Why Clinton’s Private Email Server Was Such a Security Fail
wired.com
wired.com
The clintonemail.com domain was registered by Justin Cooper [1] and the MX records point to mail servers run by mxlogics.net, now owned by McAfee, not some solo server in Clinton's home. The sole evidence from the AP report is:
> It was not immediately clear exactly where Clinton's computer server was run, a business record for the Internet connection it used was registered under the home address for her residence as early as August 2010. The customer was listed as Eric Hoteham.
A business record for an Internet connection doesn't prove anything, let alone the location of an email server. A history of the MX records [2] is evidence of the location and management of the email server, which has always been set to a mxlogics domain. That it took me only 5 minutes to gather his information but unsourced reporting is being parroted is poor journalism.
[1] http://who.is/dns/clintonemail.com [History & DNS Tabs] [2] https://dnshistory.org/dns-records/clintonemail.com
With that out of the way, I suspect some HN readers might have an interest in the attribution process.
1) Find the mail servers for clintonemail.com, using DNS MX records. These days, they're run through McAfee. Back in 2010, though, the records pointed to mail.clintonemail.com. (There are a handful of services that keep those historical records, e.g. dnshistory.org.)
2) Find the IP address for mail.clintonemail.com, using DNS A records. Today, it's 64.94.172.146.[2] Back in 2010, it was 24.187.234.187.
3) Run an ARIN WHOIS on the old IP address. It's a static IP range through Optimum Online, allocated to "Eric Hoteham" at the Clinton home in Chappaqua. The surrounding IP ranges map to small businesses in the area.[3]
So, there is some nontrivial technical evidence that the email server was at the Clinton residence. But it's hardly definitive. It's possible, for instance, that the registered address is merely for billing purposes.
[1] There's even a glaring a factual error in the story. It was a web hosting service offered by Network Solutions that was hacked in 2010, not their DNS service. That would've been a much bigger deal.
[2] There's still a live server at mail.clintonemail.com. It's running Windows Server 2008 R2 with a valid SSL certificate. And it appears to be colo'd at Internap. Between that and the MXLogic protection, hardly a slapdash setup.
[3] Quite a few of these records have odd contractions or typos, suggesting the misspelled name wasn't intentional.
Both computer security experts he talked to--seriously, experts, Matt Blaze and Jonathan Mayer do great work--explained that this isn't necessarily insecure. But most of the story belongs to this whining Soghoian guy from ACLU, who doesn't appear to be a computer scientist, software engineer, or even IT admin.
NetRange: 64.94.172.144 - 64.94.172.159 CIDR: 64.94.172.144/28 NetName: INAP-NYM-GIGLINX-64-94-172-144 NetHandle: NET-64-94-172-144-1 Parent: PNAP-05-2000 (NET-64-94-0-0-1) NetType: Reassigned OriginAS: Customer: Private Customer (C04601460) RegDate: 2013-06-07 Updated: 2013-06-07 Comment: rirCallout v1.07, Fri Jun 07 00:29:27 -0400 2013 Ref: http://whois.arin.net/rest/net/NET-64-94-172-144-1
CustName: Private Customer Address: Private Residence City: Redondo Beach StateProv: CA PostalCode: 90278 Country: US RegDate: 2013-06-07 Updated: 2013-06-07 Ref: http://whois.arin.net/rest/customer/C04601460
ool-18bbeabb.static.optonline.net - 24.187.234.187:25
ool-18bbeabb.static.optonline.net - 24.187.234.187:80
ool-18bbeabb.static.optonline.net - 24.187.234.187:443
ool-18bbeabb.static.optonline.net - 24.187.234.187:3389
http://www.exfiltrated.com/query.php?startIP=24.187.234.187&...
There was nothing returned for the 64.94.172.146 address.
Agreed.
But, in my opinion, the point of the story isn't to prove factually one way or the other whether or not Clinton did anything at all. The point is to put yet another seed of doubt in the collective subconscious of the voting public in the run-up to the 2016 Presidential election.
Performing this simple feat simply requires a small group of the right people to parrot the same lines ad nauseam. Then it becomes "fact" in the world of punditry.
