11 ms·
NSA Implementing 'Two-Person' Rule To Stop The Next Edward Snowden
- PavlovsCat 13y agowhere you are <---> Rubicon <---> where a sane person would want to be
- PavlovsCat 13y agoYeah, yeah. Yawn. I'm not hearing any words ;)
- meritt 13y ago> "make sure that if another person were to turn against his or her country" http://en.wikipedia.org/wiki/Dutch_Ruppersberger http://en.wikipedia.org/wiki/Dutch_Ruppersberger Dear Maryland: Please vote intelligently at your next opportunity.
- hfanson1 13y agoLooks like he won the seat in a gerrymandered district. This manipulation of district boundaries takes advantage of people who vote along party lines regardless of an individual candidate's qualifications.
- hga 13y agoExquisitely gerrymandered. Wikipedia closes with this note on the current one: "In 2012 the district was found to be the eleventh least compact congressional district in the United States." And a link to this article, which shows that district, and is titled "Maryland has least compact congressional districts in nation": http://marylandreporter.com/2012/10/03/maryland-has-least-compact-congressional-districts-in-nation/ http://marylandreporter.com/2012/10/03/maryland-has-least-co... Now, in all fairness they do have a cragy coast, but it is very clear the districts are unconscionably gamed.
- jmyc 13y ago> Now, in all fairness they do have a cragy coast, but it is very clear the districts are unconscionably gamed. I'm not sure how it was done in the source for that news article, but gerrymandering-detection algorithms should ignore natural borders in that regard. See, for example, this paper which measures gerrymandering in terms of convexity: http://mathdl.maa.org/images/upload_library/22/Polya/Hodge2011.pdf http://mathdl.maa.org/images/upload_library/22/Polya/Hodge20...
- alexqgb 13y agoThis point simply cannot be overstated. The absolutely deplorable level of "oversight" performed by Congress is a direct function of the degree to which they've been able to insulate themselves from the electorate. Being able to select who can and can't vote against them is one of their most effective means for doing this. Indeed, this practice explains why so many of them can hold onto their seats while continuing to act against the interests of their constituents in ways beneficial to their funders. In short, gerrymandering, closed primaries, and private campaign finance form the Triangle of Doom. In combination, they provide the noose with which Congress is choking America to death. Abuse at the hands of the NSA (and their multi-billion dollar web of contractors) is just the latest, and perhaps the most chilling example of this phenomena.
- saalweachter 13y agoPrimary elections, primary elections, primary elections. Primary him. Primary him credibly. Primary him principally on this issue.
- chm 13y ago“When one of those persons misuses their authority it’s a huge problem.” But of course, this doesn't apply to the Government. Why can't someone in power admit that surveillance has gotten out of bounds, maybe illegally, rather than devise ways to counter such divulgations?
- rfnslyr 13y agoNobody cares about anything unless it disturbs their daily rituals. At the end of the day, if they are still able to go to work, collect a paycheck, watch a movie, see their family, they aren't going to care. Similarly with government workers. They don't care. They want a paycheck. It's not their fault, it's somebody else. Until the government starts pointing fingers, nothing is going to happen. We've been carefully coaxed into complacency.
- rayiner 13y ago> We've been carefully coaxed into complacency. Or, we rationally process the information we have and conclude that we're okay with the status quo.
- rfnslyr 13y agoIt is not rational to agree with being spied on, lied to, and having our rights revoked. It's apathetic, and frankly, disgusting. Long as we can still instagram and facebook and tweet whatever the fuck we had for lunch today!!!!!! Right?
- jivatmanx 13y agoThe Roman republic actually did have a copresidency (two consuls).
- jlgreco 13y agoThey also had a functional Dictatorship system. Well, functional for a time... until it went wrong. I think they were actually onto something with that idea though. The flaws likely could have been corrected. A common theme with most dictatorships gone awry is a rogue general, but the real problem is a military comprised of men that are willing to follow a rogue general.
- throwaway10001 13y agoHey Booz Allen, we need another 6000 analysts to double team your other 6000 analysts. Truly yours, Current NSA Chief, and future Booz Allen Hamilton CEO.
- rhizome 13y ago"...and we will pay handsomely for this requirement."
- blahyawnblah 13y ago"The rule required that anyone copying data from a secure network onto portable storage media does so with a second person who ensures he or she isn’t also collecting unauthorized data." Don't mind me over here by myself, I'm not copying anything...
