7 ms·
Why David Petraeus’s Gmail account is a national security issue
- rpm4321 14y agoWho knows if it's accurate, but Buzzfeed is reporting that it may have been Anonymous as part of its Stratfor attack: http://www.buzzfeed.com/zekejmiller/anonymous-may-have-hacked-petraeus-mistress http://www.buzzfeed.com/zekejmiller/anonymous-may-have-hacke...
- kinble32 14y agoI doubt it.
- Zigurd 14y agoThe news story there claims the first step in this scandal was that Paula Broadwell's yahoo account was compromised. That's not too hard if you can guess her password hints. The next step, it seems, was sending some trolling emails. That requires acquiring or just guessing some email addresses. The people who got the trolling emails set the discovery of the affair in motion. Well played. But did not require a 133t hAx0r.
- staunch 14y agoIf I was a foreign government I'd have multiple spies working inside Google by now.
- thechut 14y agoI'm sure the US government DOES have spies working inside Google as we speak
- GHFigs 14y agoYou're sure?
- jballanc 14y agoI'm sure the US doesn't need to bother wasting the resources required to train and embed a spy when a lawyer with a subpoena will do...
- alexgartrell 14y agoI know that this is a pot shot against the American legal system (especially with regard to copyright stuff), but it really makes no sense. A spy would likely be no more expensive than a legal team (in fact, he'd be subsidized by his salary at Google) and would be monumentally more effective and secretive. Beyond that, the hard part of training a spy to get into Google would be getting a good enough computer science student involved. From there, it's really just a matter of teaching them to cover their tracks semi-intelligently. However, given what I'm sure is a mountain of completely legitimate reasons to look at user data (for example, to resolve data corruption, investigate malicious users, etc.) and an inconceivably larger mountain of user data to look at, I don't actually think it'd be that hard to get away with it.
- neurotech1 14y agoA surprisingly few people at Google have the authorized access to read a users GMail mailbox. It would mainly be the GMail Site Reliability Engineers, and support teams. The developers usually don't access to peoples inboxes. Any support/SRE/developer access to a users' GMail mailbox would be logged and if they exceeded their authorized access by such as accessing a "public" persons email, They'd be fired pretty quickly.
- alexgartrell 14y agoI'm sure the auditing and control is more than enough to stop your average creeper employee from reading normal people's inboxes, but I very much doubt that it's enough to stop a very smart, very determined spy from doing the same. At the end of the day, someone has root, and that guy can do pretty much anything. I'm confident that Google is doing a better job than pretty much anyone else, but this problem is a more or less unsolvable one. Edited to add that another interesting idea is that the people who man the DC's are actually pretty sparse (relatively few people for a lot of servers) so it's not inconceivable that one could trigger a failure on an important box, take down a replica of the figure's mailbox, swap out the drive for RMA and then do a quick copy. I bet this would be easy. I guess my point is that no level of internal controls at any company can actually stop a determined government. If that were true, governments, which are much more paranoid than tech companies, would have eradicated spying a long time ago.
- ImprovedSilence 14y agoI'm sure the US doesn't need spys working in Google. I'm sure there is systemic collaboration with the NSA, to the point where they don't need spys "working" for google. Also, I think actual spys are placed much closer to personal sources of information, not technical. If that makes any sense. I guess I'm trying to say is, if you are going after computer information, you're going to get it from the outside. If you're going after people information, you're going to have a guy on the ground.
- walshemj 14y agoOne would hope that the US has something like list X status for companies that are sensitive (and telcos and coms companys are) and have senior people and those with acess to sensitive information vetted. I know a senior developer in British telecom who worked on the system that tracks every private circuit in the UK and she was being PV'd (positively vetted its called developed vetting these days) - as she had root access to this system same as being TS cleared in the USA.
- danso 14y agoWell, Petraeus gets a +1 for not using his official e-mail account, or an old DoD account for this. In fact, it's kind of pleasantly surprising that he used GMail over...say, an aol.com address. In fact, it seems that for any given government official who wants to conduct risky non-official business, using something like GMail would actually be the more secure route, if you were trying to keep secrets from both your employer (which includes the public and public record requests) AND from the usual enemies of the state. If both Petraeus and Broadwell had used GMail accounts not associated with their names, such Dave501010@gmail.com and PaulSmith900@gmail.com, how likely is it that anyone would discover their shenanigans? For an enemy of the state to find out, it would have to compromise both GMail and somehow connect Dave501010@gmail.com with David Petraeus. Sure, it's security through obscurity, but we're talking a nearly unsurmountable amount of obscurity. Of course, once they start forwarding emails from their private account to their publicly known addresses, then the game is riskier. There's also the problem of keeping the ruse without making an AutoComplete mistake, such as sending a message from petraeus@cia.gov to PaulSmith900@gmail.com without realizing he's logged in as petraeus@cia.gov.
- toomuchtodo 14y agoI argue that mail clients should have a blacklist option: When logged in as account X, NEVER permit me to send email to email address Y.
- Daniel_Newby 14y agoThe blacklist can be compromised, which is a larger vulnerability than having no blacklist.
- toomuchtodo 14y agoI blacklist is modified, notify me via SMS (the same way Google/Facebook can handle you not able to get into your account).
- TeMPOraL 14y ago
- ricardobeat 14y agoHe wasn't even using two-factor authentication?
- eigenvector 14y agoHow would two-factor authentication stop the FBI from lawfully demanding your email from Google?
- ricardobeat 14y agoHis mistress accessed his e-mail first, not the FBI.
- cbsmith 14y agoActually, sounds like all they had to go on was she got certain e-mail addresses. Seems kind of thin really.
- dror 14y agoThere's a log of bogus assumptions in these articles, and he got caught because she was investigated, not him. If he used a gmail account and used a separate device such as a private smart phone or tablet to access that account there would have been zero vulnerability, other than the fact that he could have been blackmailed. Gmail is pretty hard to hack into, the IP address of the device probably wouldn't tell anyone anything about where he is, since it's a private IP on the telco (can you tell a person's location from the IP on the telco?), and there wouldn't be any way to get to any of his secure accounts or make a mistake of using the wrong email account.
- patrickgzill 14y agoTelco's log everything! So it would not have been difficult, if you could connect the phone number to him, to track everything else.
- mynameishere 14y agoPetraeus's personal email should be no more sensitive than the mailbox outside his house, which any junkie could "hack". If he put classified information on google's servers, that's a whole different problem. This is a non-issue and a distraction from the real reason why he was forced out.
- pemulis 14y agoThat depends on what he used the e-mail address for. If it was strictly for romantic liaisons, it's no big deal. But if he used it for any other purpose (talking with his lawyer, chatting with senators, etc.), it would be a hell of a platform for social engineering attacks. In that scenario, the information in Petraeus' personal inbox is beside the point[1]; you can use the trusted address to get your hooks into something more interesting. [1] Ignoring the blackmail value of the affair.
- kposehn 14y agoThe most likely explanation is that she accessed his smartphone or computer when he was not looking.
- mayneack 14y agoSounds like Janet Napolitano has the right idea. http://techdailydose.nationaljournal.com/2012/09/napolitano-i-dont-use-email-at.php http://techdailydose.nationaljournal.com/2012/09/napolitano-...
- ChristianMarks 14y agoObviously Google should delete David Petraeus's account immediately. National security is at stake! ;)
- fleitz 14y agoYes, in the hands of voters that kind of information could ruin an administration. He should definitely be fired lest the public find out what the CIA is upto.