How can it be that breaking policy was a status symbol?
It would be more normal that having a policy waiver is a status symbol. Flagarantly breaking a rule/law otherwise just allows you to be blackmailed[1]. (you're basically a dead man walking subject to prosecutorial discretion...).
Since that is a common disqualifier for having top-secret security clearance...
none of this makes any sense whatsoever.
I think DNS hosts should offer a waiting period option or approval system (with warning alert) for changing email records. Obviously you want website records to change instantly for failover, but I don't want a hacker changing email records in the middle of the night without anyone knowing. I use Linode and DNSMadeEasy and I don't remember either service sending me a notification when an email record was changed.
Also, seems like you could sell a 3rd party service to monitor DNS hosts. (I didn't bother to Google if that service exists already.) I'm assuming "dnshistory.org" only pings once per day--pretty much useless info from a security standpoint.
Just bad writing from AP, even worse from Wired since Greenberg should know better.
Furthermore, it has a rep of being style over substance, with facts left unchecked in favour of the more attention grabbing story.
I don't blame the journalists who write it, I understand how fast you have to work in such jobs, and there might simply not be the time to track down every lead (certainly the journalists wouldn't be expected to have the expertise to fairly present every story they're asked to write (as opposed to (say) a political correspondant)). This is especially the case with our content-aggregating type media (although Wired are more able to investigate themselves than most, since they're a big player).
I'm glad it exists, as popsci articles can easily help make people interested in supported of things they wouldn't otherwise be interested in, which is good for the industry, but without trying to be snooty I don't think that I'm their target audience (and I suspect you're not also).
When i think about the email requirements of any corporation, every real job I've had, the use of personal email for company business is against policy and would be a fireable offense.
Also interesting to consider the FOIA is more fearful to a politician, than having this private email service hacked by a foreign intelligence service. state department is essentially an adjunct to the CIA at the highest levels, so this is a real risk.
Rarely enforced. Executives in regulated industries do it all the time. Or (more commonly) when hordes of contractors use their own email systems to discuss client matters -- which is perfectly normal because they are covered by NDA. If someone is fired for using personal email, it's likely because a higher up was looking for an excuse.
Of course a contract doesn't cover classified or FOIA material which is where the questions regarding Clinton's setup will go.
Most corporate hardware should be presumed "insecure" from the perspective of personal communication, and similarly so shoud any account that is used to co-mingle work and personal communication.
In other words, it is with great risk[1] that you don't use company hardware. Unless you have duplicate systems, of course. And if you have a duplicate system that you pay for in lieu of the company, only to for the purpose of subverting company policy, you have an ethics problem.
If that makes sense.
In any event, the technical issues here about how this was setup are legitimately interesting. It might very well be that the NSA/secret service or whomever set up this system to very secure indeed. I think the jury is out on that, frankly, and I'm not sure I would jump to the conclusion that SOS would be so wreckless as to not have her system vetted. (Or that the secret service or NSA or whomever would be so wreckless to not do it for them). Obviously it was a very carefully considered and pre-meditated decision to set up this system.
But then again people do stupid stuff all the time.
[1] To your personal life and privacy, not to the corporations per-se.
Yes ... towards things like Google Mail for Corporations. If you make your corporate email better than your personal email, people will use it. If not, they just won't, if they have enough political power within the organization.
I speak from close exposure to white glove CxO level IT service where we do everything from ensure the biometric reader on the CEO's laptop works, to helping wire the CFO's home theatre system, getting the board chairman's vacation photos printed, and setting up all their personal devices.
If these sorts of folks don't like a system, they won't use it. They chucked the Blackberry for an iPhone. One of the reasons I've seen biometrics on a laptop is that a particular leader refused to remember a password longer than 4 digits. That alone made them prefer the corporate Lenovo vs. their personal Macbook Air.
"Most corporate hardware should be presumed "insecure" from the perspective of personal communication, and similarly so shoud any account that is used to co-mingle work and personal communication."
Bring Your Own Device is becoming popular. Every company I've worked for in the past 8 years (2/3 in the Fortune 100) allows BYOD in some form for executives, where they mix their personal and corporate communication. And sometimes for all employees.
