Why David Petraeus’s Gmail account is a national security issue
washingtonpost.com
washingtonpost.com
In fact, it seems that for any given government official who wants to conduct risky non-official business, using something like GMail would actually be the more secure route, if you were trying to keep secrets from both your employer (which includes the public and public record requests) AND from the usual enemies of the state.
If both Petraeus and Broadwell had used GMail accounts not associated with their names, such Dave501010@gmail.com and PaulSmith900@gmail.com, how likely is it that anyone would discover their shenanigans? For an enemy of the state to find out, it would have to compromise both GMail and somehow connect Dave501010@gmail.com with David Petraeus. Sure, it's security through obscurity, but we're talking a nearly unsurmountable amount of obscurity.
Of course, once they start forwarding emails from their private account to their publicly known addresses, then the game is riskier. There's also the problem of keeping the ruse without making an AutoComplete mistake, such as sending a message from petraeus@cia.gov to PaulSmith900@gmail.com without realizing he's logged in as petraeus@cia.gov.
IMO, there's nothing wrong with a little security through obscurity if:
1) It's not your main game plan, just an extra obstacle. Anything can be compromised eventually, so you buy extra margin.
2) The obscurity is agile. Similar to benchmarking password complexity vs. projected brute-force capabilities of enemies and rotating passwords accordingly, rotate the obscurity- acknowledge that your enemies will figure it out eventually, and change it up faster than you think they can figure it out.
I'd argue that every security agency worth its salt is also keeping a close watch on its bosses (especially on its bosses) so that let's say if Petraeus had logged in with joe.doe@gmail.com his communications being intercepted someone would have noticed. As a non-American, I'm not exactly sure what's for example the relation between the NSA and CIA, but I guess it's somehow telling that the whole thing seems to have been driven by the FBI
> WASHINGTON — The F.B.I. investigation that led to the resignation of David H. Petraeus as C.I.A. director on Friday began with a complaint several months ago about “harassing” e-mails sent by Paula Broadwell, Mr. Petraeus’s biographer, to an unidentified third person, a government official briefed on the case said Saturday.
It also makes a good april fool joke - if you still have one matching your name, just send a message on Apr 1 to your geek buddies explaining you are moving from gmail.com/outlook.com/whatever to aol, and wait for the "WTF?" replies :-)
Of course for such a high risk relationship it wouldn't have been a big deal to purchase 2 laptops that are only used for this particular communication and nothing else (no web surfing nothing, just to setup an email account to communicate with the other party). That way, no risk of auto complete and can avoid any other traces and be easily destroyed. Doesn't avoid any IP address matching but that can be handled in other ways.
Beyond that, the hard part of training a spy to get into Google would be getting a good enough computer science student involved. From there, it's really just a matter of teaching them to cover their tracks semi-intelligently. However, given what I'm sure is a mountain of completely legitimate reasons to look at user data (for example, to resolve data corruption, investigate malicious users, etc.) and an inconceivably larger mountain of user data to look at, I don't actually think it'd be that hard to get away with it.
Any support/SRE/developer access to a users' GMail mailbox would be logged and if they exceeded their authorized access by such as accessing a "public" persons email, They'd be fired pretty quickly.
I'm confident that Google is doing a better job than pretty much anyone else, but this problem is a more or less unsolvable one.
Edited to add that another interesting idea is that the people who man the DC's are actually pretty sparse (relatively few people for a lot of servers) so it's not inconceivable that one could trigger a failure on an important box, take down a replica of the figure's mailbox, swap out the drive for RMA and then do a quick copy. I bet this would be easy.
I guess my point is that no level of internal controls at any company can actually stop a determined government. If that were true, governments, which are much more paranoid than tech companies, would have eradicated spying a long time ago.
I do not disagree with your overall assessment, but this is not strictly true. Most good real-world security schemes don't follow the 'root is God'-model of Unix, and for good reason. It's perfectly possible to design a system where each operation performed by a "superuser" must be validated, or at least logged.
If Google were serious they should have brought out Bruces company Counterpane and put him in charge of security.
Its blindingly obvious to any one with even a basic knowledge of computer security best practice.
Security is hard, and it is even harder when any device on the internet is intended to be able to work with the system, and it is even harder when you operate one of the most valuable networks in the world.
And systems used by your TLA's to handle law enforcement access are not available to "any device on the internet"
As I said they should be set up to only talk over a private circuit to one other end point and also have proper hardware crypto gear that is external to the systems.
separating the extraction of data and applying the decoding probably should have been done on separate systems.
http://techcrunch.com/2010/09/14/google-engineer-spying-fire...
A spy would also be illegal and, more importantly, potentially very embarrassing politically. It should be clear to anyone by now, the US government doesn't care about cost or efficiency. And further, there are secret court proceedings for national security kinds of cases (of which there are literally hundreds at any given time), so there's no secrecy advantage.
The KGB back in the day had an entire department Line X that was dedicated to industrial espionage - Putin apparently was in this Department
I know a senior developer in British telecom who worked on the system that tracks every private circuit in the UK and she was being PV'd (positively vetted its called developed vetting these days) - as she had root access to this system same as being TS cleared in the USA.
If he used a gmail account and used a separate device such as a private smart phone or tablet to access that account there would have been zero vulnerability, other than the fact that he could have been blackmailed. Gmail is pretty hard to hack into, the IP address of the device probably wouldn't tell anyone anything about where he is, since it's a private IP on the telco (can you tell a person's location from the IP on the telco?), and there wouldn't be any way to get to any of his secure accounts or make a mistake of using the wrong email account.
http://www.buzzfeed.com/zekejmiller/anonymous-may-have-hacke...
The next step, it seems, was sending some trolling emails. That requires acquiring or just guessing some email addresses. The people who got the trolling emails set the discovery of the affair in motion. Well played. But did not require a 133t hAx0r.
[1] Ignoring the blackmail value of the affair.
http://techdailydose.nationaljournal.com/2012/09/napolitano-...
;)