4 ms·
It was previously my job (for 3 years) to investigate security breaches and destroy devices. You are almost uncannily correct. >I doubt the components are bac
by ZenPro 12y ago
It was previously my job (for 3 years) to investigate security breaches and destroy devices. You are almost uncannily correct.
>I doubt the components are backdoored by default in stock hardware. More likely, GHCQ was worried that other nations (China, Russia, etc.) were targeting Guardian journalists in an effort to gain access to the Snowden cache. As such, GHCQ probably was simply taking extra precautions in the event that hostile intelligence agencies had installed implants into the Guardian's hardware.
This is it in a nutshell, and, legislation states they had to physically destroy the devices. It was not optional. It was the law. There is absolutely nothing more to it.
> [Edit to Add]
Believe me, I have destroyed the brand new iDevices of senior Government personnel because they plugged it into a classified network to charge it for less than a minute. The law is the law. I actually had a wall of digital devices we had drilled, degaussed etc etc. The Guardian were treated the same way we treated everybody. I had my phone confiscated cause I stupidly did the same thing at the start of my career. shrug
There really is no story here which makes the cloak and dagger theories even more funny. It is almost cargo cult-ish. Some guys at Cheltenham will be rolling in the aisles reading these comments.
> [Legislation Guidance for those asking]
You can Google and read the statutes and policies yourself.
>> Once the classified material had been confirmed, security operators were then legislatively bound to destroy or other render unusable the material in question.
The legislation which required all reasonable and necessary measures are contained within the Official Secrets Act 1989, the National Security Strategy, the Data Protection Act and the Regulation of Investigatory Powers Act 2000 with detailed policy guidance promulgated to intelligence operators via HMG Information Assurance Notes (1/2 (SPF)) and, more importantly, HMG Information Assurance Note 5 and the Joint Services Publication 440 which governs counter-compromise measures.
Ultimate responsibility for HMG security policy lies with the Prime Minister and the Cabinet Office. Departments and Agencies, via their Permanent Secretaries and Chief Executives, must manage their security risks within the parameters set out in the framework, as endorsed by the Official Committee on Security (SO).
All HMG employees (including contractors) have a collective responsibility to ensure that government assets (information, personnel and physical) are protected in a proportionate manner from terrorist attack, and other illegal or malicious activity.
The loss or compromise of such Critically Important Assets would have a severe, widespread impact on a national scale and Departments must work with the National Technical Authorities and the Cabinet Office to ensure they are afforded appropriate levels of protection.
[EDIT TO FURTHER ADD]
I have posted the links to 7 policy and legal frameworks. If you cannot find these documents or you are still asking then frankly, you are too fucking stupid to trying to analyse the law or most other things.
People on HN are not your legal secretary. You not being able to find something is not proof of it's absence.
- 6d0debc071 12y agoIf they thought it had been compromised by someone other than themselves, wouldn't destroying specific chips rather than destroying the computers entirely leak more information about the information they had though? Don't get me wrong, I'm not saying you're wrong. Just seems odd, is all ^_^;
- tptacek 12y agoYou'll get downvoted now for complaining about downvoting; you were originally downvoted for spoiling the narrative. If you want to inject pragmatism into conversations about Internet surveillance, suck up the downvotes and grey text as a sign that you're doing something right.
- Zigurd 12y agoPick your battles. Zen Pro also derped his way through an unconfirmed and subsequently removed AMA on reddit: http://www.reddit.com/r/IAmA/comments/1vpluh/iama_former_military_operational_and_counter/ http://www.reddit.com/r/IAmA/comments/1vpluh/iama_former_mil... No wonder he thinks he can bluff about British laws here.
- tptacek 12y agoFair point. Happy to see more facts introduced into any discussion on HN, regardless of whether they confirm my biases. :)
- ZenPro 12y agoThat's a weird attack... [1] I posted the link to the AMA on HackerNews. Stop acting like you "uncovered" it. It's in my submissions. I also don't think a single one of my replies on that AMA counts as a Derp - if you do, please post the replies in particular. I had a number of PM's from Redditors saying they thought it was actually very clear and interesting. Unlike your book on Programming Android which currently has 35% of it's reviews listing as terrible. http://www.amazon.com/Android-Application-Development-Programming-Google/dp/0596521472/ref=la_B001KE4L4G_1_4?s=books&ie=UTF8&qid=1400830000&sr=1-4 http://www.amazon.com/Android-Application-Development-Progra... [1] "Whatever your Android programming level is, this book is a complete waste of time and definitely doesn't worth a single penny. " [2] "I am an avid Oreilly fan. I write software in a number of different languages and environments. This has got to be the absolute worst coverage of android I've seen. It was less informative than the books covering beta releases. There are typos, not just normal sentence typos but method signatures in the examples. I feel pretty ripped off having bought this book." One of the worst rated books in O'Reilly history it seems. Congratulations. If you want to get into personal attacks Zigurd let's do it, let's get the rulers out and do some measuring. Derp derp. [2] The AMA was cancelled because I redacated the names of individuals from my documents (Managers etc) so the Reddit Team decided it was not valid since it could be forged. That's fair enough, it's their platform and I was not willing to provide any other than my assessment reports. I can provide you the email chain if it bothers you that much and you present a compelling enough reason to want to verify it. However some very diligent Redditors actually did find my full details and contacted me to continue the ama offline. EDIT TO ADD: It was all very friendly and the AMA Team kicked the concept around for a over a week before they said that the evidence was not in line with their guidelines of total transparency. One of the guys actually apologised shrug. At no point was there the insinuation of lying. [3] Unless you can counter my citations of the law with evidence that they are false then your opinion ranks a little bit below that of my daughter and she is not even 5. Last time I checked RIPA, Data Protection, HMG Security Framework were all perfectly readable right here on the internet and the Joint Service Publications were viewable under certain circumstances. I would expect better from you than this ridiculous cheap shot making me out to be some sort of liar when we have never met and you don't know me. You could have even messaged me on Reddit with your concerns. Hell, I have the same username. Would you mind furnishing us with your experience of UK Legislation and the UK intelligence community?