If you clear millions of people, that sounds unsafe to the general public, but it isn't really because the clearance is only a confirmation that nothing is wrong in your background. It doesn't give you any access.
Us: “UFOs!”
Him: “Oh, you mean FUOU? That goes by CUI these days.”
Us: “No, UFOs like Aliens!”
Him: “GET THE HELL OUT OF MY OFFICE!”
So yeah, even with TS/SCI I couldn’t couldn’t get access to aliens :|
FOUO - A doctors patient list. That isn’t the business of the public and should not be released. That data does not contain PII, patient health data, and is not protected as a matter of security but it is still protected data.
Classified - Data that is restricted from public release. This is lowest level of protection and is intentionally vague.
Secret - Information that if disclosed can be used to harm people or disrupt government operations by adversaries. This includes information like convoy travel schedules and communications outages. Secret data is typically really boring office information in otherwise more exciting work.
Top Secret - This information, if disclosed, will likely result in embarrassment to the extent that national security or diplomatic relations suffer or that the intentional imminent danger of death or bodily harm occurs to people.
e.g. all Secret is Classified but not all Classified is Secret.
https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/do...
Is it possible that you actually learned some important private cryptographic key? If so, that number might have been sexy but you just didn’t actually have visibility into a bigger picture?
No, it was more like "this chainsaw cuts through 3 inches of wood per second and it falls apart in half a minute, so the amount of wood you can cut with it is [REDACTED]"
No, it was more like "this chainsaw cuts through 3 inches of wood per second and it falls apart in half a minute, so the amount of wood you can cut with it is [REDACTED]"
That actually sounds like a pretty secure password.
But where would the x or y have ever been written publicly?
a lot of nuclear navy info is decades old and shares the same classification level of new, novel tech. suffice it to say submarines are doing cool things and i certainly dont know the half of it.
Is this serious?
In IT projects, most of us with any kind of clearance NEVER see anything controlled. But the clearance is needed in case we ever need to see controlled information, in order to write code, debug it, operate it, or train others to use the system.
Though some may eventually end up on a system or program whose very existence is classified. And that fact alone, is often not very special, and may be the only thing they ever "know" that's controlled.
It sounds unsafe once all the information collected on those millions of people is placed in a central location and then hacked by or leaked to a nation-state level adversary.
If you said that 99% of them don't actually have power or access, it could be true, but irrelevant if an adversary has essentially 100% and unlimited resources to review them and double check the work.
>the clearance is only a confirmation that nothing is wrong in your background
In theory. The security clearance investigators are not perfect, and moreover, it's been publicly reported that sometimes contractors have falsified records showing they performed investigations. Statistically, X% are going to be flawed.
If an adversary has ~100% of the records, then think what they can do by reviewing them. Compromising someone doesn't require an earthshattering discovery because the cardinal sin is failure to disclose.
Let's say, for example, a person smoked pot a few times. From what I've read, that's generally not a big deal as long as you aren't doing it currently and don't lie about your history.
(The DOE rule seems to be that if you haven't used illegal drugs for two years, then they're not disqualifying per se, depending on a holistic look at a person)
But if an adversary has the entire investigation and every other piece of information that the federal government has on every employee, and they can determine that a given person did in fact conceal anything, then it is leverage to compromise them. Do X or you will be exposed as having lied. Or even "do X or you will be framed as having lied". It could be just enough to get someone to perform some action that further compromises them, and so on.
The more people this is done to, the more it snowballs. They could say "this higher up person works for us, so if you don't cooperate they will help us frame you for X". And it could be true, so how can a person verify?
If they have everyone's investigation, then all of the people who do have access to important things are at risk, and anyone who is truly spotless cannot be sure who is compromised.
Ancillary information like fingerprints makes it even worse, as all covert agents anywhere can in principle be detected and eliminated. This type of apocalypse being quiet, an absence of reporting on it wouldn't be evidence against.
I deduce that the whole scenario likely happened starting several years ago, based on public information, summarized at:
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
I am not making a categorical statement that seeking a cleared federal position is a mistake, but consider the gravity of the decision to trust the system if you do.
If people are saying it was hacked by country X, it might be strategic to share it with a couple other countries and let them cause chaos. Then, with clean hands, make speeches tut-tutting about the degeneracy of American culture and democracy.
Trying to orchestrate anything, by actually controlling the US government has a lot of potential downside, and what really is the strategic goal?
Presumably all the countries on the list that the US doesn't like want one simple thing - to be treated (as countries) equally to US allies. It's not necessary to make the US do anything, just to make us incapable of doing anything and unable to be trusted by allies. And that's inherently much easier than control. Not only that, but it doesn't require trust and cooperation among themselves to an unrealistic degree.
if has_clearance(): grant_access()
but if not has_clearance(): reject_access()
as the first hurdle to jump.Exactly.
"Need to know basis." is the key phrase here.
The clearance is just the tag that gets you in the door. If you do not have a specific need to access the information to do your specific job, you do not have any right to access it.
AFAIK, deliberately taking steps to access info beyond your need to know -- even if it is within your clearance level -- is grounds for disciplinary action or prosecution.
So the TS/Q-cleared janitor, parts contractor, or engineer from the other project who gets found browsing in TS/Q file cabinet is waaay out of line,and likely in big trouble.
I was in a internal software tools department at a large company that did some classified work. Because I might need to interact with departments doing classified work I had to apply for Top Secret classification. This was required just in case I might have to get into those areas of the company to teach them how to use our in-house compiler.
(I didn't finish the process of obtaining the classification because of my desire to return to grad school in a different city. I never touched or even saw a classified document despite having Secret clearance already.)
(And in reality I didn't even need that because several people kept their lab key in plain sight on their desk in their open office 24/7...)
The DOE isn’t the CIA
Not necessarily. Maybe in DoD land, but there's also a different system (uses similar terminology) for the State Department, and Department of Education (and some others) also has a thing called "Public Trust Clearance" and they involve different background checks (which aren't transferable). But the DoD clearance is the one that takes much longer to complete.
Similar status applies to the ESA, ITER, and many others.