11 ms·
Did the Clinton Email Server Have an Internet-Based Printer?
- Esau 10y agoAm I the only one who dislikes the domain name itself? Every time I see it, I read it as "Clint One Mail", not "Clinton Email".
- rosalinekarr 10y agoYeah, as important and fascinating as the whole story is, every time I see "ClintonEmail.com," all I can think is that surely the Clintons of all people should have the influence and power to get a hold of just "Clinton.com." I mean the current owner of clinton.com is some investment firm that could probably do just as well something like ClintonGroup.com or ClintonInvestments.com. If I was her, I would fight for the email address "hillary@clinton.com." Then again, I'm a programmer, not a politician.
- Alupis 10y ago> If I was her, I would fight for the email address "hillary@clinton.com." How does one "fight for an email address"? Once you own a domain, you own it. It doesn't matter that it just so happens to be someone else's last name. She would have had to pay most likely a large sum to the investment firm that already owns clinton.com... and perhaps they aren't interested in selling, or they value the domain too high.
- drakefire 10y agoThis story just keeps getting better. There is either a grand nefarious plot, or worse, horrific incompetence. I just can't find a third possibility.
- Aelinsaar 10y ago"Many journalists have fallen for the conspiracy theory of government. I do assure you that they would produce more accurate work if they adhered to the cock-up theory." -Bernard Ingham
- ZenoArrow 10y agoSeems similar to Hanlon's Razor: https://en.m.wikipedia.org/wiki/Hanlon%27s_razor https://en.m.wikipedia.org/wiki/Hanlon%27s_razor
- mpnordland 10y agoThank you, I'd been trying to remember what this was called.
- levyinglocal 10y agoObvious throwaway account for obvious reasons. I worked at a well known international "activism" type organization. If our data practices ever came to light, the organization wouldn't exist anymore. I promise. Never underestimate the incompetence even by the largest of organizations.
- gizmo 10y agoNo nefarious plot. My understanding is that it went roughly like this. Back in 2009 Clinton requested a secure smartphone from the NSA. It's a custom made device (security by obscurity?). Anyway, the president gets one. As the secretary of state she has to travel a lot, and not being able to do email on the road is highly impractical. So she thought she should get one too. The NSA denied her request for a secure smartphone and gave her some nonsense excuse. She tried a few more times to get one, and then Clinton gave up and ordered somebody to set her up with a private email server. She used this unsecure email server for years. She used it to communicate with top level officials (including the president). That she had this server was common knowledge in the administration. She knew it wasn't secure and she's been very careful not to discuss any classified information over email at all. In a handful of cases she slipped up and some classified information ended up on email anyway.
- Kluny 10y agoThat's the most believable version I've heard so far by a long shot.
- blhack 10y agoDo you have any sources for that? The story I keep hearing is that she had this set up to make FOIA requests more difficult/impossible to fulfil. The really out there stuff is that this was to hide any cash-for-favors exchanges that happened with relation to The Clinton Foundation.
- daughart 10y agoIf the latter was the case why not just use the .gov email for state dept. business and the clintonemail.com email for international cash for favors?
- blhack 10y agoI don't want to go too far down the conspiracy theorists' rabbit hole here, so just consider this some alternative reality fiction for a second: Because it is easier if everything is in one place. Imagine emailing back and forth with somebody, and they accidentally send you an email to the wrong account. It makes it easier to control everything.
- ZenoArrow 10y agoDepends if you class lobbying as a grand nefarious plot or not. I suspect there's likely to be financial reasons for the private email server in this case.
- shas3 10y agoIt almost sounds like a farce: Clinton gets indicted or loses face due to incompetence relating to the e-mail server scandal, and in her place is elected The Donald, a man who has committed worse transgressions and has the potential to do even worse things when given power. Frankly, she doesn't sound any more incompetent than even a typical old company c. 2010: think Target, Sony, etc. It would be sad, given that her opponent will likely be Trump, if this scandal sinks her candidacy.
- toomuchtodo 10y agoShe has no one to blame but herself.
- bitJericho 10y agoWorry not. Any democrat candidate on the ballet will beat trump. You can't win an election on the rich, white, male vote.