- jessaustin 13y agoHmmm. The impression I have is that Snowden had access as a sysadmin, not as an analyst. That is, he didn't really have any duties that called for him to access the "secret" data. If the systems allow sysadmins to bypass proper authorization procedures, what good is another authorization procedure? Perhaps they'd be better off auditing the ACLs. In the Cloud Era, very few machines ever need to allow root access. However, this scheme would seem to prevent previous "laptop leaks", so I think it's a good idea.
- spikels 13y agoNow Sunday's oddly worded press release makes more sense: "The statement that a SINGLE analyst can eavesdrop on domestic communications without proper legal authorization is incorrect" http://www.dni.gov/index.php/newsroom/press-releases/191-press-releases-2013/880-odni-statement-on-the-limits-of-surveillance-activities http://www.dni.gov/index.php/newsroom/press-releases/191-pre...
- jrochkind1 13y agoOr perhaps the emphasis should be on ANALYST. An Analyst maybe not, a sysadmin, oh, yeah, sure (and we have about 1000 of those). But really, I don't believe anything they say, or believe that I'm capable of figuring out the true meaning of the careful wording that they think they are using to 'technically' tell the truth while intentionally making everyone think they meant something else that was really a lie. I mean, Clapper has already admitted he lied to Congress, right?
- bigiain 13y agoEspecially when they're clearly using regular words re-interpreted into jargon to intentionally mislead the people responsible for their oversight. "Collect" apparently has an intelligence-community meaning that's quite different to the regular dictionary definition - when the NSA says they don't "collect" data, what they seem to mean is that their computer systems intercept and archive that data, but that human analysts haven't (yet) looked at it. In what other profession would you get away with making up a new definition of a word that's almost 100% opposite to the "regualar" meaning of that word, then using the word with your meaning when talking to the government? "Oh no, I didn't 'steal' that money - in the investment-banking-community, 'steal' means spending stolen money. I haven't spent any of that money yet- it's still sitting in my bank account - so no, I didn't steal any money."
- cma 13y ago"So I responded in what I thought was the most truthful, or least untruthful, manner by saying 'no'."
- asperous 13y ago
- drivebyacct2 13y agoRight. When you find a way to magically control the bits read from one hard drive and can ensure that same sequence of bits isn't "copied" and written to a different storage medium... without a "second person".... well, you let me know. I guess with some right group policy settings, a TPM and BitLocker, you could get close maybe. Still going to be challenging to keep me from booting the machine, logging into it and catting that file... somewhere. Give me `wget` and a script and I could transmit data using only GETs.
- fragsworth 13y agoI think they mean that two people must be working together at all times whenever dealing with classified information. You can't even access your own work computer without another person present. It works. It's just extremely inefficient.
- jimbokun 13y agoPair sys admining!
- lsc 13y agohey, I've done this with new people, and in cases where mistakes have a high cost... "Hey, new kid... come jump on my screen session" Of course, setting it up as a security measure would take rather more work.
- Amadou 13y agoMost systems will not have any sort of external media - no floppy drives, no removable hard disks, no cd burners. USB ports will be filled with epoxy and any peripherals will also be physically secured to their ports. Wherever possible drivers for external media will simply be removed from the OS installation image for those systems. That will leave a handful of system that do have external media. Those will have extreme access restrictions - at a minimum account restrictions and audit logs that will be regularly correlated with a hand-written log that contains timestamps and signatures of both people. They may even put the system in a room with keycard access that requires two different keycards and associated PINs to be entered before the door opens.
- codeulike 13y agoI am reminded of something someone* said about leaks in 2006: The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive "secrecy tax") and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption. Hence in a world where leaking is easy, secretive or unjust systems are nonlinearly hit relative to open, just systems. Since unjust systems, by their nature induce opponents, and in many places barely have the upper hand, mass leaking leaves them exquisitely vulnerable to those who seek to replace them with more open forms of governance. In other words, in an increasingly digital world, its gets easier and easier for large scale leaks to happen, and although you can take measures to try and stop that, overall those measures will damage your effectiveness even more. Some leaks are 'good' and some are 'bad', but over time, in a leaky world, the overall long term effect should be positive - a move towards more openness. * its pretty obvious who, but I don't want to derail.
- ef4 13y ago"The more secretive or unjust an organization is, the more leaks induce fear and paranoia in its leadership and planning coterie. This must result in minimization of efficient internal communications mechanisms (an increase in cognitive "secrecy tax") and consequent system-wide cognitive decline resulting in decreased ability to hold onto power as the environment demands adaption." - Julian Assange, The Nonlinear Effects of Leaks on Unjust Systems of Governance
- fragsworth 13y agoSo we as taxpayers: 1. Did not know about this surveillance 2. Would not have voted for it to be put in place 3. Are (for the most part) angry that it happened 4. Must pay extra taxes so they can be sure to keep it secret next time I've never been more pissed off about my government.
- hermannj314 13y agoI'm not mad about it because I pay taxes. Minor children, tax-exempt institutions, those with no income: they all deserve to be free of unjust government surveillance. Conflating the issue with the paying of taxes in a progressive tax system may introduce the rationale that those that pay the most taxes are the most deserving to not be watched. In fact, some of nation's largest taxpayers (in the black corporations) are actively cooperating in this endeavor, so making this about taxes would seem to argue that the "taxpayer" has already spoken.
- cavilling_elite 13y ago> minor children You bring up a point (perhaps frivolously)that I haven't seen before. With many many minors owning cell phones, where does the court stand on collecting meta-data from children. The law is very clear when it comes to crimes on how minors are treated, this seems to make assumptions without guardian approval or regards to their status as minors.
- drivebyacct2 13y ago
- spodek 13y agoNorth Korea also has a three-person rule for its soldiers at the DMZ to make it harder for any one to defect. A better solution is to stop making your country one people want to escape from. Or in the NSA's case, stop violating the Constitution, lying to Congress, etc so people don't feel compelled to blow the whistle. Is it that hard to follow the Constitution?
- smokeyj 13y agoThis could be a new freedom index: How many bodies are required to stop the truth from getting out?
- thufry 13y agoThat may solve the whistle-blower problem, but it doesn't solve the spy problem. There are actual spies, paid in cash, who traffic government secrets, who need to be stopped regardless of your opinion on whistleblowers.
- drivebyacct2 13y agoDoes "having a second person" even really lend itself to prevent spy-leaks though? I'm imagining an embedded spy with access to this data wouldn't have to work too hard to circumvent such seemingly honor-based access systems.
- vidarh 13y agoThere's plenty of ways to make it physically difficult to copy out data onto portable storage without following protocol, so that it is not "honor-based": For starters, disable all USB ports other than on dedicated systems that are closely monitored. Then you can physically (with a guard at the door), verify that no data is copied out without a second person signing in with the person doing the copying, and signing out the data being copied. Add on electronic restrictions requiring acknowledgement from a second person, and regular audits of who takes out what, and it'd be a lot harder to get data out without finding someone to help you, knowingly or not. There will always be workarounds, but you can at least make people put in more efforts into doing things that increases the chance they'll be noticed.
- donrhummy 13y agoI'm surprised they weren't already using a threshold-scheme. (Similar to this: http://en.wikipedia.org/wiki/Threshold_cryptosystem http://en.wikipedia.org/wiki/Threshold_cryptosystem )
- fragmede 13y agoPolitical implications aside, I'm glad to hear about the technical methods for implementing this. I've heard of high-security facilities prohibiting cameras, of any sort, so no cellphone to take pictures of the screen, either.
- tantalor 13y agoThe rule required that anyone copying data from a secure network onto portable storage media does so with a second person who ensures he or she isn't also collecting unauthorized data. But copying sensitive material to portable media is still allowed. What security?
- anaptdemise 13y agoI seem to remember watching a documentary of the Berlin wall in which soldiers in the guard towers were not in casual communication with soldiers walking the wall/fenced area. None of them were there to keep people out, but in. Watchers monitoring watchers... Wish I could remember which documentary it was.
- mullingitover 13y agoI believe this was the kind of thing that Wikileaks has been shooting for all along--make the keeping of dirty secrets so cumbersome that it becomes infeasible to keep them. This chicken has already flown the coop: the next leak will likely come from elsewhere, and again the government will be forced to scramble and plug hole that already leaked.
- a3n 13y agoPretty soon NSA employees won't be allowed to bring small pocket knives and shampoo into the office.
- sireat 13y agoFor some reason I am reminded of Feds in Snow Crash. Unfortunately, in real life, we can not opt out of states so easily.
