Leader of Online Group Where Secret Documents Leaked Is Air National Guardsman
nytimes.com
nytimes.com
Another problem with clearances in general is that often those eligible come from less diverse backgrounds due to parental citizenship considerations. fields that require a clearance are often less diverse because of this.
People who have some time in the military probably won't be surprised if the situation is what the media is portraying it to be. As Abraham Lincoln pointed out about the US, the biggest problems for the country will come from within.
https://www.washingtonpost.com/national-security/2023/04/13/...
UPD They changed the wording, the current version:
>Teixeira told members of the online group Thug Shaker Central that he worked as an technology support staffer for the Massachusetts Air National Guard and at a base on Cape Cod, and this was how he was able to access classified documents, one member of the Discord server told the Post.
Or its a Snowden situation and he has access because he has privileges on the system due to being a sys admin of some sort.
I grew up outside DC and every so often you hear of the security clearance spooks interviewing you or someone you know about some jamoke you went to high school with to determine if they're a security risk. They also ask those people really difficult questions, like, "Would you use drugs at work?" "If you did, would you download illegal documents?" "If you did get high at work and download illegal documents, would you post them on Myspace?" About half of the people actually fail to answer those questions in the expected way. The other half make 200,000 dollars a year from a subcontractor of a subcontractor of Northrop Grumman pushing paper at a desk all year.
It's a national disgrace.
It's one thing for an IT admin on a Massachusetts national guard post to get access to a few local secrets. It's another when he's downloading hundreds of documents unrelated to his duties on a war thousands of miles away.
Your average file share or web server for a medium-sized corporation with a negligible amount of confidential data probably has that level of monitoring, it's not particularly surprising that the slower-moving military doesn't yet but it probably should.
But just getting a security clearance isn't enough to have access to "all this information", right? My understanding has been that getting security clearance can make one eligible to do work which would involve some specific sensitive information, but that stuff is still meant to be compartmentalized. There's no reason people who are working on e.g. the supply chain for some radar component need to have access to intel on some other country's chemical weapons and vice versa.
This situation is sort of intentional: one of the big findings of the 9/11 commission is that intelligence information was too siloized and analysts were missing big things because they didn't have access to products of other agencies. But there's a balancing act here, and this is the downside of open access.
I'm realizing my initial impression of the landscape here is also skewed by some peripheral awareness of how government contractors may have narrow access to specific material for their work. I understand why intentionally, some actual government employees have a much broader view. But how large is that group with broad access?
Even better, a 2016 article about TS Intellipedia [2], the MediaWiki install on JWICS, says it has "255,402 registered users." That's probably pretty similar to the JWICS user count at the time.
[1] https://fedscoop.com/jwics-modernization-dia-douglas-cossa/
[2] https://www.businessinsider.com/nsa-version-wikipedia-called...
I can't see how those could sensibly be in the same domain. I imagine it's about like any other huge collection of data, with large variance in how well things are categorized and restricted.
That's what happens when you don't want the government to spend money actually hiring skilled employees. Instead we waste money trying to not waste money. The government could pay a very skilled developer $150k/year + benefits. But certain people think that the government only wastes money. So we can't have public sector employees making comparable wages. Instead we pay a "contractor"[1] $200k/year where the contractor gets $110k of that and the employer takes the other $90k.
[1] They are de facto public employees
we've been losing a great deal of technical expertise recently to industry, where Fortune 500s are offering compensation packages 200% to 250% higher than the current compensation of federal contractors & technical civil servants.
No, it's s a national sport.
>When Times reporters approached the house again, the truck was parked in the driveway. Airman Teixeira’s mother and a man were standing outside in the driveway.
>When asked if Airman Teixeira was there and willing to speak, the man said: “He needs to get an attorney if things are flowing the way they are going right now. The Feds will be around soon, I’m sure.”
Looks like he didn't try to flee.
As I just posted[0], my local news just showed video of folks in military garb handcuffing a young guy in mufti.
They say it was Jack Teixeira and I have no reason to doubt that.
They focus on the perimeter and who gets access and how.
They essentially have RBAC but not mandatory access control. Your role gets you past a perimeter or a security control but access to data is granted implicitly not explicitly.
