Finally, this was clearly careless on the part of the Intercept, no proof has ever been given that this was malicious, and I'm not seeing any here.
Finally, this was clearly careless on the part of the Intercept, no proof has ever been given that this was malicious, and I'm not seeing any here.
Basically not very different from how major motion picture studios embed some sort of unique ID code into the compressed video files given out pre-release, to reviewers (and workprints sent to 3rd party CGI studios) so that they can track down a leak.
None of which Winner was aware of the existence at the time. Some of those codes made it through to the reporting, and were published to the Internet, making it fairly easy for federal law enforcement to track her down.
I have also not seen any information saying that the journalists who received the documents, definitively were, or were not aware of the presence of the ID numbers stegoed into the documents.
https://www.theatlantic.com/technology/archive/2017/06/the-m...
https://blog.erratasec.com/2017/06/how-intercept-outed-reali...
On a more meta level, it's a hard problem to solve with handling and publishing leaked documents, because on one side you have the vast resources of the NSA and the US intelligence community coming up with new steganographic and other methods to embed tracking ID numbers into documents. The full size, scale, budget and weight of various federal agencies' "counterintelligence" efforts.
And on the other side you have investigative journalists who do not have PhD level degrees in math/cryptography, and do not have the technical resources to definitely search through a huge pile of documents and say with 100% confidence that any possible tracking IDs have been stripped out.
I don't think I could reasonably expect a person from a journalism/liberal arts degree educational and work experience background to identify steganography.
All modern printers have this steganography feature.
"In October 2004, consumers first heard of the hidden feature, when it was used by Dutch authorities to track down counterfeiters who had used a Canon color laser printer." [1]
This is written in "PC World" in 2004 by journalist Wilbert de Vries. He now works for Tweakers, back then he worked for Webwereld. 2004 was mid-end heydays of Webwereld. I'm quite sure I read about this technology on Webwereld back then.
Later on, this got covered on CCC as well, not sure which years.
My point / opinion? The Intercept could have known (see above), and, given he nature of their content ([2]), should/ought to have known.
[1] https://en.wikipedia.org/wiki/Machine_Identification_Code
[2] The fact they had Greenwald/Poitras on board says enough (they were key figures in the Snowden leaks). You can look at their content from the era 2017 if in doubt.
The fact that the Editor-in-chief did not ensure their own processes were followed for an NSA leak is a failure.
But it's certainly possible that they simply failed here. That possibility warrants an internal investigation, to determine the nature of the failure, and to signal internally and publically that they take their responsibility to sources seriously.
No organization likes to be criticized from within. But some organizations are strengthened by their reaction to criticism (whatever the source), and others are diminished.
Laura Poitras is a credible party. I'm inclined to believe her side of the story here.
Related (though not directly): Bellingcat is doing impressive work. https://www.bellingcat.com/
I agree with nearly everything you said, except this.
As others have noted, this sort of document tracing has been deployed and well-known for a long time. I would expect investigative journalists working the NatSec beat to have read a bit of other NetSec investigative journalism, and mention of things like this come up fairly regularly. Not to mention, contact with people like security researchers, EFF staff, etc. will all tend to expose you to information like this - it is part of the paranoid air people who discuss this stuff breathe.
Also, a bit of tradecraft is just part of an investigative journalist's job.
If I recall correctly, the Intercept people weren't accused (by anyone serious) of intentionally outing her, just of being dangerously incompetent to collaborate with.
Correct.
> Finally, this was clearly careless on the part of the Intercept, no proof has ever been given that this was malicious, and I'm not seeing any here.
Maybe not malicious, but definitely haphazard; they're dealing with incredibly sensitive information, from people in intelligence agenecies who do not hesitate to neutralize a potential threat. In all honesty, Reality got off easy, after the Snowden and Manning/Assange sagas it beceome clear the US has will not hesitation to chase people to the ends of the World, and in apply what the UN has stated to be torture in Assange's case, and outright inhumane pressure in Manning's case that has forced her to attempt suicide. I wouldn't be surprised if many of these leaks don't eventually end up with trips to a rendition camp under the guise of 'national security' the way some of the most jingoistic in Washington speak and vote and this goes for both R/D parties.
I honestly want to see Laura on a massive platform like Joe Roan so she can go in depth on OPSEC and INFOSEC for the common non tech user told from her very relevant position and elaborate on the many misgivings from the Intercept--it's very telling that Glenn, Laura and Edward have all departed from it and there seems to be a common theme here.
I'd also like to hear what Laura has to say about Jacob Applebaum's departure from the TOR Community for so long now, she touched on her relationship with him in her last documentary about Assange. I really miss Jacob's State of the Onion speeches at the CCC and him being a general thorn in in the side of most Nation states security apparatuses. Something never really felt right about his rape accusations, as they tried to get Julian on similar charges in Sweden with nearly no evidence and just a massive media campaign, but succeed in making Jacob a pariah as he is no where to be seen--even when his close friend and possible mentor Assange was wasting away in jail.
Typing the whole leaked document into a brand new Word file does not require experienced background and would protect your sources against most steganography tricks
There are still variations in word ordering, word choice, included/omitted subtle details, etc. to watch out for.
An 'intelligence specialist' doesn't know about protecting the source, I don't think so ;]
I don't understand this point at all. Identifying oneself as a source to a journalist is a critical and important part of being a whistleblower. The Intercept could never have published anything without some authentication of where it came from. You think you can just mail some documents anonymously and papers will run with it?
I mean, maybe you could argue that in the case of specific kinds of documents that are self-authenticating, I guess. But in general, no, journalists need to know where stuff comes from. Ellsberg didn't hand over the Pentagon Papers anonymously, Deep Throat was known to Woodward & Bernstein, etc...
I see the link talking about self interest and negligence.
Poitras and others have painted a grim picture of the processes and the lack of introspection / transparency that followed Winner's capture. That lack of accountability for those in charge now hangs over the entire organization.
As Poitras says, journalists make mistakes, and it's understandable. But in the response to them, the Intercept leadership seemed more interested in protecting their own skins than in addressing the concerns brought to light.