- a3n 13y agoCoincidentally, I'm re-reading Snow Crash, read it first in the nineties. When I first read it I felt a little like a snickering boy looking up dirty words in the dictionary, reading about failed institutions and government military and intelligence services as spun off corporations. Now if you skim off the entertaining over-the-topness from the book, you have today. Booz Hamilton anyone? That program's never going away, there's too many jobs, billions, and lobbying money at stake.
- vidarh 13y agoFull body cavity scans on every entry and exit... A micro-sd card, USB plug, and necessary bits to connect them are easily small enough to be swallowed, hidden under your tongue, stuck up your anus or hidden in any number of ways.. Clearly they need to be regularly strip-searched and x-rayed.
- deleted 13y ago[deleted]
- jrochkind1 13y ago> was one of close to a thousand systems administrator Huh, that gives some idea as to the operational scale of NSA systems. It's ironic how much we're learning about how the secretive NSA does things.... from public releases by the NSA themselves, in their attempts at PR damage control.
- kragen 13y agoThis may or may not be true.
- nostromo 13y agoThe saddest part of the story is that there are two quotes, one from a democrat and one from a republican, and both are falling all over themselves in a rush to brand a whistleblower as a traitor. The second saddest part of the story is that the person responsible for securing the biggest DWH of all time freely admits that they have no protection against rogue sysadmins, most of whom don't even work for the NSA.
- gulfie 13y agoThose are the senators that have probably said something to someone over a phone that ... that just maybe might get them into trouble if it ever leaked out.
- cavilling_elite 13y agoThe "second saddest part" makes me realize why all of the government agencies get C's or less in the NIST tests for securing systems. When the NSA can't even employ their own in-house sysadmins, there is no real hope for defense against political espionage. If Snowden was the first to leak information, who was the first to sell it? The way Snowden describes the access seems like a joke.
- hobs 13y agoGREAT POINT. If someone could leak this much information as a sysadmin and do it effectively, how could it have not been sold? The value of such information would be astronomical to other spy agencies who would be opposed to us.
- scarmig 13y agoOne has to also wonder: how many have sold it before Snowden leaked it? I have a hard time guessing the ratio of people willing to silently sell information versus loud do-gooders, but I have a strong suspicion it is greater than one. And of course one person can sell multiple times...
- Amadou 13y agoFrankly, who Snowden's employer was on paper is irrelevant. There is nothing about being a government employee that makes one more loyal or trustworthy or any other characteristic. Everybody goes through the same vetting process by the same government agency to receive a clearance. If anything, a contractor is going to have additional vetting. As an employer, the federal government is bound by constitutional restrictions that private employers are not. For example suspicion-less drug testing is not a requirement for a clearance (affirmation that you haven't used illegal drugs is a requirement, but actual testing is not). However most private employers are all gung-ho on the drug testing front and do force employees to be tested to whatever level their local state laws permit (there is significant variance by state as to what a private employer can require).
- cpeterso 13y ago> “We have to learn from these mistakes when they occur,” Representative Charlies Ruppersberger said to Alexander in the hearing. “What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?” So the lesson is not how to prevent the NSA's domestic spying, but how to prevent getting caught?
- diminoten 13y agoI dunno, from a purely tech standpoint, it's a classic problem isn't it? How do you stop your sysadmin from fleeing with all of your company's data? I think the current solution is to just trust that your sysadmin's career would be over if he/she took your data. Kind of doesn't work as well for stuff like this, though, considering the person who'd steal your data probably at this point doesn't care.
- corin_ 13y agoOK so here's the question: who thinks that everything the NSA does should be public knowledge - not just what they do, but everything they have, all their data, everything. I'm sure some people do, but would imagine most don't. Most want a public overview of what they are doing and what rights they have, but understand that specifics/data need to stay secret. For this to be the case, surely they do need to make sure security is as tight as possible. But on the flip side, if they were able to 100% prevent all leaks, it would mean that nothing like this could happen again, i.e. the kind of leaks that we want to see. So where should the line be drawn?
- rz2k 13y ago>... “When one of those persons misuses their authority it’s a huge problem.” Since people working in groups never abuse their authority, this sounds like a foolproof plan.
