8 ms·
I'm still waiting for the explanation of why this was OK. "Every secretary of state has done this." or, "appropriate and very common among high elected official
by lmg643 12y ago
I'm still waiting for the explanation of why this was OK. "Every secretary of state has done this." or, "appropriate and very common among high elected officials."
When i think about the email requirements of any corporation, every real job I've had, the use of personal email for company business is against policy and would be a fireable offense.
Also interesting to consider the FOIA is more fearful to a politician, than having this private email service hacked by a foreign intelligence service. state department is essentially an adjunct to the CIA at the highest levels, so this is a real risk.
- protomyth 12y agoIt's ok if it is for personal correspondence, however it is not ok and illegal if used for any government business. All the "where was the server" is irrelevant. This is generally why Presidents hand over their personal accounts and don't use them while in office. Also, the legislative members are under no such requirement. The State Department might want to read the rules, $DIETY knows the Interior Department sure had problems with them.
- whoopdedo 12y agoCorrect. In the rush to smear mud on a potential presidential candidate, the media is overlooking why Clinton was probably using her own email address: was the State Department unable to provide her with a properly archived and secure email address? On it's face I find it hard to believe they don't have the ability to do that. But at the same time, considering the cost-cutting, outsourcing, and the political maneuverings of congress that treats the federal budget like the hapless patient in a game of Operation... I wouldn't be too surprised if they weren't.
- protomyth 12y agoMy Interior remark stems from their multiple in contempt of court problems with keeping records. If Mrs. Clinton conducted official business on that server, she committed an illegal act. There is no "I knew better" defense. She failed to account for the correspondence as official.
- A_COMPUTER 12y agoSo you figure the best explanation is it's Congress's fault that Clinton chose to use a private secret email for her entire tenure at the State department that would just happen to be immune to FOIA if nobody already knew of its existence?
- deong 12y agoIt's hard to fathom they thought it wouldn't become public knowledge. I don't think anyone is that stupid. Far more likely, they just didn't think it was a big deal.
- tedunangst 12y agoSurely if the State Dept failed to provide her with an email account, she could have piggy backed on whatever service a different Secretary used? Maybe buddy up with the Secretary of Transportation and direct her email to their server. It didn't have to be her own server.
- remarkEon 12y agoI find it highly unlikely that the department of the federal government charged with corresponding with foreign nations and representing America abroad wouldn't have a satisfactory email system. That just seems dubious at best.
- fnordfnordfnord 12y agoDoes "satisfactory" include able to be uploaded to Wikileaks by an Army Private?
- remarkEon 12y agoThose are different issues entirely. Chelsea Manning essentially walked out of the SCIF with a bunch of disks - there wasn't any email hacking involved. Otherwise it's unclear what your point is.
- dmckeon 12y agoYou may want to re-evaluate - this was widely reported last month: >The State Department is still reportedly trying to block hacker access to its unclassified e-mail system more than three months after the intruders were first detected. http://www.enterprise-security-today.com/story.xhtml?story_id=1130009IV2CQ http://www.enterprise-security-today.com/story.xhtml?story_i... Yes, "unclassified", but, really? Three months? Really??
- remarkEon 12y agoYeah that's definitely in excusable. But what makes me even more curious is the care the author took to explain that it was only the unclassified system. So what about the classified network? SIPR? CENTRIXS? Are we to assume that HRC didn't send/receive any classified email? That just seems odd. So I'm starting to think that a) she did, in fact, have a government email to handle the classified material and b) chose to have her unclassified email off the network for other reasons that remain to be disclosed. Edit: I suppose there are other options. She could have used a staffer's email to send messages on the classified networks.
- caseysoftware 12y agoI worked at the Department of Justice in 2003. We had properly archived and (reasonably) secure email systems then. I'm not sure how/why the State Department would be any different.
- comrh 12y agoAs far as I've seen it was only "OK" because it was before they changed the rules to expressly disallow this. So it was technically right, the best kind.
- klodolph 12y agoThe actual text is something like this: > Agencies that allow employees to send and receive official electronic mail messages using a system not operated by the agency must ensure that Federal records sent or received on such systems are preserved in the appropriate agency recordkeeping system. Also, I've rarely encountered a company that cared about whether C-level employees followed the company rules. A "fireable offense" for a fry cook is another day at work for the COO. If I were her, I would want to personally vet my IT department. I don't know how many Snowdens work at the state department.