- seehafer 10y agoDonald is a test as to whether or not you can win an election on white votes. The rich, white, male votes are probably the one cohort of whites he's least likely to get.
- chiaro 10y agoDepends. You'd be right if you consider rich whites with a college degree, but I believe rich whites without one are more dependably Trump iirc.
- Shivetya 10y agoWhile I care for neither she is the bigger danger because the anti-war left will be silent with her as will many other good activist groups like they are currently silent. A complicit and complacent press and Congress is the reason we have drones killing American's abroad, Manning in jail, Snowden in Russia, Libya in disarray, and a general mess in the Middle East to say the least about increased racial issues in the states. Identity based politics is poison and it shuts down too many groups. Donald won't catch a break from ANYONE, it will be good to have nearly every group riding the Administrations ass every single day. Let alone he really isn't bound to one party or another and likely will go down the middle and get more things fixed than a party centric politician. tl;dr the real threat Clinton poses over Trump is that press, Congress, and activist, will be silent against her.
- bpchaps 10y agoSomewhere in between, just based on experience from spending 1.5 years to get Rahm's phone records. I've received one week so far and now I'm working on getting as much of a sample of his phone records as possible without them invoking their usual "unduly burdensome" rejection [0]. (Hoping to have something published within the next two months or so. Crazy story.) The level of misinterpretation of FOIA among FOIA officers, lack of domain knowledge, intentional delays and reject-if-possible mentality makes these things very difficult. Total incompetence. Though, if you find yourself close to something juicy, you can bet your ass a lawyer will swoop in and find something technically wrong to prevent information from being released. Chicago did that to me eight months in by saying "We don't use VoIP, so your request is void." after the state's attorney general's office told Chicago to give me the info. I'd consider this mildly nefarious. [0] As far as I'm concerned, "unduly burdensome" is just another way of saying "we're not clever enough to get that information, so you're going to have to come up with a clever way on your own, with 1% of the information we have".
- koolba 10y agoIt's both. The security aspect is incompetence. The idea of having it external is deliberate to avoid FOIA.
- godgod 10y agoIt's a vast right wing conspiracy. All the scandals...over her 30 year public career. Nothing to see here. /sarc
- okaram 10y agoIt is neither. It is just standard 'incompetence'; this is really '65 year old doesn't understand computers' ; details @ 11
- venomsnake 10y agoIt is "65 years old wants to skirt the rules and no in her entourage had the skills to do it properly or the balls to tell her it is a bad idea". In a sense I am sympathetic with her - this is the type of hacking the system we at HN tend to admire. Clinton is "Uber for Email" before it was cool - dislike the rules and current infrastructure - build your own.
- ghostly_s 10y agoDoes this really indicate any private correspondence was printed via the internet? Even if a printer was set up which _was_ writable via this web address, that doesn't mean that emails from the email server itself were printed to that address rather than directly to the device, does it? In fact, presumably the printer and email were hosted on the same server so it doesn't make much sense to me that they would send one to the other via the web address.
- moyix 10y agoIt seems like it would be strange to give a printer a DNS name if you didn't intend to talk to it over the internet. If you're directly connected it doesn't need an IP at all. I think the sniffing threat mentioned is overblown. As one of the commenters mentions, ISPs don't generally allow adjacent IPs to sniff traffic. A bigger threat is that a vulnerability in the printer may have been exploited. E.g., for a long time most HP printers could have their firmware upgraded by sending them a print job. And so far the cursory look I've taken at various printer firmware has been really alarming – think thousands of calls to strcpy/memcpy and other unsafe friends. Edit: Here's a reference for firmware upgrade via print job: http://www.internetsociety.org/sites/default/files/03_4_0.pdf http://www.internetsociety.org/sites/default/files/03_4_0.pd... Edit2: Also, when I say "firmware upgrade" I mean arbitrary code – it wasn't verifying a digital signature or anything.
