4 ms·
I've been in the computer security industry for decades, 20 years ago I did intrusion detection and computer network security for a large government location as
by Claudus 10y ago
I've been in the computer security industry for decades, 20 years ago I did intrusion detection and computer network security for a large government location as part of a team of about 12 people. I referred people to the Inspector General for prosecution when they attacked our networks.
I am really shocked at the level of incompetence here. Even 20 years ago we had 300,000 to 450,000 probes and hack attempts on that one network alone, on a weekly basis. It seems almost certain that her emails were compromised.
Destroying them is inexcusable, at the very least those records could have been used to determine what data had been potentially compromised.
I can't imagine what went on at the State Department where this kind of thing could happen. And, it isn't just Hillary Clinton who is guilty here.
I remember the first day after my security clearance and background checks completed, they spent several hours explaining security policies to me; that felony charges would be brought against me if I walked out the gate with so much as a hard copy of an internal email. I only had the lowest level of clearance for "classified" of "confidential" and even then only as was relevant to performing my job. There were entire buildings in our complex that had "secret" data, and only certain members of our team could investigate those systems for potential intrusions.
Even at that level, when you work with potentially classified material, the default behavior is to act is if all information is classified. If you want to published, or release information, it needs to checked and approved, even if it's not sensitive, just to be sure.
The only excuse I can possibly imagine, is that the clintonemail.com server was actually an elaborate ruse to leak misinformation to foreign actors.
- cm2012 10y agoRemember that all of the classified information on the server was either not classified at the time or was 1 of 3 incorrectly marked classified emails. Also remember the official state server at the time was also confirmed hacked.
- Claudus 10y agoI made some updates to my post regarding classification. Being marked as classified was not something I would expect, instead you should operate as if all information is sensitive. Act as if information must be white-listed for public release. Much how the FBI is handling the data, each piece of information must be reviewed before release. The excuse of "not marked as classified" is akin to a thief using "not marked as don't steal" to justify theft.
- aceperry 10y ago'The excuse of "not marked as classified" is akin to a thief using "not marked as don't steal" to justify theft.' That doesn't make any sense.
- Claudus 10y agoDo you think it's okay to run a private email server as your primary conduit for work communication, if nothing "marked as classified" is ever sent to you as Secretary of State? I'm not sure why it doesn't make sense. Removing any information, classified or not, off site is a huge no no. The fact that it was confidential information, that was later marked as such does not change the nature of the information.
- EdSharkey 10y agoBut, why was she moving any State-related content off government computers? Why would she put herself and others at risk like that? These weren't all personal emails she was sending - she was discussing State department business with the foundation and with her trusted operator, Sidney Blumenthal. Worst of all is how sloppy everyone involved in this fiasco has been. I feel bad for Obama, what a cluster! > Also remember the official state server at the time was also confirmed hacked. Look, clearly Hillary engaged in unsafe IT practices. Could it be she was phished? Maybe she was the one who enabled the hack!
- ascagnel_ 10y agoSimple: the NSA refused to give Clinton the same secure BlackBerry setup they had provided President Obama.
- EdSharkey 10y agoHas she claimed this anywhere in testimony? The reason I heard given was she needed a way to send emails of a personal nature. That reason and the one you've given sound like a dodge. Fact is, if she even tangentially admitted to knowingly transmitting information _marked_ confidential off State networks (which she did), she'd be guilty of multiple crimes and none of her friends could save her. She would be frog-marched off to the hoosegow. Hence, the endless excuses, waving-off, and feigned ignorance. The drip, drip, drip of damning evidence will continue and to save her skin all she can do is shrug absent-mindedly.
- Claudus 10y agoVery rarely did I see anything marked confidential. The assumption was that all work related documents and information was to be protected. As far as I was concerned, removing any work related data, email, or other information from the site was grounds for immediate termination and likely charges being brought. I don't know the practices at the state department, but for my section, the guideline was, "Just assume everything is sensitive, protect it, and you won't have any problems." Compiling a list of networked computers by IP and OS, that data would be considered sensitive, and obviously not to be removed off site, but would not be marked in any way. From a practical perspective, the "not marked as classified" doesn't really make sense to me, it may have some legal merit, but I couldn't speak to that.