They didn't even need the yellow dots. She literally emailed the Intercept from her work email and was one of a trivial number of people who'd printed it in the first place.
They didn't even need the yellow dots. She literally emailed the Intercept from her work email and was one of a trivial number of people who'd printed it in the first place.
This was a significant clue that The Intercept did not have to give up. The warrant says they looked at all people who had accessed the report, and because the document appeared to have been printed, then at those 6 who printed it.
The yellow dots might have not been a factor, but it's nevertheless the same type of carelessness which might have exposed a whistleblower otherwise.
(But yes, this whistleblower would have been discovered by other means as well).
2. The story about only six printouts and e-mail correspondence is the official cover to draw public attention away from the yellow dots.
3. The yellow dots is how they actually found her and why she had no reasonable choice but to admit leaking, which allowed 1 to happen without drawing attention to the yellow dots.
While I didn't make my first year of law school I feel like nearly every criminal defense attorney in this country would disagree with this statement.
actually, since the dots are not at all a secret, #3 cant be right. #2 is a bold claim, obviously pure speculation. So #1, is this true? please link source.
http://www.cnbc.com/2017/06/05/feds-arrest-nsa-contractor-in...
I read another article that stated her admission came while the feds were raiding her home.
If some random journalist was able to decode the dots, the NSA probably decoded them too because why not.
The fact that they know how many people printed this document shows that they keep detailed printing logs so they shouldn't have trouble finding out who exactly used this specific printer at this specific time. And if you think about it, this is exactly what they should be doing instead of relying solely on weaker evidence.
Then they searched her work computer and got some more evidence (the e-mail contact, maybe more they aren't sharing).
They presented whatever evidence was sufficient to convince her and the public that they know it was her, she doesn't seem very tech-savvy, freaked out, told everything and now it's done.
I have no idea why people are leaking to rinky-dink operations like the Intercept. If you want to leak, then leak to the Washington Post or New York Times. I can't imagine the Intercept having the expertise to handle such documents. This was a fairly obvious screw up.
I also question their methods of receiving and storing such documents and if they aren't compromised by one or more nation state intelligence services. Are these documents being stored through a third party email or web server? Is there end-to-end encryption?
The copier explanation may be a believable fiction as not to reveal other sources.
Personally I would trust them MUCH more than the New York Times. Well, unless the documents were specifically only damaging to Trump.
Snowden anonymously sent him an e-mail saying he had documents he wanted to share, and followed that up with a step-by-step guide on how to encrypt communications, which Greenwald ignored. Snowden then sent a link to an encryption video, also to no avail.
“It’s really annoying and complicated, the encryption software,” Greenwald said as we sat on his porch during a tropical drizzle. “He kept harassing me, but at some point he just got frustrated, so he went to Laura.”
From another source [2] I cited in another comment:
"it took Greenwald several more months and help from experts before he could learn relatively basic tools like PGP encryption."
That's not exactly trust-inspiring, I'd say.
[1] http://www.nytimes.com/2013/08/18/magazine/laura-poitras-sno...
[2] https://www.dailydot.com/layer8/edward-snowden-gpg-for-journ...
2. It makes clear that providing better channels to enable legitimate whistleblowers to find a publication channel was critically important.
3. It's exceedingly easy for anyone to ignore a critical insight -- whether it's some annoying anonymous leaker, or an odd set of lab results, monitoring readings, etc. Those insights are critical in large part because they fall outside norms and expectations. (This is, generally, a major block to creativity.)
4. There are a lot of contacts which aren't of mind-blowing significance. Filtering the noise is another problem.
5. Greenwald and The Intercept were specifically created to address these shortcomings. Among The Intercept's staff is Micah Lee, technologist with the EFF. (I've pinged Lee on Mastodon over the Intercept's gross failure here -- it is a massive fuckup.)
It shows that Greenwald's association with the Intercept cannot be used to imply that it practices good security.
It's possible for someone, without a specific talent X, to create an institution to ensure proper application of some talent X, when the need for competent execution of X makes itself apparent.
Again: you're not arguing a relevant point, despite the truth value of your statements. This is an irrelevant discussion.
But that's how I, and apparently others, read the grandparent's argument.
The grandparent made a personal statement about trust in The Intercept, and did not really substantiate this trust other than by mentioning two key players.
> It's possible for someone, without a specific talent X, to create an institution to ensure proper application of some talent X
I fully agree -- one need only think of huge conglomerates who manufacture everything from light bulbs MRI machines to aircraft engines, to use GE as an example.
> when the need for competent execution of X makes itself apparent.
