38 ms·
Did the Intercept bungle the NSA leak?
- ahoy 9y agoAs with every headline that poses a yes/no question, the answer is usually "no". EDIT: I'm also unsure what the point of shifting the focus onto The Intercept's alleged "mishandling" of the leaker's identity is. It seems like a smear job meant to discredit a publication that the natsec community and mainstream media like WaPo dislike. It also removes the focus from the substance of the leaks and puts it on the "character" of the publication.
- thefalcon 9y agoExcept it sure seems like in this case, yeah, they bungled it. At the very least a total lack of awareness or care towards infosec to help protect sources (regardless of the fact that the lack of awareness extends to the source - I'd want a journalist to be better at this than I am if I were leaking information). [ The article doesn't mention this, but I wouldn't be surprised if these microdots, rather than "a crease" were the smoking gun: https://twitter.com/quinnnorton/status/871883733032415236 https://twitter.com/quinnnorton/status/871883733032415236 ]
- LeifCarrotson 9y agoThe search warrant says that the internal audit and (logged-in?) gmail account were the smoking gun. Page 11, paragraphs 14-16: https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f473l3r/show_temp%20%2866%29.pdf https://d3vv6lp55qjaqc.cloudfront.net/items/1k2I053M3J2z0f47... > 14. The U.S. Government Agency [NSA] examined the document shared by the News Outlet [The Intercept] and determined the pages of the intelligence reporting appeared to be folded and/or creased, suggesting they had been printed and hand-carried out of a secured space. > 15. The U.S. Government Agency conducted an internal audit to determine who accessed the intelligence reporting since its publication. The U.S. Government Agency determined that six individuals printed this reporting. These six individuals included WINNER. A further audit of the six individuals' desk computers revealed that WINNER had e-mail contact with the News Outlet. The audit did not reveal that any of the other individuals had e-mail contact with the News Outlet. > 16. The U.S. Government Agency determined that WINNER had e-mail communication with the News Outlet on or about March 30, 2017, and March 31, 2017. The first e-mail was from WINNER, using e-mail address [redacted].fitness@gmail.com, to the News Outlet. In it, WINNER appeared to request transcripts of a podcast. The second e-mail was from the News Outlet to [redacted].fitness@gmail.com and confirmed WINNER'S subscription to the service. The [redacted].fitness@gmail.com account is a personal e-mail account not sponsored by or affiliated with the U.S. Government Agency. Whether the 'crease' noticed by the NSA in paragraph 14 was actually creases or an internal code for microdots, if The Intercept was going to use this report there's nothing they could have done to protect this reckless source.
- dingaling 9y agoRather revealing that the "Agency" was privy not only to the e-mail metadata but also the contents. Watching outbound SMTP from Gmail or just MiTM internal agency traffic?
- LeifCarrotson 9y agoOr just logged into Gmail on her work computer?
- mjcl 9y agoCould be an ordinary search warrant. Supposedly the Intercept also told the govt. that the document was mailed with an Augusta postmark. The postmark + being the only person to print the document in that city seems like reasonable basis for a search warrant, but I'm not a lawyer.
- chakalakasp 9y agoI agree the microdots thing was sloppy. At least degrade the image of the page, or better yet retype the thing before sending it on. However, being one of the few people who printed it off from work was pretty stupid and would have boned her anyway. At some point in her brain she should have reflected that she was going up against the NSA and stealing their top secret intel and that maybe just maybe the system kept track of who printed out the Top Secret stuff the POTUS's attorneys are sweating bullets over. That said, if the dude gets impeached she will probably eventually be pardoned.
- oasisbob 9y agoWhoa - sure enough, there they are. The microdots seem to be the usual xerox-style microdots, and decode properly: Printer serial number: 535218 [or 29535218] Date: May 9, 2017 Time: 06:20
- jpindar 9y agoIf anyone is interested in seeing for themselves how this information is encoded, read this. http://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html http://blog.erratasec.com/2017/06/how-intercept-outed-realit...
