There are a wealth of things I don't know anymore... and no one else will ever hear them from me unless I am absolutely certain that it's been declassified and is in public access.
While a system that can be abused to protect people from consequences will never be perfect, in general those of us who have to work with classified information understand that adversaries getting hold of it means more danger for our own people.
I do not assume this, and if I had met anyone who expressed that kind of expectation, I would have mentioned it up the chain - they have self identified as a weak link.
Basically they tell you boots to STFU. And then then they base the rest of their decisions on the reasonable assumption that given time some of you will fail at that. Classic "defense in depth".
I'm guessing simply based on the numbers the likelihood of a tank manual leaking in some fashion (even accidentally), for any reason, is much higher than a fire control technician manual.
I would expect individual folks to do their job and not say 'well this will leak anyway'. But more generally I think expecting that 'this manual that we gave to thousands of people won't leak' would be absurd.
That second part is what I was getting at.
Some stuff is "over classified" but the definition of classified data is that which if disclosed is harmful to the national interest, and they actively seek to prevent leaks.
Tell me how long you think a given tank manual that goes into the hands of all sorts of people stays secret? That's where you assume ... yeah probably not long.
I understood your point, I just don't agree with your baseless assumption.
Once a colleague was having some problem calling a product API. He wanted coding help. I asked to see his code. He said "Sorry, I can't show you the code, it is classified". I asked, "Can you boil the code down into a Short, Self Contained, Correct Example (SSCCE)?" "I can, but that will be classified too." "How can an SSCCE be classified?" "The customer is an intelligence agency, every line of code we write while on-site is classified automatically, trying to get anything declassified is a bureaucratic nightmare". Eventually he agreed that he could go home, and try to write an SSCCE from memory at home, and that wouldn't be classified. In the process of doing that he worked out the problem himself, told me he didn't need my help any more.
That’s just weird.
I guess there’s a reason I’m not writing classified code, because I don’t think I could deal with such nonsense unless I happened to be writing a nuclear launch system.
I was very low on the totem pole, so I can't know for certain what leadership actually expects. But it doesn't jibe with my experience that there would be some kind of "leak budget" similar to Google SRE "error budget".
I think just from a super high level intelligence standpoint ... you know it is going to happen.
You are right. Security folks don't treat leaks lightly. Ever. This is part of how they maintain compliance with the rules.
But I don't think this is what the GP commenter talked about. You definitely design weapons, and doctrine and systems by assuming that it can leak to the enemy eventually. If your whole battle plan folds like wet tissue-paper just because the enemy got their hands on a single CAD file or manual then it wasn't a really good plan to begin with. Exhaust ports of doom are nice plot devices for movies, but in reality you try to avoid designed-in Achilles heels. And you do this because leaks happen.
Some information get leaked by carelessness, some by disgruntled employees, some are stolen by spies, some are picked up from a wreckage, some are stolen in transit, some are deduced from signal intelligence.
You can design mitigations against all of these. The scary security folks you mentioned are mitigation against the first two really. Their existence and behaviour doesn't have any bearing on what the leadership will expect.
While it's interesting from a opsec standpoint, there was no material loss of valuable information with the posting of this Challenger 2 data. The design and performance specs of a tank that has less than 300 units in use is a gnat on an elephant.
In a similar vein, about 20 years ago the NSA declassified the existence of their program, during the Korean War, to intercept and decrypt Communist Ground Control Intercept messages in real time and then pass the information to American fighter sweeps (the fighter pilots were told it was radar guiding them). While the NSA was happy to talk about the results of this decrypting, they haven't (at least as of the last time I checked a few years ago) released any details on what kind of codes the North Koreans/Chinese/Russians used even though obviously all three countries know exactly what they used and how it works. The reason given to me was that revealing even just how the NSA described these codes from half a century ago would reveal too much of how the NSA thinks about cryptography.