I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.
I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.
Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards.
The above is common in the DC area (lots of DoD contractors).
Google and Amazon as the biggest voice assistant makers are, of course, our competitors. But they are competitors to I would say most software companies in some fashion.
Tangental story about how serious the Gov takes OpSec. When I was in Iraq, a Marine in my unit found a roll of red Classified tape. He thought it would be cool to put a strip on his personal laptop, which was confiscated almost immediately. It was very clearly a personal machine, but policy is policy, and he never got that laptop back.
Many years ago, I worked part-time for a small construction cost management contractor. They did some TS work for DoD/State (usually combo projects, where NSA/CIA/Army had a wing of a consulate that State managed).
I did not have a TS (or any other clearance) at the time. One day, I'm tasked with counting the windows and doors in an old hospital in Munich. All the room numbers are Sharpied out in one half of the building.
So, it's pretty obvious "men in black pajamas" are using that wing. I just don't know the room numbers.
Seemed super weird to me that only the numbers were considered secured info. I'm sure there was an explanation.
Years later, a friend-of-a-friend was moving to Munich to do "State Department" work (he was an HVAC contractor with a TS). Off hand, I said "oh, I bet you'll be in wing X, floor Y or Z in the old hospital". He about fell over that somebody in no way associated with his agency would know that. Got a chuckle from me.
Regardless, WikiLeaks already spilled the beans.
Yes and no.
CUI was created: https://en.wikipedia.org/wiki/Controlled_Unclassified_Inform...
The number of SCIFs increased a ton, especially in contractors being allowed to have their own SCSI rooms. The number of clearances also went up a lot, and the cycle time on granting a clearance got much faster. Overall some things got relaxed, other things got stricter, scale increased everywhere.
IMO the biggest factor in the increase is just the ever-increasing DoD budget
Did he test it on any other items?
...and yet, Chelsea Manning walked in with nothing more than a CD player and a self labeled CD-RW and exfiltrated tons of data from a secured facility.
> and he never got that laptop back.
There are several morals to this story.
I think the combination of biometric authentication with a display that is immune to cameras and shoulder-surfing is really powerful. If the device has anti-screenshot protection and automatically logs the user out when removed from their head, there's virtually no way to quickly transfer sensitive documents out of it.
SCIF policies are usually strictly enforced. But, that's the most secure workplace available to civilians and they aren't all that common. They also tend to be located in facilities that are higher-than-normal security. Out here in Reston, all my friends who work in SCIFs are also in fenced/gated complexes with paramilitary guards.
There are secure (but not SCIF) facilities that probably vary more. My father's little 6 person contracting office had a secure room, with a Dod approved design and a safe inside, for contracts that required that level of security (State/DoD facilities in China and Russia required TS clearance, other projects varied).
The people that work in SCIFs also generally take it seriously. TS+poly is worth a big chunk of salary here in DC and not something to risk (and that's ignoring that flaunting those laws is a felony for anybody not named Trump). And most believe in the mission (whatever that happens to be). The work spans everything from military hardware to CIA or NSA operations. And a lot of stuff that probably doesn't really need to be TS, but that's a whole other discussion.
If individuals in this particular demographic are hired but lack self-control and are sexually frustrated, then they're potentially huge liabilities to being recruited by adversaries (MICE). It would seem that before issuing clearances, these factors should be assessed rather than going through a standard clipboard audit by the FBI. And, while holding clearances, positive socialization opportunities should be encouraged if not artfully arranged. Who's ever going to leave a job or be disloyal when your boss or some coworkers expedite the love lives of those who aren't already full in that regard? This implies fostering a layer of socially astute managers. It would be a radical departure for government culture perhaps, but a necessary one to ensure the integrity and stability of a clandestine community. Happiness isn't just recognition or sufficient autonomy, but total happiness beyond work. (Throw away the "work-life balance" cliche that is tired and paid lip-service to.)
The phones and networks are hardened by being their own separate network from public networks. The lines are all buried and protected and utilize hardware-encrypted point to point tunnels to merge with public backbone fiber. I've told an anecdote here many times of working at a facility where AT&T contractors dug too close to a JWICS fiber cable and had an unmarked black SUV show up in minutes to confiscate all of their gear and question them.
Keep in mind the military has been encrypting radio traffic over hostile territory for a century, so they don't even necessarily require the lines themselves to be physically secure as long as the endpoint devices are. Encryption keys are loaded from hardware random number generators that are synced manually on some rotating basis determined by local command or national policy, depending on the intended reach of the comms device. The NSA has something called a key management infrastructure for the wide-area computer net that replaced the legacy system a few years ago that is similar to PKI, but keys are only issued in-person and stored on unnetworked hardware key loaders that are kept in locked arms rooms on military installations (or with deployed units). There is, of course, also a DoD and IC PKI so they can still use develop and use regular web applications and browsers, but it is also more restrictive than regular PKI. Everything requires client certs and mutual TLS and you need to be personally sponsored to get your personal certificates.
It's actually really cool the way the JWICS websites work because your client cert provides an identity that is linked to your sponsoring agency's clearance database and web apps automatically redact content on the server side that you are not cleared to see. It's possible I'm making up memories but I think I've seen at least a few cases where some applications can do this inside of a single page, but typically you get a denial for an entire application if you're not cleared for the highest level data it provides.
I almost hate to say it because it's antithetical to the Internet and Hacker News ethos, but it's a testament to how well networked applications could work with a central authority and no anonymity. You don't need passwords. Accounts are provisioned automatically. SSO is global to the entire network. You only need one identity. But no, your office can't have Alexa.
I don't think it's necessarily a dealbreaker if you consider this: from a purely technical standpoint, there's nothing really stopping anyone from setting up a certificate authority- the only issue is getting service providers to trust it enough to accept those client certs as sufficient identification. I could easily imagine a world where I receive an "official" client cert from a government (which I can use to thoroughly prove my identity if needed) as well as several "pseudonymous" certs from various other CAs that I may use from time to time.
The main difference between CAs would be the kind of attestations they provide for a given certificate holder. For example, I could imagine a CA which (for example) is set up to attest that any holder of a certificate signed by them is a medical doctor, but will not (by policy) divulge any additional information.
Or perhaps a CA which acts as a judge of good character- they may issue pseudonymous or anonymous certs, but provide a way for application owners to complain about the behavior of a user presenting that cert.
I'm sure there are plenty of holes that can be poked in this model but I don't think it'd be completely out of the question?
How so? It would seem fairly trivial considering we have ways of sending data over phone lines as sound for decades.
https://gdmissionsystems.com/products/encryption/secure-voic...
In fact, that's why your 56kbps modem would often fall back to 38.4kbps or 28k8, until the phone company installed a fancy new exchange that demodulated the 56kbps stream and didn't compress it. The 56kbps was also due to sampling limits/bandlimiters, on the same copper line you could also get a fully digital ISDN line that did 64kbps. (And if they remove all the filters and band limits, you can reach DSL speeds.)
There's nothing inherently special about voice-compression compared to any other kind of interference/distortion you can get on an analogue line.
Also, faxes still work?