And therein lies one problem as I see it: it has to make itself apparent to the creator (resp. leader).
Because the converse is also true: It's possible for someone, without a specific talent X, to create an institution which fails ensure proper application of some talent X.
From another comment, we seem to agree that there should absolutely have been policies and procedures in place that should have prevented this mess in the first place.
I posit that this is one of the things that should have been apparent from the start (as preserving anonymity is crucial to The Intercept's cause), yet most probably weren't.
The following arguments you make, here, are actually pretty good. The one you you'd lead with was poor, as I've already addressed.
I'd especially like to emphasise your point on the failure of good intentions. That's highly salient, and something that should probably be kept generally in mind with tech startups -- many of which seem to sprout like mushrooms from the dark and ... fecund substrata of Silicon Valley and YC ... and yet fall short of their respective putative aiming points.
(That The Intercept can trace its roots to start-up culture may also be relevant here, through Omidyar.)
The interesting (and troubling) part of this story is that it involves four members of the staff, working together, none of whom is named "Glen Greenwald", and presumably with the technical support of Micah Lee. And yet we've still seen what we've seen.
Definitely room for improvement.
But it's still a bit rich to pin the fault on Greenwald specifically, and pre-Intercept Greenwald especially.
And, more broadly, citing his pre-Snowden behavior seems unreasonable. For literally all people, there was a point where they didn't know PGP, and another point where they were confused and just learning to use it. If you trust their current knowledge of it, that's hardly a serious criticism.
As I read you, you did not say that Greenwald's association with The Intercept implies it is insecure. You did say that Greenwald's delays in adopting PGP mean "that Greenwald's association with the Intercept cannot be used to imply that it practices good security".
I didn't miss that distinction, but I'm making a stronger assertion - I think his presence does (weakly) imply good security. I think that "Greenwald's association... cannot be used to imply" is false.
If we're resorting to logic for this, you're suggesting that Greenwald's presence should not raise our expectation of good security (which is, as you point out, different than saying it should lower our expectation). I'm saying that it should raise that expectation, so we really do disagree.
Uh, I suggest you read about how poorly he handled the Snowden materials and how he's about as tech savvy as my grandpa. This fuck-up alone is inexcusable.
That's a mistake I think most security-conscious, tech-savvy non-professionals would avoid. The printer steganography here is a substantially more subtle error than the one we already say the NYT commit.
This is something that can be learned with a few minutes research, so raising it as "questioning their methods" seems like FUD.
The answer is yes, there is end-to-end encryption handled via Tor. Using SecureDrop, the same tool as the Washington Post and New York Times. Treating that as some kind of distinction between these organizations is absurd.
Assuming The Intercept detected the printer dot, how could they possibly know the printer dot wasn't some random one from a printer a library vs her work computer?
If I was The Intercept receiving a document from someone claiming to be an intelligence officer I would assume they used some very basic OPSEC - such as not printing the document out on a MONITORED WORK COMPUTER. This is basic stuff.
I don't see what more The Intercept could have done here to protect her.
She messed up, not them.
It isn't if they make blunders like this.
[0] https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f47... PDF page 12, paragraph 19
No, I'm not sure about that, and if they'd made the mistake after having claimed to be safe for whistleblowers I'd be gently complaining about them on an Internet message board too.
What matters is that if she had not made any mistakes the intercept made it trivially easy to reduce the pool of possible suspects. That´s fairly stupid if your whole reason for existence is to handle documents sent to you by vulnerable people.
If this is not the last article by the Intercept based on stuff leaked to them it would highly surprise me.
They totally messed this up.
Still I don't see how the Intercept could have handled this better. Maybe they should have been looking for printer dots in documents received in the mail and then block it out when they digitize it. But is this really a common practice among news orgs handling leaked docs?
I see people on Reddit attacking The Intercept because, they say, the printer dot thing is 'common knowledge'. But to me this seems like an easy thing to overlook. Especially if most other leaks were digital. News organizations and leakers will certainly all be looking for this going forward (I hope).
As far as I'm concerned all the 'common knowledge' stuff that was overlooked was all via the leaker.
The intercept could have handled this better by describing the article and maybe a citation or two, to pass the originals back in some form to the government is about as stupid as it gets.
If anything this article shows how easy it is to play 33 bits if you have help from the subject or some outsider that is just doing their job in a ham fisted way.
There's a hell of a lot of capability which comes about through opportunity, chance, and simple dumb luck or repeated attempts to do something. This tends to show up frequently in terror and mass-criminal activities. Simply wanting to accomplish some negative effect, and having general means to do so, is frequently enough, particularly if that threat is underappreciated and/or requires a high degree of vigelance.
