Did the Intercept bungle the NSA leak?
washingtonpost.com
washingtonpost.com
* The story is a huge black eye for the Intercept, makes it look like they are very inept.
* The leak is not really substantial, mostly analyst notes about an ongoing thing that's been talked up in the press quite a bit.
* The DocuColor thing is ancient as well: https://www.theregister.co.uk/2005/10/20/outlaw_printer_dots...
Maybe my tinfoil hat is on too tight, but this just has a funny odor to it. One might speculate that this is a calculated leak intended to discredit The Intercept, sow fear in the minds of potential leakers?.
If the comments on other forums are anything to judge by, there are at least two groups of paid astroturfers battling it out today.
[0] http://www.military.com/veteran-jobs/security-clearance-jobs...
For social media activity, someone would likely have to report you for anyone to take action.
I for one think its pretty reasonable, it sucks working for the government enough already, if we put people under 24x7 surveillance just for trying to serve their country they will go from having very few talented/ethical people working for them to absolutely none.
----
"The non linear effects of leaks on unjust systems of governance
[...]
The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive "secrecy tax") and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption."
https://web.archive.org/web/20071020051936id_/http://iq.org:...
Critics charge that, at a minimum, the Post needs to disclose its CIA link whenever it reports on the agency. Over 15,000 have signed the petition this week hosted by RootsAction." http://www.hangthebankers.com/washington-post-owner-receives...
Critics charge that, at a minimum, the Post needs to disclose its CIA link whenever it reports on the agency. Over 15,000 have signed the petition this week hosted by RootsAction." http://www.hangthebankers.com/washington-post-owner-receives...
Whistleblowing is warranted in cases where information pertinent to the public interest won't come out otherwise. Given Mueller's investigation, the responsible thing would have been to wait and see, unless you had reason to doubt him.
She only sunk herself and gave ammo to critics of government leaks because now it seems that the NSA can't even investigate espionage incidents without somebody leaking to the press just to add fuel to some ongoing drama.
- It's really not the government's job to decide what the public has an interest in knowing. The system is, for the most part, set up as "default public", and that's how it should be.
- The fact that information (may) come out eventually doesn't help if it requires action now. I believe it's quite obvious that the public debate about these hacks is happening now, and that this is information that is central to that debate. Let's say nothing happens to prevent future hacking, and we learn about this incident in three or five years: I have no trouble imagining FOX commentators dismissing it as "We had this fight in 2017, and now the democrats want to talk about it again?"
I recommend reading the search warrant application, paragraphs 12-19. It's the second document in this BuzzFeed story: https://www.buzzfeed.com/stevenperlberg/a-federal-government...
And in the end even this leak doesn't contain any evidence of anything that would even tie it to Russia, let alone GRU. On the internet no one knows you're a dog. So she will get 10 years in the slammer for nothing.
http://blog.erratasec.com/2017/06/how-intercept-outed-realit...
It pointed to the exact printer being used and the exact time and date the document was printed. They didn't need her email to figure out it was her, but I'm sure that will help them in her court case.
edit: cleaned up some sloppy verbiage
I don't think we should expect news outlets to scour every printed document for these watermarks and remove them. Most aren't that technically savvy and this solidly seems like the responsibility of the person doing the leaking.
Leaking is dangerous and risky. I don't know the leaker personally but I could understand someone feeling that documents need to be released to the public and, at the same time, feeling like they can't evade the NSA's investigation. At that point any counter-measures probably seem pointless, especially for those who are not technical and can't imagine any bounds to the NSA investigative powers.
My first thought is that even blogs like AndroidPolice protect their sources better than The Intercept does here - they go as far as re-creating screenshots or renders of phone leaks.
The Intercept's lack of care is astounding. There wasn't any reason they needed to publish the fact that they received printed copies, let alone the actual scans.
They should have assumed it. While I agree they can't be expected to have enough technical savvy to remove watermarks, they should have re-typed it and hid or (better) destroyed the original.
What she did was illegal and the government is going to nail her to the wall for it, if for no other reason than as an example to others contemplating the same thing. I'm astounded how little effort they (both the leaker and the Intercept) put into avoiding discovery.
If it were me the watermarks would have been gone before the document left my possession. If you depend on other people to keep your secrets you're doomed.
