4 ms·
I remember hearing about bad OPSEC at Volkel. Something about how there was sensitive national security secrets indirectly being leaked bc soldiers didn’t set t
by The28thDuck 4y ago
I remember hearing about bad OPSEC at Volkel. Something about how there was sensitive national security secrets indirectly being leaked bc soldiers didn’t set their Quizlet flashcards to private when studying for their exams.
- DigiDigiorno 4y agoWow, I missed that one. I just looked it up. https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/ https://www.bellingcat.com/news/2021/05/28/us-soldiers-expos... I know these human mistakes are inevitable in a large organization, but it's still sobering seeing that a soldier would post nuclear vault release code locations and more online. I guess it's easy to be careless in the daily grind whether it's PII or nuclear secrets...
- warner25 4y agoIf someone puts classified information into Quizlet, that constitutes spillage whether they set it to private or not. Sometimes this kind of thing needs to be explained even to very senior people, not just lowly troops. I knew of a four-star general asking a few years ago why we didn't use Signal for stuff instead of Teams (O365 tenant hosted in Microsoft's Government Community Cloud), because he "heard that it's so secure that even the NSA can't break it." The answer is that there's a difference between a system being "secure" and being accredited for classified information or even unclassified information that the government owns. Edited to add: Another very senior DoD person actually got in trouble for using Signal for official business a couple years ago because, among other reasons, there's no way for the government comply with FOIA when someone is using a personal account on a commercial application like that.
- vuln 4y ago> Edited to add: Another very senior DoD person actually got in trouble for using Signal for official business a couple years ago because, among other reasons, there's no way for the government comply with FOIA when someone is using a personal account on a commercial application like that. Do you have any additional information on the punishment? The precedence has been set that “no reasonable prosecutor “ would prosecute someone over using personal servers/apps/out band communication to subvert FOIA and National Security. > Although we did not find clear evidence that Secretary Clinton or her colleagues intended to violate laws governing the handling of classified information, there is evidence that they were extremely careless in their handling of very sensitive, highly classified information. > Although there is evidence of potential violations of the statutes regarding the handling of classified information, our judgment is that no reasonable prosecutor would bring such a case. https://www.fbi.gov/news/press-releases/statement-by-fbi-director-james-b-comey-on-the-investigation-of-secretary-hillary-clinton2019s-use-of-a-personal-e-mail-system https://www.fbi.gov/news/press-releases/statement-by-fbi-dir...
- ambicapter 4y agoYour quoted text doesn't reflect the sentence you use to introduce it > there is evidence that they were extremely careless in their handling of very sensitive, highly classified information. is not the same thing as > using personal servers/apps/out band communication to subvert FOIA
- boomboomsubban 4y agohttps://www.nextgov.com/cxo-briefing/2021/06/defense-digital-service-director-used-signal-violation-pentagon-policy-ig-says/174879/ https://www.nextgov.com/cxo-briefing/2021/06/defense-digital... He stepped down, and my quick search doesn't show him actually facing punishment. And his case was different, as some members of staff did believe he was encouraging use of Signal to prevent FOIA strikes.
- warner25 4y agoYeah, I have no inside knowledge, but it certainly looks like nothing in the way of criminal punishment. From various articles, it sounds like he only intended to do a two-year term, and he actually stayed in the position a few months after that while the investigation was taking place. He stepped down before the report was finally published: https://media.defense.gov/2021/Jun/21/2002745247/-1/-1/1/DODIG-2021-092.PDF https://media.defense.gov/2021/Jun/21/2002745247/-1/-1/1/DOD... Per his LinkedIn page, he went straight to what is probably a cushy job at Vanderbilt University. Interesting career path, by the way. He was "Director of IT at OpenTable" for seven years, and then did four years as a "Police Officer" in the Chicago PD before going back to IT stuff there.
- Spooky23 4y agoProsecutorial discretion does not have precedent.
- iamerroragent 4y agoI'd like some toasted hombres with a nice big fat slab of butter please.
- itronitron 4y agouhm, setting the quizlet flashcards to private would have still resulted in a leak of sensitive data...
- whalesalad 4y agoYou’re not wrong - but “If a tree falls in a forest and no one is around to hear it, does it make a sound?” comes to mind.
- havblue 4y agoThe espionage act treats negligence with strict liability. So if you "could have" caused a leak, it's still treated like a leak.
- whalesalad 4y agoIs your username an homage to the stealth fighter?
- havblue 4y agoYes
- dragonwriter 4y ago> The espionage act treats negligence with strict liability “Negligence” and “strict liability” are different standards, you can’t treat one with the other. > So if you "could have" caused a leak, it's still treated like a leak. That’s very much not how the Espionage Act works, even just on the statute and beforr considering Supreme Court precedent limiting its application.
- havblue 4y agoMy original explanation wasn't that good and yes, I conflated the espionage act with how this situation would be handled (by the DOD) https://www.cyberdefensemagazine.com/data-spill-an-everyday/ https://www.cyberdefensemagazine.com/data-spill-an-everyday/ This is a better summary. At the start, everyone's phones would likely be confiscated and, I would think, destroyed, if they were discovered to have classified data on them. However, if the data was in the cloud it would be an even bigger deal.
- WeylandYutani 4y ago(When Russia opened its archives in the 90s we learned were all the nukes in Europe were stored. It wasn't a secret to the KGB). Officially to this day this is all a Dutch state secret (can neither confirm nor deny bla bla bla). But there was an interview with ex prime minister Lubbers and he talked about the nukes. The poor man's mental faculties were already slipping. If anyone is wondering according to NATO plans as I understand it the Dutch Airforce is supposed to be under US command dropping the bombs. A bit of a democratic cluster fuck that bypasses parliament to initiate nuclear Armageddon.
- Someone 4y ago> But there was an interview with ex prime minister Lubbers and he talked about the nukes. He wasn’t the only one. FTA: “two former Dutch prime ministers and a defense minister in 2013 even acknowledged the presence of the weapons.”
- gambiting 4y agoThat last part is literally in the article. If US President, UK Prime Minister and NATO Nuclear planning group all approve the strike, then the weapon is loaded on a Dutch F-16 and dropped by a Dutch pilot.
- bpye 4y agoThey had a linked article talking about a prior exercise [0] which includes the source for that procedure [1]: > “If NATO was to conduct a nuclear mission in a conflict,” NATO says, “the B-61 [sic] weapons would be carried by certified Allied aircraft…However, a nuclear mission can only be undertaken after explicit political approval is given by NATO’s Nuclear Planning Group (NPG) and authorisation is received from the US President and UK Prime Minister.” It is unclear why the U.K. Prime Minister would have to authorize employment of U.S. nuclear weapons, and unless NATO territory had been attacked with nuclear weapons first, it seems unlikely that the 29 countries in the NPG would be able to agree to approve of employment of non-strategic nuclear weapons from bases in Europe. It is interesting that use of the weapons would require authorisation by the UK PM. In WW2 mutual consent was required due to the Quebec Agreement [2], but that requirement was included in later treaties. [0] - https://fas.org/blogs/security/2022/10/steadfast-noon-exercise-and-nuclear-modernization/ https://fas.org/blogs/security/2022/10/steadfast-noon-exerci... [1] - https://www.nato.int/nato_static_fl2014/assets/pdf/2022/2/pdf/220204-factsheet-nuclear-sharing-arrange.pdf https://www.nato.int/nato_static_fl2014/assets/pdf/2022/2/pd... [2] - https://en.wikipedia.org/wiki/Quebec_Agreement https://en.wikipedia.org/wiki/Quebec_Agreement