NSA contractor indicted over mammoth theft of classified data
reuters.com
reuters.com
Only a crazy Intel officer would leak damaging privileged info to the press given the amount of money they invest in counter intelligence.
This is the line General Petraeus crossed. No info goes to the press that results in uncontrolled blowback or merely for personal gain.
But otherwise taking info out like a hoarder is just really bad security and a different matter that should be considered within that context.
>The leakiness of the Trump White House has been a boon to the press corps, who find themselves feasting on the juicy insider details that were hard to come by during the “No Drama Obama” years.
http://thehill.com/homenews/administration/318621-trump-whit...
This seems to have spanned 2 decades and was a much larger trove of docs. Petraeus certainly avoided much more substantial punishment due to his position but that doesn't make this incident legit.
Or if we are to swallow the intended implication of the article without much investigation. The hot-button term "steal" doesn't fit how an average person would describe the situation even if "theft" is the charge he's facing.
This is the contractor who was hoarder. He took documents home and kept them. There's no implication he did anything beyond keeping them and considerable reason to think he very intended to keep the information otherwise secret.
Sure, it was a violation of protocol. It was a potential disaster if some entity found out and could take advantage. But so far, there's no implication of any information being leaked.
Do I think this is the "official story", No. Of course not. But in terms of actual national security threats; not just the ISIS/Russia/ect propaganda-- a contractor bringing home terabytes of data is worrying. This is actually a huge threat to NatSec. This isn't whistleblowing this isn't treason; it's incompetence. Whether this is where the shadowbrokers kit came from or this is a patsy, this is irresponsible.
The information this guy had is almost certainly leaked. Whether he had a "convenient" penchant for bringing his work home and became the fall guy, or whether his home was compromised, or whether he outright sold them, its obvious this was dumb.
I don't love the NSA/FBI ect. But they are gonna do what they do so they might as well do it securely.
It's especially interesting to me because I'm currently writing a novel that involves an NSA employee, and in my novel any bags are controlled for documents and electronic devices at the entrance to NSA Headquarters, Fort Meade, and employees have to go through airport-like scanners both when they enter and exit the building. Obviously, this is fantasy and I've never been there.
Am I being unrealistic? Should I instead assume that everybody with a green employee badge can just walk in and walk out with a trove of documents under his arm, as long as they are in a nice envelope?
Also, I should mention that I feel sorry for Harold. He just seems to be a pathological hoarder with no evil intentions.
http://boingboing.net/2016/10/20/nsa-contractor-harold-thoma...
I cringe thinking NSA would have DVD-burners connected to any machine on their campus. Sure in their labs they probably have every device ever made -- strictly labeled and used only for hacking. But it would be asinine to have their "corporate" machines equipped with them. I bet he either used a microSD card or just put HDDs in his pocket.
Equally, what's to stop them being in the know of exactly what he's doing and abusing their privilege to allow him to do it? You assume he's acting alone... what if he wasn't?
The best lies contain elements of truth... or are almost entirely true. Find a legit reason for bypassing security and while you're bypassed, abuse it without getting caught.
Because violations and exceptions to policy are logged and those logs are periodically audited. There is a process for achieving access with an exception to policy for various approved reasons. Deleting entries from access control logs requires an accomplice that doesn't mind jail time. At some point this starts to sound like a crazy conspiracy theory.
I find the most simple answers are generally the most probable. Let's not forget this went on for nearly 20 years and security staff gets rotated.
$ echo 20*10 | bc
200
Funny counting indeed. <g>My guess is he was addicted to "stealing", the same way some people shoplift for the thrill. It can feel empowering to steal because it gives the thief control. So subconsciously he's thinking "huh, NSA thinks they're so tough and powerful, but look how I can break their rules right under their nose and they can't even figure it out". Or perhaps he exfiltrated people's phone calls/emails. Thats another power theory: "I'm as big and mighty as the NSA because I can tap communication lines and invade privacy just like they can".
Like others in this thread, I dont think he was a spy. A spy wouldn't hoard shit in his basement that could get him life in prison. He would have stolen it, sold it, and GTFO.
A spindle can hold 100 and you get more than 4 of them per cubic foot. So call it 15 cubic feet of DVD's that's basically just a single plastic tub. Granted, more than that with CD's and less than that with Blue Ray disks. But, if he took burnable DVD's home regularly.
Anyway, it would be interesting if he had a fetish for this stuff, wanted to sell it, or was just being really stupid.