There are numerous attacks (water, food, infrastructure) which have been highlighted for decades as potential attack vectors, though they appear not to have been undertaken.
Another possiblity, of course, is that there is constant low-level probing of such attacks, which are lost either at the internal or public-discourse level as noise or accidents. There remain cases -- the San Jose electrical power substation attack via small-arms fire, US military seeding of infectious agents over urban populations[1], the CIA's attacks on Soviet gas infrastructure via control equipment[2] and Iranian nuclear material refining via stuxnet[3]. In which case, much of the expressed concern of US intelligence agencies is an awareness of their own capabilities, and practices. Other foreign powers have their own history here -- Russian tea[4], Israeli hotel service[5], and Chinese messenger service[6] come to mind.
Criticisms of The Intercept are validated, IMO, by the Intercept's own positioning of itself as a safe channel for such leaks,[7] and specific in-house expertise on the matter, Micah Lee.[8]
Even if The Intercept's actions didn't directly contribute to identification or confirmation of Ms. Winner as the source of these documents, the fact that they could have is absolutely material, and represents a massive failure on the part of Intercept staff and procedures.
Other points to consider: people's technological savviness is on general exceedingly poor, and even domain experts are generally only experts within that specific domain. At the level of the general population, only 5-8% of users have "advanced" skills -- which means ability to use such features as "sort" or "find and replace" within a word-processing tool.[9]
This means that an organisation such as The Intercept should focus as a principle priority on protecting its sources against themselves.
Ms. Winner's OpSec was poor on multiple counts. The Intercept amplified those weaknesses.
Finally: Information isn't power, but is a force-multiplier. It may amplify either your strength's or your opponents'. In this case, the question (from the NSA's perspective) was to identify just who it was that might have provided the information in question. Any one individual can be uniquely identified by 33 bits of information. In the NSA's case, most of those bits are already defined by a simple basis of access to information. The documents here had only to discriminate amongst the much smaller set of people -- call it 3-6 bits -- who might have supplied them to The Intercept.
Other lessons are that in previous totalitarian societies, registration of typing and duplicating equipment was routinely used to identify a potential source of documents. Because those determinations were based on fixed characteristics, that was all they could divulge. Today's printers define not only the specific machine, but time, and potentially metadata of the document itself or submitting user.
You might want to reflect on that for a bit.
________________________________
Notes:
1. http://blogs.discovermagazine.com/bodyhorrors/2015/06/28/san...
2. http://www.telegraph.co.uk/news/worldnews/northamerica/usa/1...
3. https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/
4. http://www.telegraph.co.uk/news/uknews/law-and-order/1138178...
5. http://www.spiegel.de/international/world/tourists-with-a-li...
6. http://www.foxnews.com/tech/2011/06/01/gmail-compromised-chi...
7. https://theintercept.com/leak/
The Intercept did not encourage her to steal this information, nor did it give her any direction on how to do so. She chose her own method of exfiltrating the data, and in this case it turned out to be an quickly identifiable one. She knew this document was going to be published by the Intercept; that was the entire point of leaking it. Once published, regardless of form, you can bet that the FBI would have agents knocking on the Intercept's door asking to see the physical source material.
Furthermore, In order to prove the veracity of its published claims, the Intercept provides its source documents - if they do not, they simply open themselves up to accusations of fake news and falsified material. Any editing they do to the document will be ammunition for the FAKE NEWS crowd - so where is the compromise here?
Greenwald is not located in the United States for a reason (so good luck knocking on that door), and if they wanted to verify the documents they could have done so with a bit more care.
Assuming the text did not contain steganographic tricks (yes, that works) they could have cited back a few paragraphs and the document title. That would have been enough.
While you have some good points, I think hanging your argument on a 'would' is not really convincing :)
I am trying to come up with a suitable analogy to illustrate how stupid this is. I imagine a WWII intercept of an Enigma message being decoded and the clerk in charge then calling up the German High Command to verify the accuracy of the decoder. It is totally baffling to me that they did this in the way described without for one second thinking about how vulnerable their source was.
> Greenwald is not located in the United States for a reason (so good luck knocking on that door),
Greenwald has said he moved to Brazil because he wanted to be with his partner and that was the solution that they chose; at the time, one couldn't sponsor an immigrant visa for a same-sex partner in the United States.
