US Soldiers Expose Nuclear Weapons Secrets via Flashcard Apps
bellingcat.com
bellingcat.com
Just a sign of how deeply flawed the base of our thinking about information is these days. Everything is public by default, in part because of the warped Google/Facebook worldview has been drilled into us by the likes of Schmidt and Zuckerberg.
Seeing it used that way was a real "a ha!" moment. I'd love to know what Venmo's activity looks like around the time that people are putting together or paying out office sports brackets and such.
1. It's more honest. With Facebook, you are given the illusion of sharing information only with your friends, but it's actually ...with your friends, and Facebook, and anyone Facebook chooses to share it with. Cambridge Analytica being the highest profile example. When you tweet, the expectation is that whatever you said is now On The Internet, a matter of permanent record.
2. It opposes the network effect. Twitter doesn't force me to create an account in order to view a tweet. Or, from the other perspective, if I post on Twitter, I'm not requiring anyone who wants to read my stuff to sign up as well. It's closer to a microblogging platform.
e: On second thought there probably are exceptions - I'm not worried that something backed up to Backblaze will be leaked, for example. But a random flash card app? I'd assume that info is public. Maybe I'm just paranoid.
This is why it's important for things like password managers, personal documents, etc. to be encrypted client side if backed up or hosted somewhere on another machine that isn't yours.
A good line that I've seen people use on this forum: "the cloud is just somebody else's computer".
*[Hans Kristenssen, director of the Nuclear Information Project at the Federation of American Scientists] added: “There are so many fingerprints that give away where the nuclear weapons are that it serves no military or safety purpose to try to keep it secret. Safety is accomplished by effective security, not secrecy. Granted, there may be specific operational and security details that need to be kept secret, but the presence of nuclear weapons does not. The real purpose of secrecy is to avoid a contentious public debate in countries where nuclear weapons are not popular.”
This seems to depend on your threat model. Two threat models were explicitly mentioned here - terrorists, and contentious public debate.
But it seems a third threat model, and the most important one given that nukes are anti-nation-state weapons, is to prevent nation state adversaries from knowing with certainty the location of those nukes. In which case, secrecy is still a necessary component of nuclear safety, or more specifically, deterrent effectiveness.
>"There are so many fingerprints that give away where the nuclear weapons are that it serves no military or safety purpose to try to keep it secret."
Yes exactly. One necessary, but not sufficient, layer of a multi-layer defense-in-depth security strategy.
If I were the supreme commander of a nuclear power, I wouldn't even want to know where the enemy subs are. I'd make sure the military isn't trying too hard to find them. That's because A in MAD stands for "assured". Nuke-carriyng submarines are often billed as first-strike weapons, but arguably their main role is being a backup - an assurance that, no matter how effective your first strike is, you are going to be glassed in retaliation. So, your submarines check the enemy, enemy submarines check you, and the standoff continues.
If you can credibly threaten to detect enemy nuclear-armed submarines, then the enemy has a strong incentive to launch a first strike immediately, before you've completely neutered their subs.
Unfortunately, it was just a really long run :)
Joel, btw, dead/typo'd link top of this list: https://joelrunyon.com/impossible/
Have a good day, everyone!
Nominative determinism
For example, this one appears to list a number of installations that hold various critical networking infrastructure as well as the names of various admins. https://quizlet.com/414907821/eiws-study-guide-here-it-is-bo...
I'm only familiar with this being used for really mundane training, so OPSEC and FOUO[1] info being posted is surprising.
[1]: For Official Use Only, which was recently changed to CUI (Controlled Unclassified Information).
For example [1] is basically a standard police academy study guide, but it also has the names of which armored car services are allowed entry to post, which parking lots are used for storage of nuclear materials during Safe Haven event, [2] has real world and exercise countersigns mixed in with non-sensitive form names and acronyms. Another one had a list of duress words (all named after spices), though it says these are changed every six months. A lot of stuff you could guess easily but still identifies weaknesses (ex. school buses can get on base with a district badge, which is nowhere near as hard to copy as a CAC). [3] has the location of a SCIF. Some other ones had room numbers of buildings containing information networking infrastructure (no public map, but googling the building number returned a picture of the facility from the architect's site).
I'm not military, so I'm curious how big of a deal this is relatively? Like is this stuff that a credible attacker could easily find out anyway or is it actually a major weakness?
[1]: https://quizlet.com/411678831/qc-questions-flash-cards/ [2]: https://quizlet.com/347943371/bdoc-flash-cards/ [3]: https://quizlet.com/478059813/iec-qc-flash-cards/
Sounds like a post promoting the idea of having a more general purpose but secure app using the stuff they already built within the AF, rather than saying it is already widely available.
I didn't, though. Thanks!
US compliance systems often favour rote learning over knowledge, hence memorising vast numbers of irrelevant details as a false proxy for competency.
To monitor actively, you have to ask for related content. Asking about related content in a context where you have something to keep secret is an implicit acknowledgement there is something there.
It's a trick I've seen used in intelligence gathering contexts quite often. You get close to a researcher and technical expert on classified matters, then ask questions and gauge responses.
Sometimes you don't need an answer, you just need to know you're asking the right questions.