PS: Only idea I have for a dumb, but plausible explication is if he was backing up his classified work laptop every week or something.
*edited for grammar
My wife works in electronic discovery, processing huge caches of corporate documents for complex litigation. 50tb is a lot of data but it's not that much in organizational terms. From what I remember when her firm was processing material for the SEC-Goldman Sachs litigation over the financial crisis (a case which involved several years of discovery work), they were dealing with a roughly similar quality, 30 or 60tb of data. I've got an unopened 5tb drive sitting right here on my desk.
No offense, but I feel you're arguing against the existence of large trucks because you've never had any reason to drive one.
You think they would be watching everything like a hawk.
You would, but in my experience managers pay about as much attention to IT people as they do to the janitors. That goes double for contractors, because the buyers tend to assume security screening and so on was built into the terms of the contract. At one point I was the only IT guy for a small private bank in London; I was contracted to work for Digital Equipment Corp, who in turn had the corporate contract with this bank due the contractual arrangements between DEC and the much larger corporate parent of the private bank.
I got the job because their existing guy fired or quit in a hurry or something and they were desperate. Technically it was easy, I just ran backups, did a few service calls around the office each day if anyone had a problem, and most of the actual work consisted of passing on the bank's procurement requests to the DEC people. Eventually I lost the gig because the bank got sick of dealing with DEC and terminated the contract but I got glowing personal references which was nice.
I remember being sort of amazed at the degree of freedom I had. As you may know, small private banks cater exclusively to the ultra-rich, and I was the only IT person on site and had total access to anything. If I were more financially oriented I could have enriched myself in any number of ways.
I'm not saying that companies don't have 50TB of documents, or that you cannot transfer 50TB, either via the network or physically. I am saying that for a place which prides itself as the "National Security Agency", they should have extremely tight security about transferring 50TB of their crown jewels, either via the network or physically. So, I think we are talking about different things. Goldman Sachs and DEC are in totally different ballparks, or should be, compared to the NSA.
I don't really care either way. I just think logistically this is a crazy amount of data for someone to walk off with at a place that should be the model of a secure site.
I'm sure they do have elaborate security procedures but the size and scope of the organization means that any operational issue (including security) is almost always Someone Else's Problem. And since the NSA's purview is basically ELINT + crypto, they don't have the same sensitivity to more traditional espionage methods that a HUMINT organization like the CIA does.
Incidentally I'm thinking of setting up an OSINT entity if you're interested.
I have a vision for the post-web environment, but it's inchoate and will take many years to realize. In the more immediate term, I want to build a prototype and use it to thwart my political enemies :)
same name at gmail for anyone who's interested.
Does anyone monitor amounts of data transferred? Honest question, I don't know of any ACL levels that say 'after x MB, deny access' (or send alerts or whatever). You monitor/restrict directories or servers, i.e. pieces of information, whether they're 5KB or 5TB (I mean, that's what I've seen, I'm not in opsec/admin myself). Still you'd need to make several trips to take out that much data; although you can fit 6GB on a $35 LTO tape...
It also alerted if in the last hour more than 80gb was moved around.
I would have thought that the NSA would have similar policies...
Should have been done 20 years ago. An intrusion detection switch and restrictive policies to lock down hardware access is all you need for a first line of defense. All 1990's tech.
And remember, even the best systems can be socially engineered. With patience and cash there is no door that cannot be opened.
Or 100 512GB micro SD cards which are available to consumers; say 5 a day for a month...
Physical exfiltration is not the problem.
If you don't know how the NSA works why on earth pretend like you do?
> It was allegedly all kept on computers and drives at Martin’s Glen Burnie, Maryland home.
[0]: http://www.theverge.com/2017/2/8/14555238/nsa-leak-indictmen...
What does huge storage array even mean in today's context? I recently built a 20TB server at a price point less than a new 13" MacBook Pro for personal use that occupies a cross section the size of a notebook sitting at the edge my desk...all from commercial-grade hardware that's been on the market for at least 2 years. I would think that the home setup of any serious professional engineer who has been in industry for the better part of my adult life would have some sweet kit up his sleeves.
Imagine this: authorities confiscate anything that looks like storage media, storage capacity rough order of magnitude is calculated, figures reported to media, an assumption is made that it's all highly classified, spin some click bait article.
We're talking about a civilian contractor from private industry who supposedly played an "advisor" role, not some intern whose shoulder was constantly being looked over.
I'm not calling outright fibs here but we're talking 10 2TB sata's here or what?