This document wasn't reported by Glenn Greenwald, but rather by Matthew Cole, Richard Esposito, Sam Biddle, Ryan Grim, who all appear to live in the United States. Almost all of the Intercept's reporters who report on and publish leaked classified materials live and work in the U.S.
Corporate emails sometimes use this trick to catch company leakers.
If only there were like.... some group of people who cared about the privacy of others.
The problem is inadequate access control to classified materials. There tends to be a lot of information that people can access without a need to know, that is not rigorously tracked and locked down. This means that someone looking to steal or leak can get their hands on a lot of stuff they shouldn't without raising suspicions if they're not stupid about it.
The reason we may be seeing a number of spillage incidents with contractors is simply because there a lot of contractors working at government agencies. In IT a lot of the time contractors outnumber government people by a significant margin.
http://projects.washingtonpost.com/top-secret-america/
Some findings:
> Some 1,271 government organizations and 1,931 private companies work on programs related to counterterrorism, homeland security and intelligence in about 10,000 locations across the United States.
> An estimated 854,000 people, nearly 1.5 times as many people as live in Washington, D.C., hold top-secret security clearances.
> Analysts who make sense of documents and conversations obtained by foreign and domestic spying share their judgment by publishing 50,000 intelligence reports each year - a volume so large that many are routinely ignored.
Fourth possibility: that the NSA did use the forensic marks in question to identify her, and fabricated a parallel construction in order to avoid acknowledging the existence of said marks.
(But still, most likely this is Hanlon's Razor. What's there to be suspicious about?)
Six: she was a weak security link and someone used her access details without permission.
The way politics are now I'd believe anything at this point.
so yes, there is at least circumstantial evidence this was not a "real" thing that happened. either a plant or make believe
[0]https://www.airforce.com/careers/detail/cryptologic-language...
This is a true story from the book Freakonomics [0]. Reality Winner could be a real person.
[0] http://freakonomics.com/2009/04/21/winner-loser-and-marijuan...
Not likely. It's been common knowledge for a long time.
http://www.nytimes.com/2008/07/24/technology/personaltech/24...
http://www.washingtonpost.com/wp-dyn/content/article/2005/10...
The big Wikipedias have long articles on it with many sample images: https://de.wikipedia.org/wiki/Machine_Identification_Code https://en.wikipedia.org/wiki/Printer_steganography
If you need to fax one, you'll need to find a really old fax machine without color printer or scanner capability.
[1] https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
Secondly, often assuming just a tiny bit of malice can account for layers and layers of stupidity. Occam's razor is sharper :)
I think it is a good thing; truth is discovered in the clash of opposing forces.
Send some xor-ed file out using a non-secure connection and sneak the key out somehow ?
Take photographs/video using the phone, cold-war style ?
This said, it's been reported some contractors and employees routinely took home loads of external drives, so your expectation that IO ports are completely disabled might be unrealistic; the NSA is good but it's just another large org, just a bit more paranoid than average.
Hard drives labeled unclassified can be removed from those facilities with special permission but I think hard drives are under more scrutiny nowadays.
Stray thought: You don't have to sneak a OTP out, you only need to sneak it in. Then you do your XORing, transmit the mangled data, and erase that copy of the key.
What is suspicious about it?
This isn't 4chan. Present some evidence but don't just make up random speculation that "could have happened".
I mean it's possible to come up with elaborate theories, but the most likely explanation is that she was just spectacularly stupid.
or she intended to become a martyr
I'm not sure being this dumb is going to get much sympathy from anyone.
Could she and should she have taken better precautions, without a doubt. Would the average intelligence analyst who is not being coached by a foreign power do a better job, I doubt it. In fact many foreign spies have done a far worst job and not been caught immediately. This is because the intelligence they stole was not published. Being a source of a journalist is much harder than being a source for a foreign power.
(Kind of annoyed that the derp became the story while the actual leak never made the front page.)
https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f47... PDF Page 11, Paragraphs 15 and 16
Basically you can't believe any narrative, as the gov can legally put forth anything they can contrive after-the-fact as long as it's plausible.
Bonus points? Any mention of possible COINTEL tactic gets you labeled a conspiracy theorist. A lovely term invented by the CIA that readily dismisses anyone who points out that a COINTEL tactic might be in use. Lucky for them most the general public bought it hook, line, and sinker.
back in the last world war they managed to pull off creating an atom bomb with even the vast majority of people in office knowing about it, today every damn snowflake is looking for their five minutes of fame.
Surely, NSA contractors aren't this stupid ? Something smells.
I did something only somewhat less stupid when I was about that age: http://www.shub-internet.org/brad/cacm92nov.html