British spies 'moved after Snowden files read'
bbc.co.uk
bbc.co.uk
> we are told authoritatively by people in Downing Street,
> in the Home Office, in the intelligence services
It seems disingenuous to use the word "authoritatively" when talking about people with a huge stake in the game, who will at no point be willing to (or needing to) verify their claim.BBC are also totally unreliable when it comes to the top level stuff. They get told what to write.
The world isn't just this peaceful and happy place where only the USA is the big bad wolf.
The word "authoritatively" just seems obviously wrong.
Austerity politics, London real estate boom, UK knife laws
Chelsea Manning, too, got away with a considerable amount of material.
Surely other state actors would have moles at these levels - so they probably got all this stuff as well.
Security by obscurity may be a bad rule to follow at the state level - in the future we may need to know we are safe and not trust spies or wonks with our safety.
Cryptography needs to be provably secure. Perhaps safety should be? Which raises the question can National Security be performed transparently ?
Was the hack of GMail by China attributed to a NSA backdoor ?
The real problem may be general to any government department that lacks oversight - total and utter incompetence.
No-one has publicly hacked Greenwald - the secret services have been caught with their pants down at least twice.
The BBC reports Russia and China have cracked encryption implemented by Snowden. From what I read about Snowden it seems he would have used the best publicly available crypto and so that is quite a considerable claim.
Conclusion : leaks are more likely to come from the leaky sieve.
http://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9-...
I cite Adam Curtis :
"Maybe the real state secret is that spies aren't very good at their job and don't know very much about the world"
These super secret departments get more funding and power when there is more terror not less.
The career incentives of the intelligence classes may not align particularly well with actual national security.
1. Russia/China have got hold of the files, and know how to decrypt PGP (Very unlikely).
2. A journalist with access to the files and the encryption keys has left them lying around, or was cooerced into decrypting them. (Unlikely but possible).
3. Intelligence services are lying, possibly for political gain ahead of new legislation (specifically in the UK), and/or have fallen for a bluff by China and Russia. (Most likely).
5. GCHQ or NSA had same or similar documents lifted (umm... leveraging Office of Personnel Management or a similar type hack) and they are preparing a cover story.
plenty of conspiracies to go around but as someone else said... until some proof is shown there's no reason to give much weight to the statement that individuals needed to be moved.
I'd say its #5 honestly :p
> “The best advice here is to shift your thinking from passWORDs to passPHRASES,” Snowden recommended. “Think about a common phrase that works for you. It’s too long to brute force and also make them unlikely to be in the dictionary.”
(emphasis mine)
0. http://rt.com/usa/248401-snowden-oliver-password-protection-...
https://www.youtube.com/watch?v=yzGzB-yYKcc#t=1m30s
He mentioned "margrattethatcheris110%SEXY" - I would be totally unsuprised if someone managed to crack that.
Diceware is a great choice.
While I'm asking, perhaps you can come up with a reason that doesn't boil down to "Bruce Schneirer said XKCD method was bad"?
XKCD is bad specifically because it is specifically talking about attacking a password via an internet based oracle rather than attacking a hash, but people generalized it. A search space of ten or twenty trillion is laughable when a few GPUs can make a billions of guesses per second against a vanilla hash algorithm.
Ultimately, if you want a password or passphrase that a computer can't guess, you should let a computer pick it for you, or if you're really paranoid, use diceware.
It doesn't have to be a "journalist". E.g. I'd consider Bruce Schneier to be more of a cryptographer or researcher.
My scenario:
1) He's had extensive access to the Snowden material
2) He uses Windows
3) Q.E.D.
Yes he's taken precautions, but he's certainly a "high value target".https://www.schneier.com/blog/archives/2013/09/how_to_remain...
Perhaps the next press release will claim, 'paying taxes reduces the risk of death by 42%!'
Section 23 of the Freedom of Information Act 2000:[0]
"Information held by a public authority is exempt information if it was directly or indirectly supplied to the public authority by, or relates to [...] the Government Communications Headquarters"
Anyway, you know how when one person shits in the pool everyone has to get out? GCHQ, NSA, you're that person and this is your moment.
Alternatively, is it believable that they both miraculously broke the encryption at exactly the time?
I would expect at the very least for the BBC to seek a response from Snowden/Greenwald/theGuardian/etc before publishing this article with subheadings like: >'Hostile Countries' >'Huge Setback'
It's worth considering the idea that technological spying by procuring vulnerabilities without reporting perpetuates a technological arms race and concentrates power in the executive with no balance among other branches.
>"Well, we are told authoritatively by people in Downing Street, in the Home Office, in the intelligence services that the Russians and the Chinese have all this information and as a result of that our spies are having to pull people out of the field because their lives are in danger."
There is a line about also damaging ability to collect information, but this is a separate claim; allegedly, information in one or more of the million+ files could jeopardize lives of human intelligence people stationed in foreign countries.
Or maybe we're confusing the wiki leaks insurance file with the snowden files?