- ceejayoz 9y agoIt seems clear they should've redacted the printer microdots - they're a known concern. It sounds like their source was caught in other ways, but that's not an excuse.
- sambe 9y agoAre you saying that, having read the article, you think the answer is no? If so, having read the article, would you trust The Intercept to deal with a hypothetical leak by yourself? Or are you saying "I didn't read the article, but the answer is usually no"?
- problems 9y agoIt's a common adage, see https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headlines https://en.wikipedia.org/wiki/Betteridge%27s_law_of_headline...
- austenallred 9y agoI'm not sure how you can arrive at "no" here. Regardless of how you feel about the politics involved, if you publish information that outs a source you've "bungled" it almost by definition.
- mmjaa 9y agoYes, or maybe no. It doesn't really matter, because this is just one of many battles being waged in the current cyber-war gripping our lives. I mean, we have to just see it in the larger context: there is very definitely a war going on among various, nefarious, otherwise, or indeterminate, hostile parties. It seems that if we must dismantle the military-industrial state, it is going to be through info-wars. The key targets are all secrets. (Curious that both sides seem to want the same thing though, i.e. "the info wants to be free", isn't it?)
- CogitoCogito 9y agoYeah I think it's basically guaranteed that this is what we would hear regardless of how they found the leaker. Maybe this method was used, maybe they looked at printer looks, maybe they looked at access logs to the document, etc. Regardless, they _say_ that the problem was The Intercept's handling because there is no way to verify it and it makes them look bad. Really this news should be taken with a grain of salt. That said, the important thing for any leaker to do is to try as much as possible to obscure any links they have to the documents before handing them off to third parties even if those third parties are supposedly trusted (because once you hand the documents off, you are no longer in control).
- mmjaa 9y ago>Really this news should be taken with a grain of salt. Something I think is valuable in this leak is the fact that the general public will be better educated that in fact their printers are capable of tracking every single thing they print, and there is no really, truly, anonymous personal printing any more. I hope the blahgosphere will pick up on this and that we see Stories targeted to the normals that explains these sorts of things to them. Grandma may not care too much about her phone being listened to (after all, it was always so, to her at least..), but if you explain to Grandpa that there is a secret code that will tie every single printed sheet back to his house-hold, well, that may raise a few shingles ..
- fixermark 9y agoI'm curious: If there is a war going on, did this leak help or hinder? Which side did it help or hinder? Who benefits from this leak, and who is harmed? I have a sinking suspicion that the average American, for example, isn't benefited by this leak.
- tanderson92 9y agoHave we learned nothing about the NSA's tactics? The Intercept publishes reporting that they would rather not have been printed, and the very day the DOJ unseals charges where they try to say they learned about the leak from a paper crease from what can be reasonably inferred to be The Intercept. Meanwhile the alleged leaker allegedly used her work computer to contact The Intercept (in contradiction with their recommended best practices). It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again. Do we still really trust the NSA? It was disappointing yet expected from the WaPo that they took as fact everything the DOJ alleged about how the case proceeded.
- user982 9y ago> It has all the appearances of the government trying to smear a news outlet and ensure no one leaks to them again. A scheme that would be less effective if not for The Intercept's demonstrably deficient opsec in protecting its source in this affair.
- tanderson92 9y agoIf you trust that what the NSA/DOJ says is true, sure.
- CogitoCogito 9y agoThere's no evidence that it was The Intercept's actions that caused her to be found. I agree that they should be more careful (they should _always_ be more careful), but there are many ways the source could have been found independent of the newspaper. Regardless, the government has many incentives to claim that it was The Intercept's deficient opsec that caused them to find the leaker. There really isn't much you can reasonably conclude about this. Is the government lying? Is The Intercept incompetent? The only thing you should remember is that if you are going to leak documents you need to do as much as possible while they are still in your control to hide your involvement. Once you send them off, your fate is in the hands of others.
