How many people have Q Clearance?
blog.nuclearsecrecy.com
blog.nuclearsecrecy.com
If you clear millions of people, that sounds unsafe to the general public, but it isn't really because the clearance is only a confirmation that nothing is wrong in your background. It doesn't give you any access.
Is it possible that you actually learned some important private cryptographic key? If so, that number might have been sexy but you just didn’t actually have visibility into a bigger picture?
No, it was more like "this chainsaw cuts through 3 inches of wood per second and it falls apart in half a minute, so the amount of wood you can cut with it is [REDACTED]"
No, it was more like "this chainsaw cuts through 3 inches of wood per second and it falls apart in half a minute, so the amount of wood you can cut with it is [REDACTED]"
That actually sounds like a pretty secure password.
But where would the x or y have ever been written publicly?
In IT projects, most of us with any kind of clearance NEVER see anything controlled. But the clearance is needed in case we ever need to see controlled information, in order to write code, debug it, operate it, or train others to use the system.
Though some may eventually end up on a system or program whose very existence is classified. And that fact alone, is often not very special, and may be the only thing they ever "know" that's controlled.
Is this serious?
a lot of nuclear navy info is decades old and shares the same classification level of new, novel tech. suffice it to say submarines are doing cool things and i certainly dont know the half of it.
Us: “UFOs!”
Him: “Oh, you mean FUOU? That goes by CUI these days.”
Us: “No, UFOs like Aliens!”
Him: “GET THE HELL OUT OF MY OFFICE!”
So yeah, even with TS/SCI I couldn’t couldn’t get access to aliens :|
FOUO - A doctors patient list. That isn’t the business of the public and should not be released. That data does not contain PII, patient health data, and is not protected as a matter of security but it is still protected data.
Classified - Data that is restricted from public release. This is lowest level of protection and is intentionally vague.
Secret - Information that if disclosed can be used to harm people or disrupt government operations by adversaries. This includes information like convoy travel schedules and communications outages. Secret data is typically really boring office information in otherwise more exciting work.
Top Secret - This information, if disclosed, will likely result in embarrassment to the extent that national security or diplomatic relations suffer or that the intentional imminent danger of death or bodily harm occurs to people.
e.g. all Secret is Classified but not all Classified is Secret.
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/do...
if has_clearance(): grant_access()
but if not has_clearance(): reject_access()
as the first hurdle to jump.It sounds unsafe once all the information collected on those millions of people is placed in a central location and then hacked by or leaked to a nation-state level adversary.
If you said that 99% of them don't actually have power or access, it could be true, but irrelevant if an adversary has essentially 100% and unlimited resources to review them and double check the work.
>the clearance is only a confirmation that nothing is wrong in your background
In theory. The security clearance investigators are not perfect, and moreover, it's been publicly reported that sometimes contractors have falsified records showing they performed investigations. Statistically, X% are going to be flawed.
If an adversary has ~100% of the records, then think what they can do by reviewing them. Compromising someone doesn't require an earthshattering discovery because the cardinal sin is failure to disclose.
Let's say, for example, a person smoked pot a few times. From what I've read, that's generally not a big deal as long as you aren't doing it currently and don't lie about your history.
(The DOE rule seems to be that if you haven't used illegal drugs for two years, then they're not disqualifying per se, depending on a holistic look at a person)
But if an adversary has the entire investigation and every other piece of information that the federal government has on every employee, and they can determine that a given person did in fact conceal anything, then it is leverage to compromise them. Do X or you will be exposed as having lied. Or even "do X or you will be framed as having lied". It could be just enough to get someone to perform some action that further compromises them, and so on.
The more people this is done to, the more it snowballs. They could say "this higher up person works for us, so if you don't cooperate they will help us frame you for X". And it could be true, so how can a person verify?
If they have everyone's investigation, then all of the people who do have access to important things are at risk, and anyone who is truly spotless cannot be sure who is compromised.
Ancillary information like fingerprints makes it even worse, as all covert agents anywhere can in principle be detected and eliminated. This type of apocalypse being quiet, an absence of reporting on it wouldn't be evidence against.
I deduce that the whole scenario likely happened starting several years ago, based on public information, summarized at:
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
I am not making a categorical statement that seeking a cleared federal position is a mistake, but consider the gravity of the decision to trust the system if you do.
If people are saying it was hacked by country X, it might be strategic to share it with a couple other countries and let them cause chaos. Then, with clean hands, make speeches tut-tutting about the degeneracy of American culture and democracy.
