Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Surely we can agree that the director of the CIA is going to be better a maintaining privacy than the average person.


I don't think the example of CIA director John Deutch, who I tracked because of his prior role in the midnight execution of the MIT Applied Biology Department (I had a roommate in it at the time), give us any assurances of that. The bare bones from Wikipedia only hints at the severity of his crimes (read later, pardoned by Clinton in the latter's last day in office; http://en.wikipedia.org/wiki/John_M._Deutch#CIA_career):

"Deutch left the CIA on December 15, 1996 and later that year it was revealed that several of his laptop computers contained classified materials designated as unclassified."

Specifically, he took sensitive compartmented information (SCI, http://en.wikipedia.org/wiki/Sensitive_Compartmented_Informa...), stuff which was covered by special access programs (http://en.wikipedia.org/wiki/Special_access_program) that required you to acknowledge each time you accessed it that it was so, and that you not leave the secured area with it, and put it on his personal PCs connected to the Internet, which he used to write up stuff which he emailed, again over that unsecured Internet, to people in the Clinton White House.

It's hard to express just how bad this is, not to mention how this angered the community of people with "tickets" (clearances, which, BTW, I've supplied recommendations for two of my friends, one who went to the NSA, the other with a TS/SCI ... which I know nothing about, except we can and do discuss which technology he's using (e.g. Microsoft)).

I would hope "the average person", after getting the usual training, and signing off on access to SCI, would understand and follow the simple idea that "Don't take it out of this room" means exactly that.

"The average person" would, I think, know he wouldn't be protected from prosecution by political pull if he violated that simple, white line rule....


Why should I agree to that? The director of the CIA is a political appointee not an uber spy. They probably have more security training than your average citizen but not much more.


I think it just says more about the types of people running the CIA. Not the smartest... not very moral... etc


His method of hiding his activity was saving drafts in gmail... roughly on par with what I'd expect most people to do to maintain "privacy".


Errr, I've read that's a standard tactic nowadays. You write and save drafts, and the other person logs into the account and reads them. No email servers are touched, it's supposed to be a good method ... unless of course an IP address is compromised. As mentioned, once they started looking, they correlated the IP addresses and times with her hotel stays.


Yes, I read that somewhere as well. It is still a bad tactic.

At first you would want to encrypt the information. Then you would like to have some method of transfer that does not stick out and could hide the intent to transfer encrypted data. Perhaps with the help of some steganography tool. And you would make sure that nobody identifies you in the process by using tools like Tor. This "I hope they don't notice" method is just gambling.


Agreed, the "saving as draft" method is more hiding in plain site than anything. It doesn't protect the content of the data, and if you're not paying attention it's easy for someone to see who's been accessing the data. It's more a defense against people that aren't really looking that hard.


Well, it might be a good method of keeping the readers identities Anonymous(provided they use Tor or a VPN to connect). But "saving a draft" is definitely keeping a copy on Google's servers, an interested party would have no trouble getting their hands on the content.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: