don't know why it should be kept secret doesn't imply that they don't have a good reason.
True, but when Tom Blanton comes out and agrees that "90 percent" of it doesn't need to be classified, that more than implies they don't have a good reason.
"Readily imaginable" is just blaming based on prior history of the one being blamed. In some cases, the expansion of who can be blamed is easier than the not blaming part. Unfortunate.
And, FWIW, I'm not disagreeing with you here. Just trying to get us out of the knee deep rationalization pit of shit that is the government.
Any supposed advantage we gain by spending our resources and credibility flooding the world with spies is far less then what we lose by having our society, our rights, and our freedoms completely subverted by the primacy of "national security".
Let's replace "The NSA" with "Joe, who happens to work at the NSA, doing a spot check".
Joe, who happens to work at the NSA, while doing a spot check decides to keep redactions in 20-year-old document confidential doesn't sound like as much of a headline, though.
With stuff like this or filling out time sheets/expense reports, it's really clear cut. Employee X signed the form to declassify document Y.
Since people in charge of bureaucracies like to figuratively torture and execute bearers of bad news, it's easier to err on the side of inaction.
And bosses should be held responsible for the actions of their companies / agencies. All kinds of bad things happen if they're not.
At some point I'd love to donate it to the ACM museum or something, but I don't want to get in trouble over a historical document, so I'm just keeping it for now.
Here's the newer instruction so you can see if any of it is applicable to what you found: https://www.fas.org/sgp/othergov/dod/af053006.pdf
Apparently, it's recipe for invisible ink.[0]
§120.50 and §120.51 are marked XXX
§121.1 : e-f and j-w after "Note to Paragraph (d)" in Category IV are Reserved
d and h-w in Category VI are reserved
etc.What the blog post fail to understand is that:
a) Intelligence operations run for years and decades, you wouldn't be hard pressed to find 5 documents over a period of 90 years which are cross referenced / linked by CODEWORD level programmes. So if this document was referring "SPRING CRICKET" which references "SPRINGROLL" which references "CHINATOWN" which references "BOUNCY CASTLE" which might reference "PRISM" for all we know. You don't give people bread crumbs.
b) Intelligence operations involve human assets, even if it was in the 1920's it can still have human assets who are alive or their descendants, and it doesn't have to be a US agent, it could be some soviet mathematician who passed information to the US (willingly or not) that has living descendants in modern day Russia and there is absolutely no reason to colossally fuck up their lives today by revealing that fact.
Declassifying information is a very expensive process you need to do a full impact analysis on every word in every paragraph and cross reference it with any other materials that are revealed, considering the age of these documents many of them might not be digitized which makes this process even more expensive and time consuming.
Beyond that once a document is set for release a very expensive process of document recovery is kicked off, all copies and revisions of the document must be collected to ensure that no revisions other than the approved for declassification and no unredacted copies remain to be found or leaked.
And once you release some document which is redacted if by some coincidence it is missed by the OSINT departments of foreign intelligence agencies some 'BuzzFeed' "reporter" that his next meal of cup ramen noodles is dependant on his daily blogspam quota will dig it up and make a click bait out of it and depending on how sensational they make out to be going to be picked up by some bigger news outlets and by then every counterintelligence outfit will step up their game if only to have a response to this for their next oversight hearing and if they kick their bug sweeps and mole hunts into high gear they might actually find something even it's completely unrelated.
The likelihood of a tool/method/source that has been used in 1925 being relevant today is about zero, the likelihood of them not being able to complete an impact analysis on that paragraph and hence having to redact it or not wanting to get the grandchild of some Russian asset harassed by the FSB the media and the immediate public is considerably more likely.
What a rich history Java has. Wonder if they were developing trusty ol' JavaScript back then too... ;)
Either way, the message is clear: "don't fuck with us."
Tons of stuff is classified, sits in a safe for years and years, and eventually just gets shredded. Probably 99.99% of it. There is a cost to declassify documents, but for the mountains of stuff that never gets declassified (because it just goes into the memory black hole) there is no cost.
Honestly I think there is just a CYA mentality to just slap SECRET on documents rather than trying to thread the needle and figure out the exact correct classification. In theory these documents should be classified at the paragraph level, and in that case things like public statements by public figures would be unclassified even if they were a part of a highly classified document.
People will properly classify things if there is some reason to, but day to day it's not trivial to do and in the end nobody sees their goal as 'get the exact right classification on everything' vs 'find a terrorist or figure out what russia is planning'.