A jury (with nullification power), in principal, might (as might the electorate who choose Presidents who have pardon and clemency power); if you aren't going to flee to avoid capture and aren't confident of your ability to evade the counterintelligence services in the long term, compromising your ability in the short term to improve the optics of the event may not be completely irrational, even if it is far from guaranteed to pay off.
I've not only been on juries, but studied them. Nullification is a thing. It's quite rare and unlikely in the specific circumstance at issue, but that's already factored into the discussion in the grandparent post.
"Russian General Staff Main Intelligence Directorate actors … executed cyber espionage operations against a named U.S. company in August 2016, evidently to obtain information on elections-related software and hardware solutions."
which seem to directly tie it to GRU.
To me, this statement which was:
* made contemporaneously with the investigation * by experts * not intended for public consumption
is evidence. It's not a formal proof, but it's evidence.
The leaked info contains a few more specifics about the hand waving from a few months ago, but no actual evidence. What's worse is how the wording of the leaked document and press coverage (including that of The Intercept) interleaves simple assertions of fact into the narrative which do not support claims made by the narrative but simply make the whole thing seem "fact-based" even if it's speculative.
Generally speaking, The Intercept publishes very high quality work, but the presence of Sam Biddle's name on the byline is generally a good indicator of low quality work.
There is also no consideration of the possibility of false attribution of the above.
Suppose I see that an enemy wears size 10.5 Adidas sneakers. If I buy an identical pair and leave muddy footprints with them near a crime scene, does the presence of the footprints implicate my adversary?
In the case of hacking, our assessment must include a notion of how easy it would be for a nation or group to be falsely implicated.
Separately, there must be a discussion of motive apart from specific evidence. But what we're seeing is a blurring together of various tiny pieces of data, analysis, guesswork, etc., into a narrative.
Within intelligence circles such narratives are meant to be used to allow higher order analysis to proceed in the absence of low level proof.
This is useful in the same way that imagining Travis Kalanick as a misogynist is useful in assessing the question of how such a trait might have impacted corporate culture, but it does not follow that it's true just because one lower-level incident occurred, etc.
> Separately, there must be a discussion of motive apart from specific evidence. But what we're seeing is a blurring together of various tiny pieces of data, analysis, guesswork, etc., into a narrative.
Do you believe that the intelligence community has failed to consider these fairly obvious principles when producing their reports?
It seems you've constructed a belief system by which you can never be convinced of Russia's involvement. This is what I was getting at with my question above (which you didn't really answer).
No, but I think that those spreading these kinds of reports are intentionally masking the way that they are meant to be used in intelligence circles. This happened during the buildup to the Iraq war also.
My point is that the reports make those leaps intentionally in order to support higher order analysis. They are not meant to be taken as a distillation of all of the available intel.
> you can never be convinced of Russia's involvement
Not at all. But your use of the word "involvement" is a great example of insinuation. What does "involvement" mean in this case? I'll take a stab at it:
- Russia is a geopolitical adversary to the US (check)
- Russia and the US are engaged in a proxy war on several fronts and have been for decades (check)
- Russia and the US both undertake various mischief campaigns against each other and have since the cold war (check)
- Russia and the US both have at least two distinct offensive and defensive capabilities... one being cyber "warfare" and another being cyber "mischief". (check and check)
I agree on all of the above. I think many of the people who are up in arms about the Russia story did not believe the above until quite recently, yet it has been the case for a long time.
The appropriate analysis is to consider whether Russia actually thought it would impact the outcome of the US election, or if it intended to merely create mischief and chaos/mistrust. Clearly the latter is true per the history between the two nations and is consistent with the ongoing mischief campaign.
A deliberate effort to hack election machines, trigger power failures in hospitals, or any variety of more severe attacks crosses the line from "cyber mischief" into "cyber warfare".
What we're seeing is the anti-Russia hawks seizing upon the mischief and trying to make it seem like a cause for war. Don't forget that many have been vehemently trying to get the US to use force against Russia for quite some time.
Thus, the key evidence that is needed to escalate Russia's "involvement" from routine mischief and turn it into something akin to "warfare" is the hard evidence of intent to harm infrastructure.
While spear phishing voting machine companies may signal intent to conduct a Stuxnet style attack on US electronic voting machines, is spear phishing really a nation-state level attack approach?
Clearly, unless "The Russians" had far better predictive models than American statisticians, it would have been utterly foolish to undertake an attack that would personally tick off the sure-thing presidential candidate.
So I think that proof entails both a clear delineation of what sort of behavior/mischief is actually abnormal or asymmetric, and the notion of what constitutes proof of intent to escalate.
I really don't understand that at all because if we want to get real, the OPM china hack was bigger than most of the things being alleged at the moment by stealing the database of everyone with a security clearance and yet, not a peep from anybody.
It would seem if you were consistent about cyber threats, these people yelling for sanctions on Russia should be yelling for sanctions on China as well.
My belief system isn't convincing me that Russians didn't hack the election system, or that they aren't capable of it. Just that this particular document is not the smoking gun.
For example: It was, until this administration, extremely rare for the US government (the executive, to be precise) to lie to US-based press. They'd deny to comment, or say something that was meaningless when examined closely, or tell you to ask X (who will deny to comment). But, contrary to common believe, it's extremely hard to find examples for them straight-up saying A when knowing that it's really B.
"But nothing suggested that CNN “staged” the demonstrations to any extent greater than engaging protesters, directing their positions, and asking them questions as part of a news segment."
So it was staged, but not "really staged"?
This is like the fact-check where Trump precisely and accurately quoted a decrease in the national debt, but Politifact still checked it as "mostly false".
[1] - http://www.politifact.com/truth-o-meter/statements/2017/feb/...
That aside, I don't see how it's rated false. Just because they claim "well this is how we do things" doesn't make what they have been doing for years any less fake.
I understand they didn't go out, pay some actors to hold some signs up but the scene itself was created and crafted for the TV and in my opinion that's fake.
The media is supposed to be informing the public, when you start using tricks to an attempt to hoodwink your audience into your narrative that's the opposite of informing the public.
All they had to do was point out either that they brought a few protesters over from the main protest to show you them specifically, or maybe a better idea yet, just go to the protest and turn the camera on so we can see what is actually happening, not what they are staging for us.
I can recall of a number of occasions during the Bush and Obama era where high-level officials were caught lying, sometimes in public testimony. And I don't even have any data points for Russia because we don't get their official statements on our news so I don't even know how I'd compare. How did you get both sides of the story accurately enough where you feel so confident in your beliefs?
Experts in what? Security research or PR?
Because the bar for hiring is pretty much the same lol
I have too many theories, but first we need to figure out if there is such a person: That's right, I'm questioning Reality.
Although you would think that when applying for a job that requires security clearance (even though she already had clearance), you would at least try to scrub your history, at the very least, you'd remove your retweets of Edward Fucking Snowden and Iranian politicians.
Did anyone do even a cursory check of her social media? I thought that's what most employers did these days before hiring people.
And lying can have very real consequences for politicians, even when it happens without breaking a law.
- TheIntercept failed to sanitize the documents before posting
- They provided the govt (or rather a govt contractor) with further information, at least that the mail was posted in Augusta, Georgia.
The former can be attributed to simple mistakes, but at least the latter is gross negligence of the highest order.
Given these two things alone, even if she had her own opsec in order, she'd likely been found out.
One thing that the Intercept--and Glenn Greenwald in particular--have been very critical of is news organizations that blindly publish leaks as verified facts. Here[0] is just one example where Greenwald writes:
> THE WASHINGTON POST late Friday night published an explosive story that, in many ways, is classic American journalism of the worst sort: The key claims are based exclusively on the unverified assertions of anonymous officials, who in turn are disseminating their own claims about what the CIA purportedly believes, all based on evidence that remains completely secret.
Now, in this case they at least have a document, which they verified was a real document created at the NSA. But even the Intercept's own article[1] admits:
> A U.S. intelligence officer who declined to be identified cautioned against drawing too big a conclusion from the document because a single analysis is not necessarily definitive.
So, are they living up to their own standard here? I don't think the answer is black and white. But I am certainly tired of hearing all this talk without seeing the technical details.
If the U.S. election system was hacked--even just one voter registration company--the American public deserves to get the details. Period.
What were the IP addresses used, and what ties them to Russia? What does the malware actually look like, and has it been seen before? How was this whole thing discovered?
For now, all we have to go off of is what the NSA says may have happened. That it was a leaked document doesn't make it any more revealing than if it was a phone conversation with another unnamed official.
[0] https://theintercept.com/2016/12/10/anonymous-leaks-to-the-w...
[1] https://theintercept.com/2017/06/05/top-secret-nsa-report-de...
Given that the average American barely understands what a computer virus is, is the level of technical detail you're calling for sensible for public dissemination?
I think it's also informative to look at how attribution was viewed in the past. We as a tech community used to almost pride ourselves on our skepticism, as can be seen in this Bruce Schneier post[0] on Stuxnet.
In the post (written in 2010), he points out that attributing Stuxnet to the US Government is "almost entirely speculation", that ties to the Bushehr nuclear power plant were "rumors" at the time, and that "Once a theory takes hold, though, it's easy to find more evidence".
It took years months of more research, technical similarities to the Flame virus, video of an Israeli intelligence official joking about the virus, and much more before the tech community accepted the theory that Stuxnet was a US Government creation.
I'm not saying there's a perfect solution, but surely we as a tech community have lost our skeptical tone and no longer see it as important to question the government's technical claims as we once did.
I have a feeling if the roles were reversed, and it were Trump crying foul about Russian hacking, that's exactly what we'd be doing.
[0] https://www.schneier.com/blog/archives/2010/10/stuxnet.html
I'm also really sceptical of what, if anything, the government could provide as evidence that people would accept. If the evidence is technical, that doesn't only prevent non-technical people from evaluating it. It also means it's susceptible to being called "fake" when it isn't.
Say, for example, the NSA has log data from a bunch of switches across the world, and maybe the Russians also tapped into a few honeypots. All the NSA then has is IP addresses and other system logs–all of which could easily be faked.
Concerning your last point: Yes, we would treat the reverse different. And there's nothing wrong with judging some information by their record: If I read something on a website that open 6 pop-ups for porn, and that I have never seen before, I'm going to trust it less than the New York Times, which has, contrary to popular myth, an excellent track record of trying their best and making it public when they fail.
One thing people forget to mention about the FBI director 10 year term is that it wasn't put in place in order to have a director serve over a long period of time (somewhat like the SCOTUS) but to prevent somebody from amassing so much information and power that they can blackmail anybody.
That was decades ago, we now have agencies like the NSA who have far more information on people and if we are going to top that off with allowing them to make claims on wrongdoing without having to disclose actual evidence I just don't know such power could be kept in check.
What is the right amount of fuzzing for a news organization to perform on leaked documents, to protect a source while providing credible evidence to support a claim?
Meral, H. M., Sevinc, E., Ünkar, E., Sankur, B., Özsoy, A. S., & Güngör, T. (2007, February). Syntactic tools for text watermarking. In Electronic Imaging 2007 (pp. 65050X-65050X). International Society for Optics and Photonics.
Maybe paraphrasing the key points or claims of the document would be the only safe way.
It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again.
Do we still really trust the NSA? It was disappointing yet expected from the WaPo that they took as fact everything the DOJ alleged about how the case proceeded.
A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.
There really isn't much you can reasonably conclude about this. Is the government lying? Is The Intercept incompetent? The only thing you should remember is that if you are going to leak documents you need to do as much as possible while they are still in your control to hide your involvement. Once you send them off, your fate is in the hands of others.
Massive incompetence and amateurish stuff on part of the leaker and The Intercept. Yellow dots have been known for ages.
> Armed with this evidence, the NSA was able to quickly determine who had printed the document by checking audit logs.
So no I see exactly _zero_ evidence in that article that this was the method used. If you have any other article that has such evidence, I'm all ears.
Of course you're correct that The Intercept should have taken more care in this matter, but that doesn't mean that this was the reason why the leaker was found. The leaker should also have been a bit less amateur (e.g. not communicating with The Intercept on a _work_ computer).
There's plenty of evidence The Intercept's actions caused her to be found. It's documented in the FBI's affidavits for arrest and search warrants. https://www.buzzfeed.com/stevenperlberg/a-federal-government...
To wit: 'The Reporter told the Contractor that the Reporter had received the documents through the mail, and they were postmarked "Augusta, Georgia."'
So the FBI looked up who printed the document and of those six, who lived in Augusta, GA. Open and shut. Thanks, The Intercept!
The images have clear fold lines in them.
In that situation, I'm sorry, but the responsibility for protecting your identity is on you. Anonymize the data. Do not leak something that only you would have access to. etc, etc.
Because unless you're leaking to Infowars, you have to expect that a legitimate journalist will present your data to the organization from which you leaked it to, and request comment.
Snoweden did everything right, and it still wasn't good enough.
If removing well-known, uniquely identifying printer microdots isn't a best practice, it should be.
> If removing well-known, uniquely identifying printer microdots isn't a best practice, it should be.
Very true; where is the evidence that they did not do so?
You can read the search warrant at https://www.buzzfeed.com/stevenperlberg/a-federal-government..., which is more complete than the arrest warrant. Just read paragraphs 12-19, which cover the relevant probable cause. If the FBI don't know how it leaked (printed) and from where (Winner's home town), the case becomes extremely difficult. Instead, they had so much that she just confessed when they showed up.
> Snowden's identity was made public by The Guardian at his request on June 9, 2013.[97] He explained: "I have no intention of hiding who I am because I know I have done nothing wrong."[20] He added that by revealing his identity he hoped to protect his colleagues from being subjected to a hunt to determine who had been responsible for the leaks.
But Snowden's whole strategy was to be a public figure. He fled the country and had a documentary filmmaker record the handover of the documents. It looks like Winning was hoping to remain private and had no idea what she was doing.
It was game over at that point. Nothing they could do would have fixed that.
I've worked at far less security concerned companies that monitored all network traffic going and out and logged it and continually were looking not only for internal nefarious behavior but for possibly viruses, worms, etc.
She signed up for an email subscription from her personal gmail, on her work computer.
That would certainly have been enough to raise her superiors' hackles when discovered, but the result would have been her getting fired, not indicted.
The bottom line is having a personal subscription to the Intercept was not ever going to be enough to build a case against her. You repeating that claim is victim blaming, and more importantly, wrong.
I think that really depends on whether you perceive the leaker as a perpetrator or a victim. Valid arguments can be made for either side.
Anyone who is thinking about leaking anything classified only needs to spend thirty seconds typing "Snowden" into Google to find out what happens when the federal government identifies the leaker. They then decide if it's worth the risk and how much time they will spend on covering their tracks. In this case (if true) it sounds like Reality Winner decided that they simply couldn't cover up their leaking and threw in the towel.
Much has been made of the watermarks on laser printers, we've known about those for a long time. Not everyone is aware but it's the sort of thing you can find out about if you put in time to do the research. After doing my own research, it doesn't seem like these watermarks really came into play; the NSA simply looked up everyone who had accessed the document and inspected their workstations for clues.
Bear in mind, The Intercept is likely more aware of anti-leaker strategies than most of the people they are hoping will leak them data. If they're going to encourage the act, they should do everything possible to help their sources protect themselves, and do diligence on anonymizing everything they get even further.
They do if they want to keep their jobs. It's not a moral point, it's a Darwinian one. No one talks to journalists who burn their sources.
The Intercept's literal genesis was as a clearing house for leaked data. This is... really bad if they want to be known as a safe place to send leaks.
The FBI doesn't mention the watermark in their affidavits, but they do mention that The Intercept gave away that the document had been printed and mailed from Augusta, GA. That allowed them to quickly zero in on Winner. The only "clue" on her workstation was that she had e-mailed The Intercept asking for a podcast transcript months before. In other words, she knew The Intercept existed. The Intercept burned her.
The Washington Post covered Snowden's leaks of unconstitutional actions by the NSA, won a Pulitzer Prize for the coverage, only to then stab him in the back and call for his prosecution.
https://www.washingtonpost.com/opinions/edward-snowden-doesn...
I've heard speculation that the change in attitude was tied to regime change at the Post in the wake of the Bezos acquisition.
If I had to change anything it would be the fact that they only signed up for an intercept mailing list using work email, not direct contact. I regret the error, I was going off what I read yesterday.
Anyway I'll take the lack of substantive criticism of my point and critique of form as a point of pride.
Amazon doesn't own WaPo, Jeff Bezos does. A $600 million 10 year contract for a private cloud is a tiny fraction of AWS revenue (some $15 billion per year), let alone overall Amazon revenue. It is in no way a sweetheart deal that would require Bezos bend over backwards, let alone undermine the integrity of the news organization for which he paid $250 million out of his own pocket.
I'm all for a good conspiracy theory, but you're going to have to spell this one out better.
The women was a contractor, not an agent, so they aren't sacrificing someone they've invested in. etc
Again, what actually happened, who knows?
So given the choice between "News Site Messed Up Protecting a Source" and "The Whole Thing Was Orchestrated By The Spymasters", you're refusing to make a call because... "who knows?"
I mean, if that's the level of detachment and rationality you're going to apply here... why stop at a mere egg-on-face moment for The Intercept? Surely the NSA could be applying those powers for something more juicy.
Personally, while that scenario doesn't sound impossible I think the likelihood is being overstated due to motivated cognition: if you like the Intercept you would like to believe they did nothing wrong, but in reality people do make mistakes.
I do think that The Intercept bungled this in not stripping the watermarks; I don't shield them from criticism even though I value their reporting. But I do not necessarily accept the government's version of events. Parallel construction is not unheard-of.
Thanks for pointing that out. I've edited it to simply say "via other methods", especially since other comments say the source did not directly send the info via her work email.
> I do think that The Intercept bungled this in not stripping the watermarks; I don't shield them from criticism even though I value their reporting. But I do not necessarily accept the government's version of events. Parallel construction is not unheard-of.
If the Intercept did make the mistakes they apparently made (if not they're free to deny it), does it matter whether or not the parallel construction theory is true?
> Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept.
This really should be ignored. The FBI included it as probable cause for their search and arrest warrants, but she had e-mailed them asking for a podcast transcript months earlier. As far as leaking, she mailed the document to them and had no electronic communication at all. The Intercept blabbed that it was postmarked Augusta, GA and was printed, which is what gave her away. They screwed up and if they want anyone to feel safe leaking to them again, they need to own up to it and describe how they are going to fix their procedures to protect their sources in the future.
It's called parallel construction; it has happened before and it will happen again.
http://www.reuters.com/article/us-dea-sod-idUSBRE97409R20130...
Instead, they released this chickenshit statement that tries to cast doubt on the testimony without actually disputing any of it: https://theintercept.com/2017/06/06/statement-on-justice-dep... So, it looks like we live in the reality where the FBI didn't lie on a warrant application and The Intercept burned a source.
I mean, we have to just see it in the larger context: there is very definitely a war going on among various, nefarious, otherwise, or indeterminate, hostile parties.
It seems that if we must dismantle the military-industrial state, it is going to be through info-wars. The key targets are all secrets. (Curious that both sides seem to want the same thing though, i.e. "the info wants to be free", isn't it?)
That said, the important thing for any leaker to do is to try as much as possible to obscure any links they have to the documents before handing them off to third parties even if those third parties are supposedly trusted (because once you hand the documents off, you are no longer in control).
Something I think is valuable in this leak is the fact that the general public will be better educated that in fact their printers are capable of tracking every single thing they print, and there is no really, truly, anonymous personal printing any more.
I hope the blahgosphere will pick up on this and that we see Stories targeted to the normals that explains these sorts of things to them. Grandma may not care too much about her phone being listened to (after all, it was always so, to her at least..), but if you explain to Grandpa that there is a secret code that will tie every single printed sheet back to his house-hold, well, that may raise a few shingles ..
I have a sinking suspicion that the average American, for example, isn't benefited by this leak.
But, I do think that these leaks are good for everyone, not just Americans, and that is why they need to happen.
There's a difference between the leaks Deep Throat provided ("Your President is a criminal") and the leaks allegedly executed by Reality Winner ("Russian spies are spying, as Russian spies do"). A failure to distinguish qualitative nature of dumped information weakens both the future security of leakers and the overall philosophy that more transparency is a good thing.
These leaks have value, because they continue to forward the narrative in the general public, and the centres of true power, though weakening: mainstream/middle-class/entitled-/privileged- consumers who can Do Stuff™ to change the power structures behind this big military-industrial mess.
If we hold one thing in place: Pease with Russia, we must assume that there are parties who want this, and parties who don't. Oh, sorry, I mean "War With Russia", which is what this is all really about.
Do the answers to these questions matter if the war continues regardless?
Prophetic words from a 2008 paper (PDF) [1].
This paper may be duplicate information, but reading this paper impressed upon me how many more ways there may be to spy on people than I could imagine (and I know about some existing things like side-channel attacks... how do I spy on thee? Let me count the ways.)
So don't register your printer with the manufacturer, folks; the serial number may be on every page it prints. Ditto for digital cameras.
Then again, is fighting for digital privacy a losing battle when at every turn, there are deliberately hidden bits of PII? Pun intended.
[1]: https://engineering.purdue.edu/~prints/public/papers/sp_arti...
But given the response and the constellation of corroborating info from various sources, it seems pretty reasonable at this point to presume it is NOT disinformation. It's almost certainly not a complete picture of what various parties know and it's likely a snapshot of an evolving knowledge base (ie- the broader intelligence community's knowledge of what was going on before and during our election).
But the presumption that it is not 'false' information should be pretty solid by now.
Or if you are really moral just set up the camera above your desk.
A bit of plausible deniability is much better than life in a supermax I promise...
How long until the protons in the backup tapes decay?
It is? So corporations install something that infects your laptop and updates the root certificate every time Chrome or Firefox updates? Sounds extreme to me. Something the NSA might be able to do, but hopefully not my company.
https://www.jamf.com/jamf-nation/discussions/11830/deploying...
Other applications on mac/linux that use their own keystore like OpenSSL or Java will throw cert errors if you don't also install the CA in their keystores, but that could be scripted as well if it causes too much friction for users.
If you're in such an environment, the options are either install the CA or don't use anything that requires HTTPS ¯\_(ツ)_/¯
On the whole I think this information needed to get out. There were reports of people all over the US being dropped from voter registration rolls, and now proof that the Russian military targeted voter registration companies.
Either their methods work, and of course they should be secret, or their methods don't work, and it's unproductive to help them shorten the list of attack methods they try.
That said, I think that's an important story here. The infrastructure around these machines seems sloppy. The fact that there's no source code to read means they are black boxes we have to trust.
Is this a new trend? Can you name your child with any surname you wish? For example "Tower John Trump".
The Intercept got a story published and is enjoying great attention (and ad revenue), and the guilty party was caught. Everyone can be happy.
"God’s in His heaven — All’s right with the world!" [R. Browning]
There is no ad revenue at The Intercept.
Something stinks here. Both WaPo and the NSA, who Greenwald has picked fights with, get to smear The Intercept, while we are supposed to bekieve the leaker has extreme incompetence (flagrantly incriminating herself while using a pseudonym), and meanwhile the public still has no evidence of the election tampering.
It's not like the Deep State didn't lie to the country to wage a war in Iraq not long ago.
The public deserves to see proof.
EDIT: I'm also unsure what the point of shifting the focus onto The Intercept's alleged "mishandling" of the leaker's identity is. It seems like a smear job meant to discredit a publication that the natsec community and mainstream media like WaPo dislike. It also removes the focus from the substance of the leaks and puts it on the "character" of the publication.
https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f47...
> 14. The U.S. Government Agency [NSA] examined the document shared by the News Outlet [The Intercept] and determined the pages of the intelligence reporting appeared to be folded and/or creased, suggesting they had been printed and hand-carried out of a secured space.
> 15. The U.S. Government Agency conducted an internal audit to determine who accessed the intelligence reporting since its publication. The U.S. Government Agency determined that six individuals printed this reporting. These six individuals included WINNER. A further audit of the six individuals' desk computers revealed that WINNER had e-mail contact with the News Outlet. The audit did not reveal that any of the other individuals had e-mail contact with the News Outlet.
> 16. The U.S. Government Agency determined that WINNER had e-mail communication with the News Outlet on or about March 30, 2017, and March 31, 2017. The first e-mail was from WINNER, using e-mail address [redacted].fitness@gmail.com, to the News Outlet. In it, WINNER appeared to request transcripts of a podcast. The second e-mail was from the News Outlet to [redacted].fitness@gmail.com and confirmed WINNER'S subscription to the service. The [redacted].fitness@gmail.com account is a personal e-mail account not sponsored by or affiliated with the U.S. Government Agency.
Whether the 'crease' noticed by the NSA in paragraph 14 was actually creases or an internal code for microdots, if The Intercept was going to use this report there's nothing they could have done to protect this reckless source.
Watching outbound SMTP from Gmail or just MiTM internal agency traffic?
That said, if the dude gets impeached she will probably eventually be pardoned.
The microdots seem to be the usual xerox-style microdots, and decode properly:
Printer serial number: 535218 [or 29535218] Date: May 9, 2017 Time: 06:20
http://blog.erratasec.com/2017/06/how-intercept-outed-realit...
Or are you saying "I didn't read the article, but the answer is usually no"?