NSA employee indicted for transmission and retention of defense information
justice.gov
justice.gov
Mark Robert Unkenholz has this patent claim for key escrow: "Device for and method of cryptography that allows third party access" https://patents.justia.com/patent/5631961
Maybe that meant Unkenholz emailed a PDF marked TOP SECRET to his colleague in order to help some foreign entity harm US interests (obviously a terrible thing to do and worth being outraged about). But it could have also been him sending an email along the lines of "What SD cards did you order for [classified widget]? We're making more of them and I want to be sure I get all the same parts that you did for the prototype?"
Both cases violate the letter of the law, but locking a human being in a cage for a decade or more over the second one seems like a horrific misinterpretation of the concept of justice. Wish the press release was clearer on what side of the line this case falls on.
- Blaming people for accidents is stupid. Throwing them into prison for accidents is even stupider.
- Proper security is designed in a way that people can make mistakes and it doesn't mean the end of the world.
Him knowing better about this isn't really a response to OP's initial comment of being against a lengthy prison sentence.
The prison sentence accomplishes absolutely nothing. You're just ruining a person's life as they were retiring and breaking a family apart. Makes no sense if this was indeed an accident.
If he emailed a classified document, there is absolutely no way in hell that was an accident. You are never, ever, ever supposed to put classified information onto an unapproved system. This is like saying, "Oh, I forgot which pedal does which, so I slammed the gas instead of the brakes and killed someone, but it was an accident so I shouldn't go to jail." No, you're definitely going to jail, you 'forgetting' how to drive doesn't mean you didn't ruin someone's life.
(There's a small chance that he could have wrote something classified from his brain into the body of an email and sent it. People don't get sent to jail for this, provided it's a one-time incident. If he's getting charges pressed it was pretty egregious. The term "gross negligence" comes to mind.)
And it really could be that critical. Classified information is classified because it can be damaging. If you leak the names of people spying for you in foreign countries, they might be captured or even killed. How do you "design the system" to allow for that "mistake"?
Finally, the prison sentence lets people know that security is serious. There are many rules and it takes effort to follow them. People get lazy and cut corners when there aren't consequences.
People do stamp on the wrong pedal sometimes…if it's genuinely an accident I haven't heard about people going to jail?
Maybe a better one is a forklift operator dropping something on someone because they didn't do their company-mandated safety training and pressed the wrong button. It was an accident, the guy didn't mean to hurt anyone, but he did because he was negligent and there has to be consequences for that.
I literally don't get this "revenge" view point. Maybe we're just going to disagree here. The same way punishments don't work on dogs, children, etc. They also don't "stop" security incidents from happening.
Your example is bad because proper access controls would:
1. Be designed in such a way that humans can follow them and that humans __do__ follow them.
2. If humans can't follow them, then humans shouldn't be involved at all.
There are so many examples in this thread of "well this is against security training, but everyone does it anyway". That's a bad design. That's created for selective enforcement and makes the entire thing a joke.
EDIT: Sorry @dang I know I keep editing my comments a lot and you probably don't like that, but the more I think about it the more ridiculous these claims are the more miffed I get. Seriously, to all these people telling me that the NSA is just incompetent because someone went out of their way to commit a crime, imagine the following scenario: you tell someone a piece of classified information, they then walk over to an unclas computer and type that sentence in verbatim into their Gmail and hit 'Send'. Please design a crypto system, ACL, network architecture, workflow, any technical solution that could practically prevent that from happening across hundreds of organizations and probably millions of employees. I would bet you a lot of money you cannot.
1. Undoes the damage done by the leak.
2. Prevents further leaks happening in the future.
The only thing it does is ruin a person and their families life as they were entering retirement.
Exactly that, how is it possible to have access to Highly-secret stuff but also to your personal email? Something is not right here.
You could be told classified information, go home that day, and tell your wife the same thing. There is literally nothing they can do to prevent that except make sure people know there are consequences to doing so.
There are many such examples. Classified CDs is a good one. There are many rules related to classified CDs, but at some level you have to trust your people are following these rules. This is why getting a clearance is more difficult than the average job interview, and why people from the Intel communities take leaks so personally. It has to be part of the culture.
Funny that no one in a financial institute has access to private mail (Switzerland), USB is deactivated, to Surf the Web you need another laptop, no one has access to backups (Mainframe etc) without the knowledge of the CEO but maybe the data is more worth?
But yes at the end of the day you have to trust your peoples....but private email from your working-machine....that's borderline dangerous.
I hope not ;)
Well then it's like i said....there is something wrong ;)
On the subject of classification, that has no excuse.
So it’s very possible this could end with a far less significant penalty, depending on the circumstances.
This isn't reporting and it doesn't even purport to characterize the likely sentence except by saying “Actual sentences for federal crimes are typically less than the maximum penalties.”
Various information gets classified at different levels according to the classification guide for a program. It could be as simple as a program name in certain instances.
Now I doubt they'd prosecute for inadvertent inclusion of minor yet technically classified things, but it's hard to know.
See page 24+, in Security Classification Guidance Student Guide, for some examples of things in a classification guide. https://www.cdse.edu/Portals/124/Documents/student-guides/IF...
(The French had a solution for air gapping the brain, but productivity becomes a problem).
I love how whoever wrote this clearly does not understand technology, and thinks that somehow the _data_ was stored within the _address_.
I would like to see the indictment, if it's not secret itself. There wasn't a link, was there?
Just like how a long fall doesn't kill you, the sudden stop at the end does. It's a distinction without a difference.
Because you don't have knowledge of the subject.
The subject at hand being the law.
On the other hand, understanding formal logic is of practical value in the legal industry; I was thinking of building searches to find electronic documents which is a real thing that (clueless) people (try to) do. Seems to me like it could potentially be very high stakes, at least in hindsight if you screw it up.
I don't know if boolean logic is or used to be part of a law school curriculum. It just seems to me a bit surprising if it isn't.
To disrupt any empathic thoughts towards the defendant
As well as convey omniscience of the government
If not, I think it’s an effective idea someone should start doing, and i was inspired by reading a few indictments