I'd take maybe a 1U with SFF's, but then again I've not seen how big your laptop is ;)
edit: yep, ok, I missed the words 'server' and 'cross section' there and thought you were talking about some magic home setup...... apologies and: doh!
How much do those cost?
I guess that's a kind of expensive setup for what's being suggested was his home setup though?
20TB in a mirror is cheap as in the DC, at home I've not pushed above about 5 (don't have that much data and thus won't spank so much money on capacity)...
Are you running these things?
This remark suggests that you know the location(s) of where the data was exfiltrated from. It also suggests that you're intimately familiar with not only the exfiltration sites' OPSEC and COMSEC procedures, but of a particular government contractor's as well. Moreover, it suggests that the reported amount of exfiltrated data is unquestionably accurate. Do you see where I'm going with this?
For the sake of curiousity, how would you describe military-grade security, and have you ever legitimately handled classified information in a secure enclave?
The whole system runs at 'system high' mode, both computers and people, which is that everything with access is trusted, on penalty of prison time if you even make a mistake. Events are logged but not necessarily verified in real time. There are no metal detectors or routine cavity searches. The risk of leaks is treated by compartmentalisation of information.
There are a few fields, like crypto, where special hardware is used to handle data (e.g. KYK fill devices), but they would be the exception. These techniques were implemented after the Walker spy ring leaked all the USN keymat to the USSR for decades. Its typical that innovation was only allowed to occur in response to a problem. Who is to say the Russians/Chinese/* have not been paying an insider for the same access that Snowden had?
He had to get it out of there somehow, and everything you listed has much higher mass/volume per terabyte than ordinary platter drives. That's why we're confused. (Possibly excepting magnetic tape backups--I'm not sure if they're still smaller than the equivalent hard drive--but you need bulky, very slow hardware to write them.)
Can I buy a vowel as to where there is? Apparently, everyone else seems to be confidently in the know, along with an intimate familiarity of there's OPSEC and COMSEC procedures.
The indictment also alleges that Martin stole documents from U.S. Cyber Command, the CIA and the National Reconnaissance Office.
Why not the office(s) of USCC, CIA, or NRO? Why not internally within BAH itself?
...If he stole data from the NSA, where would it have been besides an NSA office? I mean, he didn't get it from the Tooth Fairy. > Why not the office(s) of USCC, CIA, or NRO? Why not internally within BAH itself? There's an "also" in there. He stole stuff from the NSA, and some other guys too. And all of them should have had the same level of security, so that doesn't really change much.
I was thinking along the lines of “50 terabytes of data seized, some of which may be stolen classified info”, but I agree that your version of events are more likely.
Is it really though?
Probable? Sure, of course without any quantitative measure.
Likely? I simply can't convince myself of that given we know absolutely nothing of the security measures this guy had to overcome to exfiltrate the data he had.
I'm _pretty_ sure that's not how he got the data out. 18 CDs every working day for 20 years? Nope.
(A DVD pile might only be 50 feet high, but they almost didn't exist 20 years ago - certainly not at "I'll just fill up three of these every day at work" prices.)
;-)
Did you even pause for a second to consider that 50TB may be a grossly misrepresented figure, or digest the parent comment to size up the context of my remark?
(Apologies if you thought I was taking you out of context disparagingly - there's some gross misrepresentations here by people including me...)
They probably do...but...as they say, "locks keep honest men honest."
At some point, you have to have a level of trust that exists. A long term subersive employee will beat your locks eventually.
Documents with contents that would cost 50 terrabytes to scan and store as uncompressed tiff or whatever cost 5G as ascii.
This is by way of illustration only. Just think "arrested with drugs having a street value of $10M" and ask yourself if that same kind of inflation is likely to be going on here in the prosecutions PR campaign - which is what this story is.[1]
[1] Note that this could be a fair, reasonable, unbiased and accurate story, but it would be a heroic assumption not to consider the alternatives.
A year ago 6TB drives were already widely available, so now you're down to 10 drives. In other words, a medium sized home NAS for most nerds.
On Aug 27, 2016, search warrants were executed at Martin's residence in Glen Burnie, MD, including two storage sheds as well as upon his vehicle and person. During execution of the warrants, investigators located hard-copy documents and digital information stored on various devices and removable digital media. A large percentage of the materials recovered from Martin's residence and vehicle bore markings indicating that they were property of the US government
Removable digital media. Let's just assume this guy had access to backup tapes and was stealing them. LTO tapes start out at what, 100GB and are something like 1TB each right now? The guy could very easily had a couple hundred backup tapes.