- extrapickles 10y agoPrinter firmware and drivers are the worst. I've integrated with a software package that supplies its own printer drivers because the manufactures can't make a driver that will actually work well. They constantly screw up the most basic of things. A good test of a network printer is to set it offline, send 20 print jobs to it (a test page is fine), then set it back online. Way too many printers will not print out all 20 print jobs, despite reporting success for all of them (This is true even of $30k printers).
- ghostly_s 10y agoI think you've misread my point. I understand this indicates an intention to talk to the printer over the internet; I don't understand why this would indicate that the emails, specifically, were printed in that manner rather than directly through a local connection. Perhaps the printer was used for printing emails locally but also was made web-accessible as a (misguided) convenience feature for printing other content.
- Jerry2 10y agoHere's some more details about the state of security of her private server [0]: >Outlook Web Access, or OWA, was running on port 80 without SSL (unencrypted) >Remote Desktop Protocol, port 3389, was exposed through the DMZ (open to anyone on the internet.) This, at the time it was being used, was open to critical vulnerabilities that would allow for remote execution of code. >VNC Remote Desktop, port 5900, was also exposed through the DMZ. >SSL VPN used a self-signed certificate. This isn't inherently bad, but left them open for "spearphishing" attacks, which have already been confirmed to be received by Hillary Clinton and her staff It's also interesting how they responded to attacks on the server [1]: >Here is the section from page 41 of the report which references an “attack”: > On January 9, 2011, the non-Departmental advisor to President Clinton who provided technical support to the Clinton email system notified the Secretary’s Deputy Chief of Staff for Operations that he had to shut down the server because he believed “someone was trying to hack us and while they did not get in i didnt [sic] want to let them have the chance to.” Later that day, the advisor again wrote to the Deputy Chief of Staff for Operations, “We were attacked again so I shut [the server] down for a few min.” On January 10, the Deputy Chief of Staff for Operations emailed the Chief of Staff and the Deputy Chief of Staff for Planning and instructed them not to email the Secretary “anything sensitive” and stated that she could “explain more in person.” [0] https://np.reddit.com/r/politics/comments/4j2r94/judicial_watch_new_clinton_emails_reveal_clinton/d336scb https://np.reddit.com/r/politics/comments/4j2r94/judicial_wa... [1] http://lawnewz.com/high-profile/clinton-tech-says-private-email-server-was-attacked-forcing-shutdown/ http://lawnewz.com/high-profile/clinton-tech-says-private-em...
- darawk 10y agoAh yes, the classic 'shut it down for a few minutes' defense. Stops 'em every time.
- artursapek 10y ago"i didnt [sic] want to let them have the chance to" Can you imagine if this was how Google and Amazon handled security?
- 10y ago
- zaroth 10y agoThe emails themselves sent from Clinton's server were unencrypted for several months, so unencrypted printing is just more of the same. There's no reasonable question anymore that laws on handling classified data were broken, the only question is will charges actually be brought?
- cm2012 10y agoThat server was for only unclassified data though. Some stuff was later called "Classified", but many innocuous things are classified.
- toomuchtodo 10y agoI was unaware the clintonemail.com email server could differentiate between unclassified and classified content.
- untog 10y agoShe still had a .gov e-mail address. It isn't difficult to imagine there was a "confidential to @gov, all else to @clintonemail.com" rule. I'm not defending the practise, but let's not be glib.
- deleted 10y ago[deleted]
- Alupis 10y ago> She still had a .gov e-mail address She did, officially, but she's mentioned several times she never used it, and wanted to have her private email server for "convenience".
- ldness 10y agoI love her values - personal convenience vs national security. This is just the sort of person we need in the White House. It reminds me of a president (I forget which one) who tied up Air Force One on a runway at who knows what cost to the taxpayer just so he could get a haircut.
- mergy 10y agoOther very serious concerns: 1. Was it running RAID? If so, what level? Better not be RAID 5. Horrible write speed. 2. Let's REALLY dig into the DNS. What about reverse lookups and CNAMEs. 3. Any idea what the screensaver was? I'll reserve judgement until I have some confirmation. 4. NIC driver version: Hearing that she just ran a generic MS driver for the Intel dual network card. Unbelievable.
- arcticfox 10y agoIs your point that the published details are irrelevant? Because if so, I very much disagree. You can ignore the details if you want.