- deleted 9y ago
- hdolt 9y agoIt's getting complicated managing 25 year olds at work these days. Lot of mistrust and entitlement issues I have never seen before. If you are a manager any suggestions about how to handle this stuff?
- davexunit 9y agoHow about getting a handle on your own prejudice against young people?
- castis 9y agoNot having your crew do things they would perceive as morally reprehensible is a fantastic start. Aside from that, providing an environment where they can disclose and/or discuss their issues with you would also work well. Any other measures of "putting a stop to it" will only make it worse.
- Danihan 9y agoDon't hire immature people for important jobs?
- pine56 9y agoI like to check on the kind of social circle they maintain. Loners generally don't get what it takes for a group to come to consensus about the grey stuff.
- rhizome 9y agouser: pine56 created: 15 minutes ago
- RickS 9y agoHow to handle mistrust and entitlement: Be trustworthy, and speak candidly about compensation.
- rhizome 9y agoWhat do you have to gain by changing the subject, and why the green account? Create an "Ask HN" with your other (established) account.
- apeace 9y agoThe yellow dots thing was certainly a mistake on their part. But there's a much bigger issue I haven't seen anyone point out yet. One thing that the Intercept--and Glenn Greenwald in particular--have been very critical of is news organizations that blindly publish leaks as verified facts. Here[0] is just one example where Greenwald writes: > THE WASHINGTON POST late Friday night published an explosive story that, in many ways, is classic American journalism of the worst sort: The key claims are based exclusively on the unverified assertions of anonymous officials, who in turn are disseminating their own claims about what the CIA purportedly believes, all based on evidence that remains completely secret. Now, in this case they at least have a document, which they verified was a real document created at the NSA. But even the Intercept's own article[1] admits: > A U.S. intelligence officer who declined to be identified cautioned against drawing too big a conclusion from the document because a single analysis is not necessarily definitive. So, are they living up to their own standard here? I don't think the answer is black and white. But I am certainly tired of hearing all this talk without seeing the technical details. If the U.S. election system was hacked--even just one voter registration company--the American public deserves to get the details. Period. What were the IP addresses used, and what ties them to Russia? What does the malware actually look like, and has it been seen before? How was this whole thing discovered? For now, all we have to go off of is what the NSA says may have happened. That it was a leaked document doesn't make it any more revealing than if it was a phone conversation with another unnamed official. [0] https://theintercept.com/2016/12/10/anonymous-leaks-to-the-washpost-about-the-cias-russia-beliefs-are-no-substitute-for-evidence/ https://theintercept.com/2016/12/10/anonymous-leaks-to-the-w... [1] https://theintercept.com/2017/06/05/top-secret-nsa-report-details-russian-hacking-effort-days-before-2016-election/ https://theintercept.com/2017/06/05/top-secret-nsa-report-de...
- fixermark 9y agoHow does the information you're describing (IP addresses used, ties to Russia, malware shape) help the average American if disclosed publicly? Because the harm seems immediate: bad actors will change their tactics and burn their channels, making them harder to detect, trace, or understand. Given that the average American barely understands what a computer virus is, is the level of technical detail you're calling for sensible for public dissemination?
- Cozumel 9y agoCheck their very public social media profiles[0], Reality Winners reads like she escaped a psych ward so how she was ever given clearance should be an issue in itself. [0]http://www.informationliberation.com/?id=56840 http://www.informationliberation.com/?id=56840
- rmxt 9y agoSays the person linking to "informationliberation dot com". Pot, meet kettle. Sure her twitter profile is highly politically charged and should likely have made her unfit for clearance, but citing that as evidence that she should be institutionalized is ridiculous. She'd likely say the same about you given your proclivity for "informationliberation". Where does that leave us for discourse?