- joshguthrie 13y agoI guess I shouldn't have expected less than badmouthing from the cynical HN crowd! Why is it that everyone chooses to omit the most important thing about this new rule? It was designed especially to make sure the next Edward Snowden would have an accomplice when taking vac...fleeing to another country and would feel less homesick thanks to the presence of a fellow motherland-er. I for one, welcome the attention and kindness of our new NSA overlords. PS: Dear NSA agent reading this, I lost access to my old Yahoo! Mail account where I still have love letters sent by my ex-girlfriend and goth poetry I wrote when I was 18. Think you could help me? Thanks for your help! XOXO
- astangl 13y agoHow well will the "two-person" rule work, once the second person starts to treat it like a rubber-stamp process? How do you prevent that from happening without introducing big inefficiencies?
- Daniel_Newby 13y agoIt will work pretty damn well when the NSA is constantly planting fake spies and the death penalty is in play.
- corford 13y agoFrom the article: Representative Michelle Bachmann emphasized that the NSA should answer “how a traitor could do something like this to the American people,” After watching the USA Today interview with Binney, Drake, Weibe and Radack (http://www.usatoday.com/story/news/politics/2013/06/16/snowden-whistleblower-nsa-officials-roundtable/2428809/ http://www.usatoday.com/story/news/politics/2013/06/16/snowd...), Bachmann's demand and the language she used make me incandescent with rage. I cannot get over the ignorance of the woman to be able to come out with something like that in good faith.
- dragonwriter 13y ago> I simply cannot understand the ignorance of the woman to be able to say something like that in good faith. What makes you think she said it in good faith?
- corford 13y agoHeh yeah. I guess I'm desperately clutching to the (futile?) belief that US congress is primarily stuffed with politicians of the dangerously incompetent and naive kind rather than the evil lizard people kind. People like Bachmann make me wonder though.
- rdouble 13y agoThe House is stuffed with politicians who appeal to their constituency. Unfortunately, the area Bachmann is from is filled with people who are similar to her.
- corford 13y agoI can understand that but surely one should be able to expect a member of congress to possess sufficient intelligence and moral judgement to be capable of recognising the stark truth of a situation when it's been laid out so unequivocally? I mean, after watching the USA Today interview, it takes some pretty spectacular mental gymnastics to paint what Snowden has done as anything other than being in the public interest. Her constituents may be ill informed but she's a fucking member of congress for christ's sake.
- deleted 13y ago[deleted]
- j_baker 13y agoI'm simply dumbfounded by this. Why is nobody at the top taking any steps to do anything about the fact that Snowden had almost unhindered access to spy on whoever he wanted? That seems like a far more concerning security hole to me.
- btbuildem 13y agoIt's a feature not a bug, apparently.
- tkiley 13y agoIf they are operating according to the laws of the land, they have "nothing to hide" from Edward Snowden and his ilk. This move looks pretty suspicious to me... ;-)
- bobwaycott 13y agoThe most disturbing comment from the article: > * "We have to learn from these mistakes when they occur,” Representative Charlies Ruppersberger said to Alexander in the hearing. “What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?"* So now the good Representative Ruppersberger is taking part in the automatic branding of Mr. Snowden as one who has turned against his country. For whistleblowing. This is the wrong path.
- a3n 13y agoBut it's the easier path. It's hard to fix the problems they have. It's easy to throw someone under the bus, dust your hands off and declare "job well done."
- glenra 13y agoI though this question was interesting: “What system are you or the director of national intelligence administration putting into place to make sure that if another person were to turn against his or her country we would have an alarm system that would not put us in this position?” The thing is, Snowden didn't turn against his country. Snowden turned towards his country...and against the schnooks who were undermining it. There's a balance here. There is danger in making it too hard for somebody with a conscience to use it to make things better. The fact that it took this long for the truth to get out suggests to me that the controls they already have in place (along with whatever social pressures surround them) might be fine or even a little too strict.
- craftsman 13y agoI once worked at a company which had a form of the two-person rule for production changes. The company's change control team thought that by requiring a second person on the development team to 'certify' that the change was 'good', they could cut down on some vaguely imagined problems. What really happened: Bob (via IM): Hey Mary, here's a change request link, can you hit 'approve' real quick? Mary: Done I bet that some slightly more sophisticated version of this will happen with this new 'two-person' rule.
- marcamillion 13y agoDon't they realize that no matter what they try, they can't stop leaks. Just like you can't get 100% security.
- HaloZero 13y agoAm I the only one who thinks the NSA should be doing something to ensure that this doesn't happen again, as in precautions against the gathering of data by an individual? While Snowden did have proper justifications and reasons for the exposure, the fact that he was able to is still not a good thing for the NSA isn't it? Someone else who might not have America's interest could do the same thing theoretically which is bad.