Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What good is a set of "rules" (not even laws) if they are deliberated and enforced behind closed doors? Why should the FBI even bother following these "rules" if nobody is transparently ensuring that they do?

Also, I did not realize just how intricately NSA data is shared with the FBI (and who knows how many other agencies). From the article, it sounds like any FBI analyst can run an arbitrary query on the "to" and "from" fields of email addresses, at any time, as many times as desired. So effectively the FBI has one giant inbox with Americans' communications in it?

That inbox will get hacked. It's only a matter of time. If thousands of federal bureaucrats have access to it, I would be very surprised if foreign intelligence agencies do not already have access to it in some capacity.

Scary stuff. People should continue to assume all systems are compromised and email is public information.



> That inbox will get hacked. It's only a matter of time. If thousands of federal bureaucrats have access to it, I would be very surprised if foreign intelligence agencies do not already have access to it in some capacity.

That is honestly my problem with NSA/FBI/etc.

They have the biggest pot of gold at the end of the rainbow and the attack vectors are limitless. Political [The Hitler scenario], technical [foreign intelligence, terrorists, basement hackers, etc.], handling of garbage [someone didn't dispose of it correctly], internal [someone wants to go a target on their own, sell it to the Chinese, etc], etc. etc.

The fact Snowden was able to do what he did is proof they aren't competent enough to be trusted with that pot of gold.


"The fact Snowden was able to do what he did is proof they aren't competent enough to be trusted with that pot of gold."

This is the most compelling reason of all.


That inbox will get hacked.

It probably has been hacked already. NSA respects FBI OpSec so little that this interface is already used to funnel disinformation to counterintelligence adversaries. That the lives of random citizens are randomly fucked up is a mere side benefit.


> NSA respects FBI OpSec so little that this interface is already used to funnel disinformation to counterintelligence adversaries.

I have never heard this before. Do you happen to have a citation for this? I would like to read more about it.


This counterintel program wouldn't work very well if there were a published citation of it. b^)


So how do you know about it?


NSA respects FBI OpSec so little

If there ever was an example of the pot calling the kettle black, this is it.

Recall that NSA allowed a Dell employee to have free reign of countless of their internal systems, and to make copies of literally hundreds of thousands of internal documents. Not just NSA documents, but also Australian Intelligence and British Intelligence documents. And probably a lot more.


Thousands of people is a gaping security hole in and of itself... Even the most technically illiterate state actor can pay off a dozen disgruntled federal employees to run queries.

It makes me wonder why the media doesn't focus on the human attack vectors. Buffer overflows and zero-day sploits are hard to understand... but anyone can understand bribes.


Because it sounds cooler because it's hard to understand.


"What good is a set of "rules" (not even laws) if they are deliberated and enforced behind closed doors?"

Nobody in government service gets punished for following rules; many are in place to serve as a CYA measure. Oh, you did something that is horrible or unconstitutional in hindsight but that was how you were instructed to do it and you were following the rules? Well, here's a hand-slap for you, shame.

Contrast and compare with how our government treats whistle-blowers, for the full depressing experience.


> Oh, you did something that is horrible or unconstitutional in hindsight but that was how you were instructed to do it and you were following the rules? Well, here's a hand-slap for you, shame.

So, Nuremberg defense? I think we pretty much agreed in 1961 that criminal behavior following orders is still criminal behavior...


And even if it's not hacked, it will be used by the next Whitey Bulger.


The data would be located on JWICS. The chances of it being hacked is close to zero. Foreign intel agencies do not have access except by deliberate leaks or a spy inside.


I've heard that one before.

Most foreign agencies would probably take a far more direct route, one they've been using for centuries, and use one of the multiple moles they surely have placed inside of these organizations.


Having a mole is completely different from a system like JWICS being hacked.


If private American communications data finds its way into the hands of foreign intelligence organizations, does it really matter whether the database was "hacked" technically or via traditional espionage? The end result is the same.


Usually when the term hacked is used it's used technically. The end result is the same but it's important to be accurate about the method and means.


Actually, the term hacked is more often used nowadays in social engineering cases since that is how most data breaches occur. Espionage falls firmly under social engineering.


:D ha ha ha. FTFY

The chances of it being secure are zero.

The career incentives of the intelligence classes do not align with actual national security.

Sadly it seems the inverse is true.

---

Empirically: who gets fired when the data is hacked ? Guy at the top or some IT peon.

Just who today is buck stop responsible for US National Data Security.

(hint: APPLE)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: