Military Bans Disks, Threatens Courts-Martial to Stop New Leaks
wired.com
wired.com
The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive “secrecy tax”) and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption.
http://zunguzungu.wordpress.com/2010/11/29/julian-assange-an...
These few lines sum it up nicely:
Because we all basically know that the US state — like all states — is basically doing a lot of basically shady things basically all the time, simply revealing the specific ways they are doing these shady things will not be, in and of itself, a necessarily good thing. In some cases, it may be a bad thing, and in many cases, the provisional good it may do will be limited in scope. The question for an ethical human being — and Assange always emphasizes his ethics — has to be the question of what exposing secrets will actually accomplish, what good it will do, what better state of affairs it will bring about.
He really isn't just randomly dumping documents - there is a very deliberate methodology to it.
There was a good discussion on that article on HN a few days ago.
No matter what one might think about Assange the person and his style, his systems thinking is brilliant.
That would never be a good idea for a host of reasons (remember the lost laptop with personal info on it? other than leaking there are lots of reasons this is a bad idea)
This ban prevents the people who work in the government offices from bringing in music CDs and pictures on a thumb drive. Recall Pfc Manning was pretending to play Lady Gaga on a CD when he was burning all this stuff onto disk. That's it. There is no other reason to use removable stuff at work except to leak or bring in files like that.
I'm actually shocked this specific ban took so long. The contractor I work for banned CDs (burned or not) after the Sony rootkit incident, flash or floppy drives have been banned forever.
Sure, it's what he wanted, but that's part of the problem here. The government, like they always do, overreacts to fix the problem, and now even basic security measures could be hampered.
I'm pretty sure anyone stealing the data is already risking a court martial.
If the secret files are really so wide open that they're just counting on people not being able to take them, then there's some much larger problems that they better start addressing.
Also, I have a really hard time believing this one Private in the army could download hundreds of thousands of State department secret communications, then smuggle them out on CDs. Something is very broken if that's true. Either Manning is just a scapegoat, or there's massive security problems with secret information, or both.
It's a hard problem. Before 9/11, "the secret files" were locked down tightly, and every branch of the federal government that kept such files kept almost all of them separately; they were subsequently inaccessible to every other branch. The intelligence and law enforcement agencies came under harsh criticism following 9/11 — since information sharing was so limited, it was very difficult to correlate data and properly address targets and threats. The response was to pool a LOT more data than was previously available in one place on SIPRNet, which is accessible to intelligence agents, the State Department, the various military branches, federal and state law enforcement, and even some non-US allies. The truth is that the only files leaked to Wikileaks were not considered to be particularly important, had the lowest level of classification, and were accessible to (and could be easily shared by) over 3 million people.
The response will unfortunately be to lock down information sharing yet again, increasing the likelihood of intelligence and response failures in the future. Most of the federal government and idiot, grandstanding congressmen made the cable leaks into a much bigger event than it would have otherwise been had they not overreacted and simply "kept calm and carried on", and the US will face the self-inflicted consequences.
Secretary Gates had it right when he noted early on that, "I’ve heard the impact of these releases on our foreign policy described as a meltdown, as a game-changer, and so on. I think those descriptions are fairly significantly overwrought."
http://thecaucus.blogs.nytimes.com/2010/11/30/gates-on-leaks...
Anyone stealing the data, yes. I read the article as saying that people using remobvable media for purposes consistent with their jobs will now be subject to court martial.
Example: A machine is normally connected to the network. It is moved to another location and is not connected to the network yet. Someone using a thumb drive to copy a file from a machine on the network to the unconnected machine is breaking the new directive even if the thumb drive never leaves the office or is erased immediately thereafter.
Just an opinion of a paraphrasing of a leaked memo describing a directive...
Naturally this was hidden in a procedures manual several 1000 pages long.
But because the procedure dealt with encryption of classified data - the procedures manual saying how it had to be protected was of course secret! And couldn't be issued to the workers.
And not being connected to the network would be the only reason you need removable media. If your computer is not connected to the network, it isn't very useful. Barely anything is stored locally, the risk of someone walking off with the harddrive is too high.
What would stop you from connecting to Gmail (HTTPS) and emailing something to yourself?
However, a lot people use machines they don't control where this kind of approach is perfectly feasible.
I didn't deal with anything classified, but my understanding five years ago was that:
1. Any device that's gets plugged in to a secure system needs to have the red "this contains classified info" sticker on it. 2. Once a device becomes classified, it can never be plugged in to an unclassified system.
It sounds like the actual story is "military reviews, reiterates security policy in the wake of wikileaks scandal."
Ahem, back to politics ...
Flash drives have always been disallowed because of malware and virus issues, but CD's and DVD's were what we used to move data between non connected systems. This could be a real pain in the ass.
I'd think that all of these problems could be solved by simply logging disks that are removed from secure facilities.
Ok so who wants to charge the gov't $65 million+ for that? Throw encryption on it and charge $150 million.
"...classified computers are often disconnected from the network, or are in low-bandwidth areas."
Classified computers are almost always disconnected from the internet. In fact I haven't seen a computer with the combination of internet connection and approval to access classified documents.
So yes, they are low bandwidth. But all of the classified computers are networked together. Recall Pfc Manning pulled the files from a database that he leaked.
The bandwidth between the classified network and the nonclassified network is almost always zero or extremely limited (or might have to go through a person who literally weeds through the files one at a time and could accurately be described as "low bandwidth").
So any time you are circumventing that protection using removable media you are breaking the protocol. Just look at Stuxnet for the reason why other that Wikileaks.
Scenario: Anything copied to the USB device is internally encrypted, offline, with one of the military's public keys. This process requires no network-side authentication, but would require the soldier's "identity key" to also be plugged in and "sign" the contents.
Putting the storage device in a non-trusted computer means the contents are not retrievable.
To decrypt the contents of the device, you have to first authenticate to sirpnet from a trusted computer. It's then and only then that the computer is allowed to unlock the information on the removable drive.
This method is not safe to hardware reverse-engineering, but should be safe enough for operational use.
Presumably wired citing 'sources' means that some people are still willing to talk to the media about the information they received. Of course, 'hard' proof (actual copies) of stuff tends to be much more damning but you'll never be able to lock up that information carrier called the brain and it will hold plenty of bits of information.
What bugs me is that no government seems to have clued in to the most obvious and totally secure method of cleaning up their act and making sure that nothing worth leaking is done.
If the USB doesn't have the RFID, or it doesn't match the carrier or it has the wrong clearance code or the drive doesn't match the RFID ...alarms, guns, trouble.
Better yet, if they want to prevent leaks, just stop doing objectionable things. Especially to their citizens.
Though if your point is that someone can always leak, that surely is true. There are thousands and thousands of people with the classified information stored in their brains walking around in public all the time, and they choose not to talk about it. Really nothing at all stops them from just blabbering on about it at the bar after work. People are the ultimate security hole.
All this is does is prevent mass dumps like Pfc Manning did (alright, is accused of doing). He didn't read all of those papers he leaked, he just dumped them on a flash drive and walked out.