- deleted 9y ago[deleted]
- vultour 9y agoHe never said he was fit for a top secret clearance. Her Twitter profile should've been an instant disqualification from any sort of security clearance.
- rmxt 9y agoNor did I say that the poster here was fit or unfit. I speculated about what two extreme opinion holders would say to one another. My point was that polarizing the discourse and reducing the other side to "just came out of the psych ward" does absolutely nothing to further reasonable arguments.
- VLM 9y agoHave either of you been thru clearance? I have. They're really excited to know if you can be bribed with drugs or sex or simple money. If you have the politics of a typical college professor they're not terribly interested. The clearance process was mostly CYA, was this candidate dumb enough to say he'd sell secrets to the soviets for weed or cash to pay loansharks or kinky sex? I've read this woman's weird social media profiles. What a nutcase. The systemic failure was in her direct superior not discussing some red flags that would be noteworthy at any other organization with HR and/or the police. Her boss is supposed to be having an awkward conversation with HR beginning with "So I've got this direct report, and in public she hates the CEO. And she's intensely racist, everything with her is all about race race race, and btw she bitterly hates the CEO's race, although she likes some other races. So she hates the race of some coworkers including the big guy, and she likes the race of other coworkers, and says this all in public which must be very intimidating to her coworkers. And she hates a couple entire countries include some that we have coworkers from which must be very awkward in the office. And she tweets out parodies making fun of the CEO, in public. And she denies and parodies the CEOs policies, and denies the CEO is the legitimate leader of the company, which makes me think shes not going to react rationally at all, if the CEO or anyone else in the chain of command disciplines or fires her, we're going to need security if not cops present. And she identifies her own race as being terrorists, which in an era of workplace violence frankly scares me, and she does this in public so her coworkers see her identify herself as terrorism race or whatever violent idiocy, and we're making an incredibly hostile workplace for every coworker who's not suicidal or martyr complex. She believes she's about to die from climate change or some nonsense, the specifics don't matter, which is super terrifying in the context of self identifying as being a terrorist, making me scared she's going to strike first perhaps. So, HR person, do we wait for her to go postal and shoot the entire office, or is there some kind of employee assistance plan for mental illness I mean if this can all be fixed with some pills she seems otherwise OK, or can we call security and fire her WRT the whole workplace violence thing combined with her bitter racism toward coworkers or the ethnic thing where she hates certain countries that we have coworkers in/from or ..."
- chakalakasp 9y agoAny article that ends with a yes/no question is always answered with "no". This one is no exception. Print classified info out at work on work printers from a monitored work computer you are logged into and said info ends up with reporters days later? Reporters you communicated with over gmail?! This person isn't exactly an infosec genius. Which, I mean, isn't a sin or anything, but when you know the organization you are directly burning is the NSA and the president of the United States, that's almost an insane level of ignorance.
- braderhart 9y agoUnless you are a whistleblower and feel that the public legitimately needs to know about something, because afterall this election affects our daily lives. We deserve to to know the truth about threats to democracy, especially when Presidential candidates are still claiming that voter data was rigged. Didn't Trump blame Hillary for him losing the popular vote, saying that it was her fault for hacking the election?
- chakalakasp 9y agoWhat are you replying to? It can't be my comment.
- braderhart 9y agoI'm suggesting, maybe it wasn't ignorant. I can think of a few examples of where I'd want to be transparent in my actions. Seems like as a whistle-blower you should be as transparent as possible. I think it is time that we see the Russian evidence though. A bunch of techies deserve to disseminate if it is legitimate. Afterall, WikiLeaks has been doing nothing but providing verifiable evidence.
- deleted 9y ago[deleted]
- JeremyBanks 9y agoWas it really vital that this tidbit be leaked right now now? Mueller is currently performing an extremely detailed official investigation of this topic and has access to this and much more information, the resources to follow up, the motive to find the truth. Whistleblowing is warranted in cases where information pertinent to the public interest won't come out otherwise. Given Mueller's investigation, the responsible thing would have been to wait and see, unless you had reason to doubt him.