- mergy 10y agoYes, let's look at all the dns records created, edited, removed and theorize all possible devices that could have been connected or not. Wouldn't a better rendering of all of this be a video from Taiwanese animation?
- jrcii 10y agoAny time in the last 10 years I setup an independent email server it had horrible deliverability rates. I wonder how they worked around that. Getting your server whitelisted with all the major providers is a major hassle.
- dmritard96 10y agoAlso curious about USB - are there any USB logs and is that something logged by whatever OS her server was running? seems like it would have been really easy for things to move from email to usb...
- xufi 10y agoThat's a intersting point. Who knows if she even had a way to do that unless she connected remotely overseas via a secure client . Granted though it'd have to be highly secure
- jaboutboul 10y agoBernie 2016?
- slantedview 10y agoOne of the commenters on the Krebs post makes a remarkable point [1]: "It gets better. Do a dig mx clintonemail.com. You’ll see that the machine’s incoming email was filtered by mxlogic.net, a spam filtering service that works by received all your emails, filtering out the spam, and forwarding you the rest. This is because the hosting provider, Platte River Network, sold a package along with the hosting. The package included spam filtering and full-disk off-site backup (since then seized by the FBI). So every email received by Clinton was going through many unsecured places, including a spam filtering queue, a backup appliance and an off-site backup server. Which has already been documented." http://krebsonsecurity.com/2016/05/did-the-clinton-email-server-have-an-internet-based-printer/#comment-406731 http://krebsonsecurity.com/2016/05/did-the-clinton-email-ser...
- themgt 10y agoHaha yeah I've actually seen her supporters claim the MX filtering meant it was "secure"! facepalm
- wrong_variable 10y agooh my god, this is depressing sad. She could have hired a team of machine learning grad students to build her a personalized spam filter. but she went with the cheapest option. this is going to keep me upset for a while.
- salgernon 10y ago"She" did nothing of the sort. She told someone she wanted her email available. They said, ok, we'll just host it ourselves. "Whatever, I want my daily suduko and make sure I stop getting those damn linked-in spams". "Ok boss". Seriously, how could anyone really believe she specc'd this out herself? Her staff probably threw it together as a MVP with the full intention of revisiting the implementation "really soon". And then they lost interest.
- stillusingvb6 10y agoShe asked and they gave her options she didn't like and then worked around it. Big difference
- mindslight 10y agoI really want to like Clinton for running her own server, respecting the decentralized basis of the Internet. Yet her domain name was clintonemail.com? What a pleb! Political corruption and murder is her family business, yet even with those capabilities she can't be bothered to obtain a better online identity? She may as well have been at hotmail or gmail and highlighted in blue!
- at-fates-hands 10y agoIf I remember correctly, Sarah Palin used a Yahoo account to do some of her business as Alaska's governor. EDIT: Found it, yeap, Yahoo: http://thecaucus.blogs.nytimes.com/2008/09/17/palins-e-mail-account-hacked/?_r=0 http://thecaucus.blogs.nytimes.com/2008/09/17/palins-e-mail-...
- gormo2 10y agoThat's not as bad as Colin Powell, who used AOL while serving as Secretary of State. And of course it also was hacked by, you guessed it, Guccifer.
- untog 10y agoAmong the more disappointing things in all of this is that there is a rational, important conversation to be had about everyday awareness of security and government inflexibility. But there won't be, because she is Hillary Clinton and it is 2016. Supposedly she got the server set up because the NSA refused to give a politician who travels frequently a secure smartphone. She (I personally believe) was likely ignorant of many of the security requirements of such a server (even one set up for unclassified e-mail), as was whoever set it up. And no-one on her staff either knew enough or was willing enough to say anything. She is also supposedly not the first Secretary of State to have an arrangement of this nature. This feels like the very definition of systematic failure and clearly needs to change. But the conversation is almost exclusively based around a) her having nefarious motivations, because she is Hillary Clinton, or b) this all being a Republican plot to derail the Democratic candidate for President. It's all very depressing.