What the infosec community has learned is that defense is best done "in depth" or "layered". Even if he needed that information for his work and permission was given to him explicitly why was he allowed to download files? Why was he able to get any sort of electronics in or out of any facility that stored top secret information? How come there was no DLP or hard to defeat watermarking on documents? Document canaries to detect a leak? I mean even in a typical corporate O365 deployment, you can classify documents so that they are encrypted by MSIP so even if you take the document home and open it, you need to authenticate to decrypt it (and that is logged of course), he can take screenshots but you can monitor that too and he needs to get that screenshot out (and hopefully TS clearance computers don't have internet access or USB ports or mass storage device support).
I don't agree that the problem is a million people have clearance. That clearance should mean you will be allowed to request access to documente and have that granted if you need those specific docs, it shouldn't mean access is implied.
And a bit controversial take: this is why the USG can't go easy or forget about assange or snowden and others. They can make a case in court or convince a jury they had no option but to leak classified info but DoJ would be incompetent if it didn't go after all leakers regardless of context.
Makes you wonder if Russian agents somehow got in his head. Impressionable 21 year old kids with access to the boss's computer to update IE will do stupdi things for the "100" reaction emoji on Discord.
Main reporter tweeted:
> (Found him through his Steam profile, will write a step-by-step on the process at some point)
Is it a young guy in a brown/grey t-shirt and red shorts with his hands on his head walking backwards past what appears to be an Army truck and being handcuffed by armed folks in military garb?
If so, then yes.
They should be able to track his e-mail and his access and already know whether or not he accessed the documents directly.
It would be on other bodies (correct me if I'm wrong) to review and adjust the internal practices around the handling of confidential documents, and how this can be prevented moving forward.
Edit: Aaaaaaand he's in custody.
1. Swoop in and arrest them immediately
Or 2. Do comprehensive physical and electronic surveillance for say 24-72 hours to see if they try to get in contact with foreign nationals, and investigate whether they have a "dead man's switch" to release more documents?
Option 2 makes more sense to me. When cleaning this situation up it will be essential to know what he leaked and who he leaked it to. Unfortunately the NYT and Bellingcat may have forced law enforcement to move prematurely. That or friendly media got a tipoff to establish the desired narrative while the government does the "no comment during an active investigation" line.
https://storage.courtlistener.com/recap/gov.uscourts.mad.255...
EDIT: I don't why I'm replying to everyone, yall are too much. I'm not conceding but I'm "deleting" my account so I'm not tempted to keep defending myself.
The amount of times people leaked classified information to win an argument on the Warthunder forums and discord alone proves that intelligence agencies have nothing on borderline teens that want to score points on the internet.
Why does it it need to "make sense" -- to you (or me, for that matter)?
I'm sure it made sense to this kid, at least on some level(s). I remember when I was 21. I did all kinds of stupid shit -- often for no reason other than I felt like it at the moment -- even when I regretted it later.
I'm probably lucky I didn't have a security clearance or I might have ended up just like this kid.
And I keep using that word: kid. And it absolutely does mean what I think it means. A 21 year old is (with very few exceptions) not yet an adult[0]:
Although the brain stops growing in size by early adolescence, the teen years
are all about fine-tuning how the brain works. The brain finishes developing
and maturing in the mid-to-late 20s. The part of the brain behind the
forehead, called the prefrontal cortex, is one of the last parts to mature.
This area is responsible for skills like planning, prioritizing, and making
good decisions.
[0] https://www.nimh.nih.gov/health/publications/the-teen-brain-...We are not supposed to know, and that is the point.
For example, as James Zhong claimed[0]:
>He recalled converting some of his Bitcoin into $700,000 in cash. He stated he did this so that he would have a “case full of money like in the movies.” He hoped the visual appeal of the cash would impress a female into having sexual relations with him. He stated his plan did not work.
Maybe this kid did it to impress his Discord buddies? Maybe he did it for shits & giggles. Presumably, we'll find out more as time goes by.
>despite being Portuguese (based on his last name)
My last name is English, but I'm not from England. I was born in the US, the child of an American citizen too. How could that possibly happen?
I've met at least half a dozen native-born Americans with the name 'Teixeira'. Why do you assume he's a foreign national? By that logic, this guy[1] must be a "furriner" too, eh?