- paralelogram 9y agoWhy are almost all official documents about Russian government-sponsored hackers "secret" or "top secret"?
- RickS 9y agoCounter question: why wouldn't they be? Either their methods work, and of course they should be secret, or their methods don't work, and it's unproductive to help them shorten the list of attack methods they try.
- cmiles74 9y agoIn this case, my guess would be fear that people would start distrusting these voting machines and, eventually, the election as a whole. Elections only work when everyone agrees the results are fair. That said, I think that's an important story here. The infrastructure around these machines seems sloppy. The fact that there's no source code to read means they are black boxes we have to trust.
- throwaway-1209 9y agoNah. Only 6 people have printed the doc and of those only one could be found in phone call metadata making a call to a press related contact. I don't know what the leaker was thinking. And in the end even this leak doesn't contain any evidence of anything that would even tie it to Russia, let alone GRU. On the internet no one knows you're a dog. So she will get 10 years in the slammer for nothing.
- strictnein 9y agoThe Intercept scanned the document and posted high quality versions of them online. They were of such quality that the embedded dots modern printers add to each page were readily available: http://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html http://blog.erratasec.com/2017/06/how-intercept-outed-realit... It pointed to the exact printer being used and the exact time and date the document was printed. They didn't need her email to figure out it was her, but I'm sure that will help them in her court case. edit: cleaned up some sloppy verbiage
- blackflame7000 9y agoPretty sure she sent the document which means she made the mistake of sending high resolution scans.
- lovemenot 9y agoThe article talks about a postmark from Augusta, GA. Presumably, she mailed the printed document.
- deleted 9y ago[deleted]
- cmiles74 9y agoIn the vast majority of cases, the watermark data wouldn't point anywhere interesting. Maybe the serial number would point to a public library or a warehouse where the printer was stored prior to sale. Certainly The Intercept had no way of knowing that the serial number would correspond to an office printer at the NSA or one of their contractors. I don't think we should expect news outlets to scour every printed document for these watermarks and remove them. Most aren't that technically savvy and this solidly seems like the responsibility of the person doing the leaking. Leaking is dangerous and risky. I don't know the leaker personally but I could understand someone feeling that documents need to be released to the public and, at the same time, feeling like they can't evade the NSA's investigation. At that point any counter-measures probably seem pointless, especially for those who are not technical and can't imagine any bounds to the NSA investigative powers.
- dfaga 9y agoYes
- rndgermandude 9y agoYes, TheIntercept did compromise their source, although she did compromise herself as well due to poor opsec. - TheIntercept failed to sanitize the documents before posting - They provided the govt (or rather a govt contractor) with further information, at least that the mail was posted in Augusta, Georgia. The former can be attributed to simple mistakes, but at least the latter is gross negligence of the highest order. Given these two things alone, even if she had her own opsec in order, she'd likely been found out.
- microwavecamera 9y agoBut it also begs the obvious question, has TheIntercept been compromised by one of the alphabet agencies? Could it have been intentional on TheIntercept's part but done in a way that gives them plausible deniability? Does seem interesting that TheIntercept isn't treated like Wikileaks for essentially doing the same thing, especially seeing how they're a domestic organization.
- 21 9y agoOff topic, her name is "Reality (Leigh) Winner"? Is this a new trend? Can you name your child with any surname you wish? For example "Tower John Trump".
