4 ms·
It’s a little more than “letter of the law” when he’s using a personal email address for NSA work, and also sending anything classified outside of official chan
by kejaed 5y ago
It’s a little more than “letter of the law” when he’s using a personal email address for NSA work, and also sending anything classified outside of official channels. He definitely knew better.
- core-utility 5y agoI have no source on this, but I don't believe NSA employees have unclassified/public email addresses. It might be common to use a "personal" email for some work-related communication like this. On the subject of classification, that has no excuse.
- andrewflnr 5y agoUm, no. I've definitely sent unclassified emails to @nsa.gov addresses, when I worked in government. They would be crippled if they didn't have some way to email the outside world.
- aaomidi 5y agoFew things in the security world: - Blaming people for accidents is stupid. Throwing them into prison for accidents is even stupider. - Proper security is designed in a way that people can make mistakes and it doesn't mean the end of the world. Him knowing better about this isn't really a response to OP's initial comment of being against a lengthy prison sentence. The prison sentence accomplishes absolutely nothing. You're just ruining a person's life as they were retiring and breaking a family apart. Makes no sense if this was indeed an accident.
- subjectsigma 5y agoYour comment doesn't really make any sense. It seems to imply that the DoD rules are backwards and that it's actually the fault of the NSA that the guy leaked this. Which I don't understand. If he emailed a classified document, there is absolutely no way in hell that was an accident. You are never, ever, ever supposed to put classified information onto an unapproved system. This is like saying, "Oh, I forgot which pedal does which, so I slammed the gas instead of the brakes and killed someone, but it was an accident so I shouldn't go to jail." No, you're definitely going to jail, you 'forgetting' how to drive doesn't mean you didn't ruin someone's life. (There's a small chance that he could have wrote something classified from his brain into the body of an email and sent it. People don't get sent to jail for this, provided it's a one-time incident. If he's getting charges pressed it was pretty egregious. The term "gross negligence" comes to mind.) And it really could be that critical. Classified information is classified because it can be damaging. If you leak the names of people spying for you in foreign countries, they might be captured or even killed. How do you "design the system" to allow for that "mistake"? Finally, the prison sentence lets people know that security is serious. There are many rules and it takes effort to follow them. People get lazy and cut corners when there aren't consequences.
- nix23 5y ago>DoD rules are backwards and that it's actually the fault of the NSA that the guy leaked this Exactly that, how is it possible to have access to Highly-secret stuff but also to your personal email? Something is not right here.
- smorgusofborg 5y agoThis isn't really a coherent statement. The DoD's rules do prevent this; the NSA refuses to follow DoD rules.
- nix23 5y ago>The DoD's rules do prevent this; the NSA refuses to follow DoD rules. Well then it's like i said....there is something wrong ;)
- subjectsigma 5y agoDCSA and whatnot cannot constantly watch everyone all the time. They also cannot prevent every single possible edge case and scenario. If they tried, nobody would get anything done. You could be told classified information, go home that day, and tell your wife the same thing. There is literally nothing they can do to prevent that except make sure people know there are consequences to doing so. There are many such examples. Classified CDs is a good one. There are many rules related to classified CDs, but at some level you have to trust your people are following these rules. This is why getting a clearance is more difficult than the average job interview, and why people from the Intel communities take leaks so personally. It has to be part of the culture.
- nix23 5y ago>It has to be part of the culture. Funny that no one in a financial institute has access to private mail (Switzerland), USB is deactivated, to Surf the Web you need another laptop, no one has access to backups (Mainframe etc) without the knowledge of the CEO but maybe the data is more worth? But yes at the end of the day you have to trust your peoples....but private email from your working-machine....that's borderline dangerous.