Various devices. Maybe he had some servers, desktops, laptops, hell maybe a small (at the time) storage array or two. He had stuff stockpiled in his shed.
The real question is, what was the data?
LTO-7 is 6TB. LTO-5 (the oldest in use) is 1.5TB.
They should screen for laziness when vetting TS-SCI clearance. Something tells me that the only rational justification for this irrational move was that it somehow made his life easier. I don't think a mole would have the guts to pull something like this.
I don't think so.
http://www.theverge.com/2017/2/8/14555238/nsa-leak-indictmen...
50TB is a lot for a single person. How the heck did he even store it all?
The article mentions no motive. Without knowing all the facts, it almost seems like it was some sort of irrational compulsion.
https://assets.documentcloud.org/documents/3149446/United-St...
"GOVERNMENT’S RESPONSE TO DEFENDANT’S MOTION FOR A DETENTION HEARING:"
"A conservative estimate of the volume of the digital information seized from the Defendant is approximately 50,000 gigabytes. This information must be fully reviewed by appropriate authorities to determine its source and classification level, as well as the extent to which it constitutes “national defense information.”"
If he's indeed a digital hoarder, and it's still open if it even "constitutes national defense information" it can be anything, even counting his Blu-rays with movies?
I've got half that in a single 2U rackmount server -- my own -- in the data center and, relatively speaking, that's not really that much.
2. Thoughts on what he wanted/did with all of that information? It seems extremely amateur and not someone versed in tradecraft to have all of that just sitting around. I wonder if he was selling this stuff on the side, Shadow Brokers tools were definitely govt sponsored.
Has he just been sitting in a jail cell -- without being charged -- in the meantime? I assume the government argued against letting him out on bond on the grounds that he was a national security risk.
Edit: Looks like he was "charged with felony theft of classified government material" at that time, according to another article.
Why are such 'TOP SECRET' documents not hashed or otherwise? Anybody can Photoshop or even copy and paste an 'emblem' or 'indicia' as his original criminal complaint made by agent Jeremy Bucalo describes. Documents can be completely falsified especially if all that identifies it is a seal or marking and basic text.
I just feel like there is something more here.
Could there be more to this than meets the eye? Yeah. There could also be more to the moon landing than meets the eye.
It seems to me we all must, in our attempt to be rational, do our best to check our biases. For a lot of people on hackernews, that means second guessing your immediate "NSA cover-up" reaction to any item of news involving the NSA.
I think the most likely scenario here is that the government is making an example of this man. I don't think that's right, and I hope he gets off with as slight a punishment as possible, but it is a fact that governments have secrets and have enacted laws in order to try to keep them.
I agree with you at the same time that they could simply be making an example of this man.
But, I believe they are 'making an example of him' to cover their own incompetence. I am not saying evidence has been planted, concocted, or otherwise. I am saying this just not seem like a cut and dried case of mishandling by a long term employee who should be more than aware of procedures and policies in place after 20 years.
Clearly, they are plagued by the same bureaucracy hurdles and lack of attention to human resource detail as every other governmental agency.
Things might not be so bad after all.
The managerial tree on this guy through at least two levels up should be fired and potentially face further sanctions. Booz Allen should be forbidden from working contracts which require clearance for 10 years.
The larger issue isn't what this guy did (or even what Snowden did) -- it's a failure of the organization and a failure of process. Organizationally, any one bad actor, especially a low/medium level contractor, should not be able to do this.
That would most likely kill Booz Allen.
Between this and Snowden, I'd hate to be a cleared employee there (again); in addition to the increased/remedial training I'm sure has been put on their plates, they're probably getting panicky emails and warnings from principals and partners about the importance of their position.
It's probably like the TPS report memo scene from "Office Space".
But firings two levels up? Doubtful. The wagons would be circled and enough CYA emails sent to prevent that.
Additionally, in fairness to Booz Allen, in the article it states: "Martin was employed as a private contractor by at least seven different companies, working for several government agencies beginning in 1993 after serving in the U.S. Navy for four years, according to the indictment."
So if we're going to hang Booz Allen management out to dry, there might be a few other companies deserving of it as well.
Positive news that they caught him anyway, another Snowden-like espionage drama would be highly undesirable.
Looks like a corruption scheme to me
Apparently not. After Snowden & this guy, BAH clearly has issues providing qualified staff.
(and yes, apparently OPM has issues too)