Trying to orchestrate anything, by actually controlling the US government has a lot of potential downside, and what really is the strategic goal?
Presumably all the countries on the list that the US doesn't like want one simple thing - to be treated (as countries) equally to US allies. It's not necessary to make the US do anything, just to make us incapable of doing anything and unable to be trusted by allies. And that's inherently much easier than control. Not only that, but it doesn't require trust and cooperation among themselves to an unrealistic degree.
Exactly.
"Need to know basis." is the key phrase here.
The clearance is just the tag that gets you in the door. If you do not have a specific need to access the information to do your specific job, you do not have any right to access it.
AFAIK, deliberately taking steps to access info beyond your need to know -- even if it is within your clearance level -- is grounds for disciplinary action or prosecution.
So the TS/Q-cleared janitor, parts contractor, or engineer from the other project who gets found browsing in TS/Q file cabinet is waaay out of line,and likely in big trouble.
I was in a internal software tools department at a large company that did some classified work. Because I might need to interact with departments doing classified work I had to apply for Top Secret classification. This was required just in case I might have to get into those areas of the company to teach them how to use our in-house compiler.
(I didn't finish the process of obtaining the classification because of my desire to return to grad school in a different city. I never touched or even saw a classified document despite having Secret clearance already.)
(And in reality I didn't even need that because several people kept their lab key in plain sight on their desk in their open office 24/7...)
Not necessarily. Maybe in DoD land, but there's also a different system (uses similar terminology) for the State Department, and Department of Education (and some others) also has a thing called "Public Trust Clearance" and they involve different background checks (which aren't transferable). But the DoD clearance is the one that takes much longer to complete.
The DOE isn’t the CIA
Similar status applies to the ESA, ITER, and many others.
Bay Area lab, lot of weirdos (who I liked a lot) living in that creepy scene. Forces of control over a cute zoo of nerds.
1. Chinese blamed for stealing Los Alamos secret by stashing hard drives behind a copy machine and grabbing them later.
2. Chinese engineer at JPL worked there for decades and was thought to be a nice family in Pasadina - but lived in a really super spartan house and the wife was the engineer's handler and their kids were the mules to haul data back to ccp
3. China's trickle hack on Lockheed by phishing employees who had attended defense conferences
4. China hacking Lockheed providers in Taiwan with an air gap and sneaker-net to gain access to Lockheed laptops via USB exploits (this was one of the factors, IIRC why epoxy in USB ports was common) -- ((But if you ever had any SGI O2 machines -- there was an additional port (serial I think - I don't think they were USB) but this 'option' was several thousand more $ -- but it was on every machine and all you had to do was punch out the plastic cover from the case)
5. Israel + USA hacking Iran via STUXNET in the same method with air-gaps etc.
6. The guy who worked at oak ridge, took on a Russian Mail Order Bride and got her a job in oak ridge (accounting I think, I can't recall) -- and it turned out she was a Russian handler, but they denied it -- but everyone knew that every single person from the USG who went to Russia was assigned a female handler, and these handlers were highly trained, and they had several levels of handlers above them to ensure non-defection chain-of-custody-of-intel.
---
I had a few more specific to nukes - but I got distracted - Ill update if I recall the others.
Some of the above have REALLY good documentaries on them. Some of them are known by fewer people - but they are not secret breaches... they got memory-holed.
1. https://www.nytimes.com/2000/06/17/us/missing-nuclear-data-f...
2.? -- https://en.wikipedia.org/wiki/Wen_Ho_Lee (I am not sure if I am conflating these with another case.)
5. https://www.youtube.com/watch?v=rOwMW6agpTI
6. I cant find 6..
I was watching this at the time and... yeah, ex Q cleared at the time, and NYT revealed some of its underlying profit driven sleazy motivations with that hack job.
The others could be legit, I have no idea. But be careful before the evidence gets brought to trial and a guilty verdict is obtained.
Snowden showed and I can confirm, from decades earlier, there's a lot of workarounds going on daily just to get shit done. Some were absurd.
Well you're going to apply for it but you're not necessarily going to get it.
Either way, we have propensity to over classify things in the government and that's a whole other argument.
Exactly the thing I was thinking after reading just the title. Glad to see he got a response and published it here!
Site is down now, but:
April 2018 – 87,113
April 2019 – 90,454
April 2020 – 98,103
April 2021 – 92,177Most of these people wouldn't have any actual access, they just have the clearance that would allow them to have access if they are in a role that requires access.