- parasubvert 12y ago"When i think about the email requirements of any corporation, every real job I've had, the use of personal email for company business is against policy and would be a fireable offense." Rarely enforced. Executives in regulated industries do it all the time. Or (more commonly) when hordes of contractors use their own email systems to discuss client matters -- which is perfectly normal because they are covered by NDA. If someone is fired for using personal email, it's likely because a higher up was looking for an excuse. Of course a contract doesn't cover classified or FOIA material which is where the questions regarding Clinton's setup will go.
- 001sky 12y agoThis answer is too flip. In corporate america, you might be able to use a personal e-mail as a stop-gap measure but not as a primary communication. Not in any fortune 50 or whatevr company with compliance and security infrastructure. This is something that has changed drastically in the past 10 years. Most corporate hardware should be presumed "insecure" from the perspective of personal communication, and similarly so shoud any account that is used to co-mingle work and personal communication. In other words, it is with great risk[1] that you don't use company hardware. Unless you have duplicate systems, of course. And if you have a duplicate system that you pay for in lieu of the company, only to for the purpose of subverting company policy, you have an ethics problem. If that makes sense. In any event, the technical issues here about how this was setup are legitimately interesting. It might very well be that the NSA/secret service or whomever set up this system to very secure indeed. I think the jury is out on that, frankly, and I'm not sure I would jump to the conclusion that SOS would be so wreckless as to not have her system vetted. (Or that the secret service or NSA or whomever would be so wreckless to not do it for them). Obviously it was a very carefully considered and pre-meditated decision to set up this system. But then again people do stupid stuff all the time. [1] To your personal life and privacy, not to the corporations per-se.
- parasubvert 12y ago"In corporate america, you might be able to use a personal e-mail as a stop-gap measure but not as a primary communication. Not in any fortune 50 or whatevr company with compliance and security infrastructure. This is something that has changed drastically in the past 10 years." Yes ... towards things like Google Mail for Corporations. If you make your corporate email better than your personal email, people will use it. If not, they just won't, if they have enough political power within the organization. I speak from close exposure to white glove CxO level IT service where we do everything from ensure the biometric reader on the CEO's laptop works, to helping wire the CFO's home theatre system, getting the board chairman's vacation photos printed, and setting up all their personal devices. If these sorts of folks don't like a system, they won't use it. They chucked the Blackberry for an iPhone. One of the reasons I've seen biometrics on a laptop is that a particular leader refused to remember a password longer than 4 digits. That alone made them prefer the corporate Lenovo vs. their personal Macbook Air. "Most corporate hardware should be presumed "insecure" from the perspective of personal communication, and similarly so shoud any account that is used to co-mingle work and personal communication." Bring Your Own Device is becoming popular. Every company I've worked for in the past 8 years (2/3 in the Fortune 100) allows BYOD in some form for executives, where they mix their personal and corporate communication. And sometimes for all employees. The latest thinking in corporate security is not to lock down devices but rather to assume that ALL devices are vulnerable, with no special status for corporate assets. The solution there is to isolate in depth at the service level, with appropriate policy and device management installed for enforcing minimum standards and for emergency remote wipe. Modern apps - email, HR, reporting, order management, etc. are on the Internet, not behind the firewall... unless there's a need for NAT. Legacy can be accessed through VDI. I admit the future here is not evenly distributed yet. But this is the trend that I see. "In other words, it is with great risk[1] that you don't use company hardware. Unless you have duplicate systems, of course. And if you have a duplicate system that you pay for in lieu of the company, only to for the purpose of subverting company policy, you have an ethics problem." I would say corporate IT has a usability problem.
- deleted 12y ago[deleted]
- SCAQTony 12y agoOn prima facie Clinton's private email server, prsuambly immune from NSA spying while she was Secretary of State, is rather aristocratic & highly suspicious. As an attorney, a former Senator, and finally a Secretary of States, she and her staff had to known proper security protocols & transparency laws were not applied.
- Shivetya 12y agomuch more likely it was even more susceptible let alone enticing simply from the host name. really if you don't want someone to spy on you use a name which doesn't declare who you are party too. regardless, it was against the law and public officials should always be held to the highest standard, they are not royalty.