I guess all the MDM and document restrictions in the world can't help you against photos of screens. Is it even possible to protect against this, short of only allowing access to confidential files in secure no-cell-phone zones?
I guess all the MDM and document restrictions in the world can't help you against photos of screens. Is it even possible to protect against this, short of only allowing access to confidential files in secure no-cell-phone zones?
0: https://www.echomark.com/post/goodbye-to-analog-how-to-use-a...
Those kinds of watermarks seem like they'd fail to a sophisticated actor. For instance, if that echomark-type of watermark becomes widespread. I supposed groups like the New York Times would update their procedures to not publish leaked documents verbatim or develop technology to scramble the watermark (e.g. reposition things subtly (again) and fix kerning issues).
With generative AI, the value of a photograph or document as proof is probably going to go down, so it probably won't be that big of an issue.
Then have an AI or intern paraphrase it.
When a competent journalist gets a leaked document, they'll learn to only summarize it, but won't quote it verbatim or duplicate it. That'll circumvent and kind of passive leak-detection system that could reveal their source.
Then the only thing that would reveal the source is if the authority starts telling suspected leakers entirely different things, to see what gets out.
This is called a canary trap [0], a well-trodden technique in the real world and fiction alike.
It's likely tougher than it seems; the big important bits that the news will care about have to match up when checked, and anyone with high-level access to this stuff likely has a significantly sized staff who also has access to it. Paraphrasing reduces the chance of some minute detail tweak being included in the reporting at all.
You also have to actively expect and plan to do it in advance, which takes a lot of labor, time, and chances of people comparing notes and saying "what the fuck, we're being tested". You can't canary trap after the leak.
Like knuckleheads, The Intercept provided the Pentagon a copy of a scanned document they received from a whistleblower, which directly led to Reality Winner's identity being discovered.
You could use an Apple or an alternative to Android like Fairphone or even load GrapheneOS on that Google Pixel phone. Even better would be a Linux phone that uses an Android VM so it looks like a bare metal installation.
Could go old school and just get a digital only camera that is not even part of a smartphone. An hidden camera in a pen or shirt button would work too.
Has anyone hacked the Meta glasses so they don't communicate with Meta and allow for communication to your own designated servers?
The yearly limit for rad workers is 5000 mrem with most receiving none. Receiving any dose is usually a cause for concern at most facilities that handle radioactive materials. A full body x-ray would dose you with about 1000 mrem. For about every 10000 mrem you receive, you gain an additional 1% chance of lifetime cancer risk. There's a reason why you wear a lead apron when getting X-rays at the doctor's office and why the technician leaves the room.
Metal detectors would be a much more reasonable method. People that work at airports, courts, jails, some schools, and even some manufacturing facilities walk through metal detectors daily.
The main reason not to bring a phone into the room is that the phone could be compromised. If the person is compromised then a device isn't your problem, because they could view the documents and copy them on paper or just remember the contents to write down later.
Similarly you could hypothetically exfil binary data by visually encoding it (think like a qr code) and video recording it in the same way.
https://github.com/CiscoCXSecurity/QRCode-Video-Data-Exfiltr...
A leaker with a smartphone on a tripod capturing video while they scroll through files etc. could probably deal significant damage without much effort.
Isn't that how congressmen and senators view them in the US? At least, that's how I've understood it to be. If so, what's good for the goose...
A few draconian DLP things could discourage exfil:
- disallow USB and remote access
- require RTO )':
- disallow personal devices in work areas
- harden buildings to prevent Van Eck and monitor image recovery
- disallow guests in certain areas