- themartorana 10y agoWhat's the rationale for not giving everyone secure smartphones? And I mean high-ranking officials, SoS certainly ranks considering how much she/he is in foreign countries with foreign leaders. Can someone in the know explain why the NSA would deny such requests?
- hobs 10y agoProbably because they know how to pwn all of them, and are certain they are insecure or an absolute nightmare to secure.
- na85 10y agoNo doubt whatever mods they make for the POTUSberry are resource- and time-intensive.
- untog 10y agoDifficult to know for sure. Obama had one, Rice previously used one, but: The NSA refused to give Clinton a device similar to the one used by Obama: a modified BlackBerry 8830 World Edition with additional cryptography installed. And while Clinton's predecessor Condaleeza Rice had obtained waivers for herself and her staff to use BlackBerry devices, Clinton's staff was told that "use [of the BlackBerry] expanded to an unmanageable number of users from a security perspective, so those waivers were phased out and BlackBerry use was not allowed in her Suite,"[1] This being Clinton there are probably conspiracy theories (the NSA is out to get her!) but I suspect they simply didn't want to have to deal with it, and had the ability to say no. So they did. [1] http://arstechnica.com/information-technology/2016/03/nsa-refused-clinton-a-secure-blackberry-like-obama-so-she-used-her-own/ http://arstechnica.com/information-technology/2016/03/nsa-re...
- internaut 10y agoThe US government should give Guccifer the Medal of Honour. This is a farce.
- deleted 10y ago[deleted]
- AnimalMuppet 10y agoI seem to recall something about a CIA head getting fired because he took a Mac from work home. Does anyone recall details of this? (I tried to find it, and failed.)
- paulmd 10y agoJohn Deutch? https://fas.org/irp/cia/product/ig_deutch.html https://fas.org/irp/cia/product/ig_deutch.html
- AnimalMuppet 10y agoYeah, that was it. Thanks.
- coldcode 10y agoGiven all the warnings I got when I had a secret clearance back in the 80's about protecting the information and what penalties I faced for not following the rules I've found it unimaginable that the Secretary of State didn't know or didn't care about protecting much higher level secrets.
- patrickg_zill 10y agoI have spent some time talking to different people I meet/know who have security clearances. EVERY one of tells me that if they had done what it appears Hillary did, they would fully expect to be in jail for years. In researching this, I find that about 4.5 million Americans currently have, and maybe 1.5 million more did have in the past, security clearances. I find it hard to believe that in Washington DC, surrounded by people with security clearances, this was unintentional and just an accident. It's like Hillary had to look far afield to find people without security clearances so that they would set this up for her.
- GVIrish 10y agoThat's because in the federal government the average employee simply doesn't have the same amount of power nor leeway that a cabinet level executive would. For one, several cabinet level appointees have original classifying authority. No regular employee has that power. A rank and file employee obviously could not direct anyone to set up a private email server for their correspondence or request that the NSA provide them with a secure blackberry. > I find it hard to believe that in Washington DC, surrounded by people with security clearances, this was unintentional and just an accident. It's like Hillary had to look far afield to find people without security clearances so that they would set this up for her. Clinton certainly was wrong here and people certainly told her not to do this. But I don't think it requires malicious intent, just someone not taking the rules/guidelines seriously and/or thinking they have more power than they do. NARA compliance is something that many people either don't know about or are confused about at State department so I could see how some might not take it as seriously as they should. I'm sure she and her inner circle rationalized away the security risk because classified materials are not supposed to be sent to public email addresses, there's a separate network for that.
- karmacondon 10y agoA rough analogy for this situation would be if a company had an "employees must use blackberries" policy, but the CFO of the company outright refused because he wanted to use his iPhone. Are they going to fire the CFO over that? Possible but not likely, especially if he is doing a good job otherwise. In the same way, the Secretary of State can also refuse to comply with government policy (not law). You can't fire the Secretary of State for using the wrong email server. It just doesn't work that way. The fact that national security is involved does change things, but organizational politics is pretty much the same all over. If Clinton's email server contained the nuclear launch codes or the contents of Area 51 then the government would have handled it differently. It's unlikely that any lasting and serious security threats were exposed.
- deleted 10y ago[deleted]