The latest thinking in corporate security is not to lock down devices but rather to assume that ALL devices are vulnerable, with no special status for corporate assets. The solution there is to isolate in depth at the service level, with appropriate policy and device management installed for enforcing minimum standards and for emergency remote wipe. Modern apps - email, HR, reporting, order management, etc. are on the Internet, not behind the firewall... unless there's a need for NAT. Legacy can be accessed through VDI.
I admit the future here is not evenly distributed yet. But this is the trend that I see.
"In other words, it is with great risk[1] that you don't use company hardware. Unless you have duplicate systems, of course. And if you have a duplicate system that you pay for in lieu of the company, only to for the purpose of subverting company policy, you have an ethics problem."
I would say corporate IT has a usability problem.
The State Department might want to read the rules, $DIETY knows the Interior Department sure had problems with them.
>The State Department is still reportedly trying to block hacker access to its unclassified e-mail system more than three months after the intruders were first detected.
http://www.enterprise-security-today.com/story.xhtml?story_i...
Yes, "unclassified", but, really? Three months? Really??
Edit: I suppose there are other options. She could have used a staffer's email to send messages on the classified networks.
> Agencies that allow employees to send and receive official electronic mail messages using a system not operated by the agency must ensure that Federal records sent or received on such systems are preserved in the appropriate agency recordkeeping system.
Also, I've rarely encountered a company that cared about whether C-level employees followed the company rules. A "fireable offense" for a fry cook is another day at work for the COO.
If I were her, I would want to personally vet my IT department. I don't know how many Snowdens work at the state department.
As an attorney, a former Senator, and finally a Secretary of States, she and her staff had to known proper security protocols & transparency laws were not applied.
regardless, it was against the law and public officials should always be held to the highest standard, they are not royalty.
The invalid certificates are a red herring. These are certificates used by SMTP servers[1], and since SMTP encryption is currently opportunistic (i.e. completely optional and trivially defeated by an active attacker), it does not matter whether the certificate is valid or not. Virtually no SMTP client validates the certificate presented by an SMTP server on port 25, let alone care if encryption is used. The only reason why SMTP servers present certificates at all, as opposed to using an anonymous TLS ciphersuite, is because some SMTP clients choke on anonymous ciphersuites.
[1] https://twitter.com/jonathanmayer/status/572779239281332224
Not sure what the solution to this might be. This is the stuff of so-called third world countries. I have long held that we are not far from "them", we just do it differently and don't take to the streets en-masse when we are lied to and royally screwed.
Maybe one day we will and things will start to change. A lot of these people belong to jail for what they've done to this country. My guess is that if you are under, say, 30, you are going to have to suffer the consequences of what these people have been doing to the country for, say, 50 years. And your children. Well, there's a school of thought that is of the opinion that your children migt just get to experiencethe US as a near third world country in about 50 years.
Our politicians must be accountable for their actions and must have consequences for misleading and manipulating the people. Not sure how that happens. Not sure what laws would deal with this. If there aren't any, there ought to be.
led to bad decision-making I think you misspelled "law-breaking"
That it is a private cert does not make it any more secure, but pinning is more secure, and with a pinned cert, having the cert signed by a CA gives no additional security.
This is effectively what you are doing every time you connect to a server over SSH and say 'yes' to that message with the funny string asking, "Are you sure you want to connect?" It's analogous to pinning a self-signed certificate.
One law for you and me, one law for them.
https://www.popehat.com/2015/03/03/a-few-comments-on-the-dav...
With your run-of-the-mill service member, it's more a culture of indoctrination - you train people to never make moves that could be perceived as exfiltrating data so that then if anyone makes them you have better evidence that they're exfiltrating data.
I think that when there are allegations being applied of a double standard, it's important to ask why the double standard is being applied.
In this case, I think it's pretty fair to assume that a Secretary of State might well have a good reason for a double standard to be applied. It could be that a staffer gave bad advice, or that she'd received advice from security people.
Certainly I could believe that she'd be better able to vet her people than the state department.
This seems to be a bit of a political crushing, though.
These things should always be a big deal.