And of course, our friend Need To Know is always in play.
Note, one of the very unusual things about a Q is access control for both information AND physical material.
<<
Q: Back up a minute! You just mentioned a "Q" access authorization. What is that and how does it relate to the Top Secret, Secret, and Confidential clearance terminology I'm familiar with?
A: Top Secret, Secret, and Confidential security clearances refer back to the level of National Security Information to which an individual may have access. Because DOE is granting access to Restricted Data and special nuclear material, it uses different terminology. Generally speaking, there are two types of access authorizations, the L and the Q. The L access authorization corresponds to the background investigation and administrative determination similar to what is completed by other agencies for Confidential and Secret National Security Information access clearances and the Q access authorization corresponds to the background investigation and administrative determination similar to what is completed by other agencies for a Top Secret National Security Information access clearance. In addition, because RD information is more sensitive than NSI information, access to Secret Restricted Data requires a Q access authorization.
>>
[1] https://www.energy.gov/ehss/security-policy-guidance-reports...
I was working with rad-hardened semiconductors in the context of weapons effects as well as natural space radiation.
Clearances just standardize that, so you can trust that it's been performed within X years. You still don't share material without a requirement, you've just outsourced the other half.
I had a clearance doing tech support, but never even saw actual classified materials. But because as IT support we also had to support SCIF facilities, high-ranking officials with potentially sloppy OpSec, etc we obviously still needed clearances.
So, no shit you're speculating, and I very well may have been lied to by the person attempting to recruit me to the NSA. I didn't want to live in secrecy; soon thereafter, Thomas Drake's reports confirmed my suspicion that the NSA wasn't as white-hat as I'd been told.
Q clearance is anyone with a CNWDI modifier, so that's secret and top secret.
I think clearence has been overused as a dramaturgical element a lot but it sure as hell sounds cool.
Access to some security comparments ("Sensitive Compartmented Information") might require both a need to know, and either a Counter-Intelligence or Full Scope polygraph examination. If you have a current (non-expired) TS/CI Poly or TS/FS Poly investigation, could be quite valuable to a defense contractor, because it can take a while (potentially months or years) and cost $$$ for you to get that investigation, which combined with the need to know, would be necessary to get you access to certain classified compartments which might be necessary for you to work on a particular project. Otherwise, you might have the necessary computer skills, but without having the requisite security clearance investigation having been done on you, the defense contractor might have to hire you and have you work on non-classified aspect of the projects for months and months (or if you are a new college grad, maybe even twiddling your fingers) until the security clearance investigation had been completed.
And basically everyone with the SCI designation could get a call to get a poly anytime, but I've never had one and know people who've had their clearances for years without getting that call (and I know a couple people who had them before the government finished that person's background investigation, so go figure). Some agencies care quite a bit, others not at all.
My boss told me, "just assume they know the answer to any question they ask and tell the truth, regardless of what it is."
Realistically, they are probably very effective at verifying whether normal people have secrets that could be used for blackmail, as you say, because of the psychology, even if the machine isn't actually doing anything.
Anecdotally, I've heard of security interviews (for government intelligence, I can't give context) where the interviewer just says "i'll know if you lie". For the average person this is enough to make them flustered if asked an awkward question.
https://www.reuters.com/article/us-usa-trump-clearances/whis...
https://krebsonsecurity.com/2016/09/congressional-report-sla...
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
That number is classified.
As of 2017, approximately 2.8 million people held TS[1]. A sizable percentage of those people are also probably TS//SCI.
Edit: Uncited, from Wikipedia:
> In general, military personnel and civilian employees (government and contractor) do not publish the individual compartments for which they are cleared. While this information is not classified, specific compartment listings may reveal sensitive information when correlated with an individual's résumé. Therefore, it is sufficient to declare that a candidate possesses a TS/SCI clearance with a polygraph.
[1]: https://about.clearancejobs.com/hubfs/Clearancejobs_Images_N...
Then you quote TS clearances. With a guess at how many have SCI access.
The amount of people who have TS/SCI clearances with a Full Scope Polygraph is classified.
It’s a fast track to a high level position at one of the nuclear defense labs doing amazing work (fusion, defense, detection, etc).
It’s non-binding (I currently work in tech), and highly supportive of the individual fellows.
I've gone through DOE/NNSA processes and what I needed for plant access (pentesting for a utility) was through NRC and a bit different.