- defined 9y ago> The methods presented in this paper have many applications in law enforcement such as tracking, counterfeiting, and child pornography. The downside is that they provide a mechanism for a simple device, a printer or a digital camera, to spy on its user. A typical user cannot turn off these signatures, particularly the intrinsic signature, without very detailed knowledge of how the device operates. This could have dire consequences for many important uses of these devices in our society. For example a whistleblower who would like to share documents with a regulatory agency could be in danger in that their printer could be identified as the one that produced the documents. [1] Prophetic words from a 2008 paper (PDF) [1]. This paper may be duplicate information, but reading this paper impressed upon me how many more ways there may be to spy on people than I could imagine (and I know about some existing things like side-channel attacks... how do I spy on thee? Let me count the ways.) So don't register your printer with the manufacturer, folks; the serial number may be on every page it prints. Ditto for digital cameras. Then again, is fighting for digital privacy a losing battle when at every turn, there are deliberately hidden bits of PII? Pun intended. [1]: https://engineering.purdue.edu/~prints/public/papers/sp_article_09_chiang.pdf https://engineering.purdue.edu/~prints/public/papers/sp_arti...
- lubesGordi 9y agoI'm not clear on what the motivation for this 'leak' would be. Is it morally reprehensible for the NSA to withhold this information from the public? Was the NSA doing something illegal by withholding this info? If the only actionable information leaked is politically charged or simply falling within the established/mass media narrative, is it wrong to suspect this 'leak' is disinformation?
- elefanten 9y agoReally? All kinds of motivations are easy to imagine, but the reporting about the leaker herself indicates that she maybe just did it for political reasons (ie- she is Anti-Trump). But given the response and the constellation of corroborating info from various sources, it seems pretty reasonable at this point to presume it is NOT disinformation. It's almost certainly not a complete picture of what various parties know and it's likely a snapshot of an evolving knowledge base (ie- the broader intelligence community's knowledge of what was going on before and during our election). But the presumption that it is not 'false' information should be pretty solid by now.
- mowenz 9y ago>The leaks contain no "raw" evidence Something stinks here. Both WaPo and the NSA, who Greenwald has picked fights with, get to smear The Intercept, while we are supposed to bekieve the leaker has extreme incompetence (flagrantly incriminating herself while using a pseudonym), and meanwhile the public still has no evidence of the election tampering. It's not like the Deep State didn't lie to the country to wage a war in Iraq not long ago. The public deserves to see proof.
- cproctor 9y agoI wonder whether NSA uses syntactic watermarking[1], imperceptible changes to word order or sentence form, keyed to the user accessing a document. This, or other techniques of embedding a fingerprint in the text itself, would allow a leaker to be identified from just a transcription of the document. What is the right amount of fuzzing for a news organization to perform on leaked documents, to protect a source while providing credible evidence to support a claim? Meral, H. M., Sevinc, E., Ünkar, E., Sankur, B., Özsoy, A. S., & Güngör, T. (2007, February). Syntactic tools for text watermarking. In Electronic Imaging 2007 (pp. 65050X-65050X). International Society for Optics and Photonics.
- wyldfire 9y ago> What is the right amount of fuzzing for a news organization to perform on leaked documents, to protect a source while providing credible evidence to support a claim? Maybe paraphrasing the key points or claims of the document would be the only safe way.
- DGAP 9y agoThat seems entirely possible, although considering the scanned classified report also contained printer watermarking that identified the printer serial number, it also seems unnecessary.
- cylinder 9y agoHow would changes to word order or sentence form be imperceptible?
- matt4077 9y ago"Imperceptible without comparing to other versions of the same document"
- microwavecamera 9y agoConsidering the NSA is an intelligence agency, arbitrarily changing info in intel documents could have serious potential repercussions. I'm thinking they wouldn't unless it was part of a counter-intelligence operation.
- kharms 9y agoI think the real fuckup is including in the article the method for IDing a Russian agent - registering with a personal phone number. That's the kind of mistake that could have been made again, but now probably won't be. On the whole I think this information needed to get out. There were reports of people all over the US being dropped from voter registration rolls, and now proof that the Russian military targeted voter registration companies.