Knowledge of this practice and regular experience doing it will not make you many friends in either the intel or counter-intel dept.
t. Apparently a professional insider threat given all the DoD documentation that describes how I fix places by actually communicating with people and ensuring effective information dissemination through an organization.
Makes interviews awkward. All the periodicals in the waiting room basically explain what I do better than I can.
The interpretations of this pseudoscience can have devastating effects on your career, and not being based on facts or anything truly measurable, you have effectively zero recourse against such destruction, whether willful or otherwise, because it's elevated to the status of "evidence", simply because "the machine said it!"
https://antipolygraph.org/pubs.shtml
What's worse is that the failings of this pseudoscientific nonsense are well known to the USG, and yet this continues for decades to be central to the system of ostensible "trust" in those who keep government secrets. It's abusive. (Imagine if your government health insurance only covered crystal healers.)
How do you know they aren't? They're probably focused on adversary nations, though.
Just gobsmacked by this, honestly.
Very little software these days simply just runs locally and does the thing it's supposed to do on your own device without transmitting your private information to a datacenter (usually owned by a giant US corporation). This is a problem for all of society (especially those companies and users outside of the US), not just runners on secret bases or students in missile sites.
When I was dabbling in apps and mobile apps, I encountered several unintended benefits of the data I collected which had nothing to do with my original purpose or vision. This reminds me of that.
As an engineer, I got some training by legal, followed up by a high level exec explaining to us that in this context, we report only to legal and are required to say "no" to engineering leadership when something would go against legal's policies.
Also I think the military has something similar with medical officers.
So it could be done right.
The phrase is "Halt politie, leg uw wapens neer! Handen op."
There is no part of this sentence that would be unique to Flanders. In fact, "Handen op" is something I would expect to hear from Dutch people and never from Belgians, in Belgium it would be "Handen omhoog", but both ways the sentence is correct and would be be perfectly understood in both countries.
I'd also expect that the small inconsequential and intricate differences between the way Dutch is spoken in Belgium compared to the Netherlands are not taken into account in this context - they probably use the same for both countries, which would make sense considering it's already difficult enough. I think Bellingcat is emBellishing.
Were soldiers sharing flash cards or were they unknowingly posted online? The selling point for some flash card apps is lots of preexisting cards to study with and presumably app users are the ones creating them. That should hint that they’re stored online.
It would be great if app stores noted network access requirements. Does an app operate standalone? Is Internet access required just for ads or also for functionality? Where is app data stored? On your phone, in personal cloud storage, in a shared storage service just for users of this app or shared to the general public?
While Apple’s app store mentions none of this, there is a link to the privacy policy for each app. I’m not familiar with Google’s app store.
I wish browser extension repositories also provided network access requirements for each add-on.
[0] https://webcache.googleusercontent.com/search?q=cache:85ved4...
[1] https://webcache.googleusercontent.com/search?q=cache:fNJwlH...
Yet they don't do the same when investigating Russia - tables of private data were revealed there, together with details of military vehicles.
Makes you think about bellingcat motives.
Understanding an argument and agreeing with it are not the same thing. I understand the premise and argument for spaced-repetition algorithms, but I do not agree that these algorithms provide a meaningful advantage over paper cards when you consider that paper cards must be written. The act of handwriting cards is an advantage paper cards have over software cards, which I believe more than offsets any algorithmic advantage the software cards have.
These service members are clearly real chuckleheads though.
Surely a gamma ray detector pointed at the building long enough will detect signs of radioactive substances inside, even if well shielded.
Heaven help us.
Maybe a bad US actor deliberately leaked the information, but in a way that make it look accidental.
Or maybe the ex-President already leaked it in a private meeting, so it doesn't matter.
USSR spooks been for decades deducing troop numbers, and rotation schedules on NATO bases based on patterns in service numbers.
Not much changed since it seems.
Though, same was done for Russian troops in Crimea.
Any links or sources for this?
And as to them being a "limited hangout sock puppet" you're of course not going to find any source on this - because it's not known for certain - but in my opinion they are most likely something akin to that. They frequently get leaked information from US/UK intelligence organizations and they launder stories for CIA/MI6s. They might not know they are a limited hangout sock puppet for western intelligence but they certainly function as such. A good example is their actions around the OPCW leaks and claims of chemical weapons in Douma, Syria [4]. A lot of these stories unfold on Twitter so you'll have to search around
You can also search on HN - there's comments from many years past calling out Bellingcat as a front for western intelligence.
[1] https://twitter.com/search?q=from%3AEliotHiggins%20ned
[2] https://williamblum.org/chapters/rogue-state/trojan-horse-th...
[3] https://podcastaddict.com/episode/121232504
[4] https://thegrayzone.com/2021/03/24/author-bellingcat-opcw-wh...
Also, why do you think a CIA-affiliated site would do a write-up on this? Seems like it makes soldiers and their secure info look bad.
Dolan came up with Matt Taibbi and Mark Ames in the eXile ( Moscow in the 1990s! Wow!) then did his own thing. Ames wrote `В Россию с любовью` sometime in the aughts. Taibbi we all know.
They're all still best buddies; who knows what kind of crazy stuff they got up to in 90s Moscow. Funny stuff.
If it is true, the CIA doesn't much like Israel's habits in Palestine.