And I said based on his last name he doesn't appear to be ethnically Russian. Why are you going on about foreign nationals?
My point was that they were both kids when they did these stupid things (with Zhong, I'm not talking about stealing bitcoin -- he thought that it would "cool" to have a suitcase full of cash and that it might impress some college coed to fuck him -- hell I even quoted it for you).
Besides, What does your assessment as to what's reasonable have to do with what Jack Teixeira thought was a good idea?
>And I said based on his last name he doesn't appear to be ethnically Russian. Why are you going on about foreign nationals?
Because it's pretty obvious this guy isn't a spook/source for any foreign government. Which was implied by your noting the source of his last name?
And even if he was a spy for Russia or Brazil or Portugal or Grand Fenwick, for that matter, what does his name have to do with it?
why would it matter whether his name is 'Teixeira' or 'Smith' or 'Brin' or 'Nahasaheemapetalan'?
Actual spies like Whittaker Chambers[0] and Alger Hiss[1] didn't have "russian" names. Please.
[0] https://en.wikipedia.org/wiki/Whittaker_Chambers
[1] https://en.wikipedia.org/wiki/Alger_Hiss
Edit: Fixed tense as to Hiss'/Chambers' names -- as they're both dead.
I think the sex in that story is a red herring. If you have a suitcase full of 700 grand you don't need to impressive anyone to have sex. If you have a bunch of illicit bitcoins converting that into cash also makes sense without bringing sex into it. Money makes sense as a motive.
> What does your assessment as to what's reasonable have to do with what Jack Teixeira thought was a good idea?
A crime like this needs a motive.
> this guy isn't a spook/source for any foreign government
We're on the same page. What I'm saying is if this guy was a spook the story would start to make sense. But it doesn't look like he is.
> what does his name have to do with it?
I'll go out on a limb and say the average person who's last name is Putin has more loyalty to the Russian government than someone who's last name is Teixeira.
> Actual spies [...] didn't have "russian" names
It's funny. In a parallel thread I'm being accused of thinking Cold War spy stories are real, and here's two men whose entire Wikipedia articles read like spy thrillers.
I'm not checking if this guy is a spy, just that some sort of evidence of Russian sympathies would make this all easier to swallow.
I think stuff too, sometimes. Does it hurt when you do that? It definitely does when I do.
Based on the above, maybe one of them was an alt-right type? A lot of the right wing in this country supports Russia.
Say you're arguing about the top speed of an aircraft carrier or some BS, the topic doesn't actually matter. The top speed is classified but you know what it is and its documented in writing you know what it is. You google for the public answer of the top speed. Some wise ass engineer on Quora uses basic fluid dynamics and hydrology principles to calculate it must be darn near Z knots and you know for a fact its exactly Z knots you plagiarize the guy or quote him, BAM if the NYT has an axe to grind about it, you're now a felon. That's how classified data works. Its content based not process based. You can't avoid prosecution using a google search or chatGPT log or a torrent file or a link to wikileaks as a magic shield, the legal structure doesn't work that way, sorry kid.
Another way to get caught is "wikipedia paraphrases the classified document I have including exact numbers and everything ... obviously my classified document must have been declassified a long time ago, no danger in quoting my original, right?" Nope, insta-felony.
Now usually if you avoid getting documented in the NYT, if you are just quoting some nonsense you downloaded from the internet that everyone has a copy of anyway, the punishment is not quite as severe as if you sold files to Russia in exchange for coke and hookers.
If everyone on the planet already knew about it except the American public who paid for it, usually not get into much trouble, but you will get into trouble.
It's an interesting security problem to guard against. If you want to F up the American War Machine almost for free, post a bunch of 'stolen' classified docs on some Portuguese (or whatever) web server and wait for the Americans to prosecute themselves for quoting the posts.
I had a clearance in the Army and no matter how many times they teach the class there's people who just don't get it, even if everyone in the world knows about ... Israeli nuclear weapons, for example, you personally are not allowed to talk about it once you're read in. Everyone on the planet can talk about it and every civvie can have a print out of those docs on their desk, but if you have a clearance you cannot talk about it.
(Not OP, but the answer is yes)