- interrupt13 9y agoI can't help but feel a Zen-like sense of balance and bliss over this. An NSA contractor violated her employment agreement and the law in providing Top Secret info to The Intercept, who then published it. The Intercept got a story published and is enjoying great attention (and ad revenue), and the guilty party was caught. Everyone can be happy. "God’s in His heaven — All’s right with the world!" [R. Browning]
- gorhill 9y ago> The Intercept got a story published and is enjoying great attention (and ad revenue) There is no ad revenue at The Intercept.
- linkregister 9y agoWhat I find interesting is that the email from the Gmail account on the work computer was able to be intercepted and logged. What mechanism might they have used, an SSL proxy with a pre-loaded root certificate? How long is this data logged?
- peterwwillis 9y agoHow long would the National Security Agency keep copies of the internet sites visited by contractors with access to classified reports while inside secure facilities? How long until the protons in the backup tapes decay?
- mi100hael 9y agoYes, that's pretty standard fare for a corporate firewall/proxy. Most configurations don't log everything, just traffic matching particular patterns or hosts. But when it's the NSA, who knows how much they retain.
- m-j-fox 9y ago> pretty standard fare for a corporate firewall/proxy It is? So corporations install something that infects your laptop and updates the root certificate every time Chrome or Firefox updates? Sounds extreme to me. Something the NSA might be able to do, but hopefully not my company.
- dboreham 9y agoIt is and they do. You'll find many historical threads here discussing cases where interested parties were actively campaigning to thwart anti-MITM measures being added to TLS, because they broke their MITM attacks that their businesses depend on.
- mjcl 9y agoIf you're running Windows, it's built into the OS using Group Policy. Very helpful when a company is running it's own internal CA/PKI.
- fnordfnordfnord 9y ago* Our leaker is a person with a Twitter timeline that makes you wonder how she maintained her Secret clearance. She retweets @Snowden, yet was hired at Pluribus in Feb. of this year, days after doing so. * The story is a huge black eye for the Intercept, makes it look like they are very inept. * The leak is not really substantial, mostly analyst notes about an ongoing thing that's been talked up in the press quite a bit. * The DocuColor thing is ancient as well: https://www.theregister.co.uk/2005/10/20/outlaw_printer_dots/ https://www.theregister.co.uk/2005/10/20/outlaw_printer_dots... Maybe my tinfoil hat is on too tight, but this just has a funny odor to it. One might speculate that this is a calculated leak intended to discredit The Intercept, sow fear in the minds of potential leakers?. If the comments on other forums are anything to judge by, there are at least two groups of paid astroturfers battling it out today.
- danso 9y agoShe had top secret clearance prior to being hired by Pluribus in February. She was formerly in the Air Force and apparently specialized in Middle Eastern languages. Apparently, top secret clearance is renewed every 5 years [0], so she may have had carte blanche to do what she wanted for a few years. [0] http://www.military.com/veteran-jobs/security-clearance-jobs/avoid-having-security-clearance-expire.html http://www.military.com/veteran-jobs/security-clearance-jobs...
- fnordfnordfnord 9y agoI don't know how that works, but I'd be surprised if there were not a sort-of abbreviated check?
- scottLobster 9y agoWhy would there be? Pluribus doesn't issue security clearances, the customer agency (in this case the NSA) does. It would be up to the NSA to do any additional background checks/vetting/polygraphs regarding security clearance for any contractors. Working for a contractor/switching jobs is hardly suspicious activity, so the NSA would have no reason to investigate her. Likewise Pluribus had no reason to be suspicious, so the most they'd do beyond the standard corporate background check is call up the NSA to confirm her clearance was active. At the end of the day even the NSA doesn't have the resources to be constantly vetting 100,000+ employees and contractors.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- andy_ppp 9y agoIn other news, if you are leaking set up a hidden camera in someone's room, steal their password and do everything from their account. Or if you are really moral just set up the camera above your desk. A bit of plausible deniability is much better than life in a supermax I promise...
- _Codemonkeyism 9y agoBoth fumbled with opsec. But the Intercept considers themselves the pros.