We had a joke that each birthday card has to either go to the security office and the personnel office to get stamped [secret] or straight into the shredder. And that's simply because by the time it goes around and everyone sings it you get a list of individuals, any list of individuals according to the regulation counts as a roster, and all rosters are classified.
The cost of classifying documents isn't in keeping them secret as the only cost of that is your storage space, the cost is in the man hours required to go over each line and paragraph and determine if it exposes any classified material, source or method and then classify it accordingly, beyond that you also have the added cost of tracking the dissemination of classified material as distribution and access lists have to be maintained and approved, copies tracked (most importantly tracked down for EOL/recovery) and you also have to do an impact analysis every time you change the classification or declassify it.
So to simplify things you shred everything you don't want to keep and give the highest baseline classification you/your department is operating under to any other document you might want/need to keep for the future regardless if it's an actual intelligence product or a group lunch order.
This. You have warehouses A, B and C full of documents. Let's assume that B and C are full of birthday cards and stuff that doesn't need to be classified. There's an operational cost to those two warehouses. With classified info it's not just some 12.50/hr security guards and lighting. You have tons more compliance auditing and other policy stuff that pushes up the cost. When some unlikely event finds a bug in your security protocol that results in a revision it costs 3x as much (because you have 3x as much to secure). If it's mixed material there's a huge cost associated with periodically determining what's what. It's no expensive compared to other things but it's a big unnecessary cost. Imagine if FedEx's policy was "employees should be hard on equipment whenever possible". It's not all that expensive compared to employees themselves but broken equipment costs money and slows things down. Classified info is the same way. Stuff should be classified per a "need to classify" standard the same way classified info is shared per a "need to know" standard.
That said, the NSA loves looking for patterns and/or needles in haystacks and may be worried about other organizations doing this to them. It would not surprise me if a lot of the stuff that seemingly needlessly stays classified stays that way to make it harder to build a big picture view. They may see the same kind of scaling problem as the one between non-networked license plate readers on toll booths (few data points, hard to build big picture) networked license plate readers on every police car and traffic light (tons of data points, easy to build accurate picture).
Regardless, there's much lower hanging fruit when it comes to government inefficiently using $.
When you declassify a document you need to go over every word, check if it related to any source or material that cannot be declassified or ad hoc declassify additional material (which is why many times when there is a FOIA request for a document you can get more than what you ask for) go over every codeword and dig up everything that relates to that and run the same process on that material also. After that once you accepted the declassification you go on a hunt and collect all copies and revisions to ensure that there are no copies other than the final "declassified" one.
Declassifying documents is like pulling a string on a sweater you start pulling it and if end up unraveling the entire thing this is why the often redact whole paragraphs and even pages since the effort is too great and you don't want to risk leaving breadcrumbs. Counter intelligence and OSINT agencies often practice on investigating declassified material and to see if they can gain any "unintended" intelligence from it and often they do and the declassification procedures are updated.
Governments need some level of secrecy to run, the level is dependant on the department and the subject but it secrecy is important none the less, people often don't realize just how many things can easily be screwed up by a tiny leak.
"Leaking" small pieces of information that doesn't seem relevant, over time, might help someone construct/discovery something big.
Example,exagerated: person A studies genetic deficiences. Person B studies some new yeast. Person C works as voluntary in vaccination campains in Asia. A "dinner receipt" gets desclassified revealing that now they are working together. A person D, Asian descendant, dies with some new untreatable disease while working with the former 3, and his death is also declassified with more details than necessary...
All these facts with a 10 year span. Could ring some bells, no?
[0] http://www.npr.org/sections/thetwo-way/2014/05/20/314231260/...
Polio vaccination in Pakistan is utterly hindered because the "village elders" and the usual suspects spread nonsense that the vaccines were donated by Israel and it's a Zionist propaganda to turn the male population gay and sterile.
After that, it gets vented out through at least three different chimneys--with armed guards on each one, to shoot anyone that sniffs too deeply.
All because of something that probably happened in the 80s, when someone was able to recover secret information from a paper document that had been burned in an insecure way. I mean, if the Soviets could eavesdrop on a mechanical typewriter, and all methods and practices are always classified on all sides, how would we ever know whether anyone can use packing tape and a relatively abundant type of medical scanner to read words off a burned page or not?
(the fictional portions of this post are based on an amalgam of true stories)
So they're holding out for ... indescribable damage? ;)