British spies 'moved after Snowden files read'(bbc.co.uk)
bbc.co.uk
British spies 'moved after Snowden files read'
http://www.bbc.co.uk/news/uk-33125068
54 comments
The UK govt have lied time and again. Weapons of mass destruction.
BBC are also totally unreliable when it comes to the top level stuff. They get told what to write.
BBC are also totally unreliable when it comes to the top level stuff. They get told what to write.
Hell, they've been willing non-anonymously to lie to Congress to protect these programs. https://en.wikipedia.org/wiki/James_R._Clapper#False_testimo...
Yet you seem to think that Russia and China would never try to do just this...huh?
The world isn't just this peaceful and happy place where only the USA is the big bad wolf.
The world isn't just this peaceful and happy place where only the USA is the big bad wolf.
Quite the opposite - I'm sure they are. I also have a huge amount of respect for and trust in my (UK) government and that they keep my best interests at heart.
The word "authoritatively" just seems obviously wrong.
The word "authoritatively" just seems obviously wrong.
> I also have a huge amount of respect for and trust in my (UK) government and that they keep my best interests at heart.
Austerity politics, London real estate boom, UK knife laws
Austerity politics, London real estate boom, UK knife laws
Don't know about the person you were replying to, but I suspect Russia and China would see Snowden and try to copy him (noticing that these agencies have terrible OPSEC) rather than attack him (knowing he's probably being very careful)
In other words the BBC is in the propaganda business.
The level of access Snowden accrued may be symptomatic of structural access failure.
Chelsea Manning, too, got away with a considerable amount of material.
Surely other state actors would have moles at these levels - so they probably got all this stuff as well.
Security by obscurity may be a bad rule to follow at the state level - in the future we may need to know we are safe and not trust spies or wonks with our safety.
Cryptography needs to be provably secure. Perhaps safety should be? Which raises the question can National Security be performed transparently ?
Was the hack of GMail by China attributed to a NSA backdoor ?
The real problem may be general to any government department that lacks oversight - total and utter incompetence.
No-one has publicly hacked Greenwald - the secret services have been caught with their pants down at least twice.
The BBC reports Russia and China have cracked encryption implemented by Snowden. From what I read about Snowden it seems he would have used the best publicly available crypto and so that is quite a considerable claim.
Conclusion : leaks are more likely to come from the leaky sieve.
http://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9-...
I cite Adam Curtis :
"Maybe the real state secret is that spies aren't very good at their job and don't know very much about the world"
These super secret departments get more funding and power when there is more terror not less.
The career incentives of the intelligence classes may not align particularly well with actual national security.
Chelsea Manning, too, got away with a considerable amount of material.
Surely other state actors would have moles at these levels - so they probably got all this stuff as well.
Security by obscurity may be a bad rule to follow at the state level - in the future we may need to know we are safe and not trust spies or wonks with our safety.
Cryptography needs to be provably secure. Perhaps safety should be? Which raises the question can National Security be performed transparently ?
Was the hack of GMail by China attributed to a NSA backdoor ?
The real problem may be general to any government department that lacks oversight - total and utter incompetence.
No-one has publicly hacked Greenwald - the secret services have been caught with their pants down at least twice.
The BBC reports Russia and China have cracked encryption implemented by Snowden. From what I read about Snowden it seems he would have used the best publicly available crypto and so that is quite a considerable claim.
Conclusion : leaks are more likely to come from the leaky sieve.
http://www.bbc.co.uk/blogs/adamcurtis/entries/3662a707-0af9-...
I cite Adam Curtis :
"Maybe the real state secret is that spies aren't very good at their job and don't know very much about the world"
These super secret departments get more funding and power when there is more terror not less.
The career incentives of the intelligence classes may not align particularly well with actual national security.
I can see 3 possible scenarios here.
1. Russia/China have got hold of the files, and know how to decrypt PGP (Very unlikely).
2. A journalist with access to the files and the encryption keys has left them lying around, or was cooerced into decrypting them. (Unlikely but possible).
3. Intelligence services are lying, possibly for political gain ahead of new legislation (specifically in the UK), and/or have fallen for a bluff by China and Russia. (Most likely).
1. Russia/China have got hold of the files, and know how to decrypt PGP (Very unlikely).
2. A journalist with access to the files and the encryption keys has left them lying around, or was cooerced into decrypting them. (Unlikely but possible).
3. Intelligence services are lying, possibly for political gain ahead of new legislation (specifically in the UK), and/or have fallen for a bluff by China and Russia. (Most likely).
4. A version left encrypted at any point and time on some old SSD or NAND cells that were then recovered, without journalist or other handlers aware this could happen.
5. GCHQ or NSA had same or similar documents lifted (umm... leveraging Office of Personnel Management or a similar type hack) and they are preparing a cover story.
plenty of conspiracies to go around but as someone else said... until some proof is shown there's no reason to give much weight to the statement that individuals needed to be moved.
5. GCHQ or NSA had same or similar documents lifted (umm... leveraging Office of Personnel Management or a similar type hack) and they are preparing a cover story.
plenty of conspiracies to go around but as someone else said... until some proof is shown there's no reason to give much weight to the statement that individuals needed to be moved.
http://www.washingtonpost.com/world/national-security/chines...
I'd say its #5 honestly :p
I'd say its #5 honestly :p
Is it that unlikely that a journalist left the encryption keys on an internet-facing machine? The protection on an essentially unguarded computer (let's face it, if someone wants to break into any of our home machines, they can) would then be the weakest link.
poitras and the intercept are both very well versed in opsec and the necessity for airgapping, and the latter hired Morgan Marquis-Boire to handle security for first look media. i don't think it's as likely as you believe
The NSA is also well versed in OPSEC, but a guy took a ton of their documents and is currently residing in Russia. There are always holes in the system.
2. A journalist with access to the files and the encryption keys
It doesn't have to be a "journalist". E.g. I'd consider Bruce Schneier to be more of a cryptographer or researcher.
My scenario:
https://www.schneier.com/blog/archives/2013/09/how_to_remain...
It doesn't have to be a "journalist". E.g. I'd consider Bruce Schneier to be more of a cryptographer or researcher.
My scenario:
1) He's had extensive access to the Snowden material
2) He uses Windows
3) Q.E.D.
Yes he's taken precautions, but he's certainly a "high value target".https://www.schneier.com/blog/archives/2013/09/how_to_remain...
More likely is that the Snowden documents have been widely distributed in encrypted form (as one of the Wikileaks insurance releases) and Russia/China have managed to brute force the key.
That broadly speaking comes under point 1, and in my opinion, that's very unlikely, given that at the point Snowden stopped contracting for the NSA, PGP was still considered uncrackable by them.
This is least likely.
Snowden's passphrase[0] advice is pretty bad - perhaps they came up with a list of phrases based on what they know of him and successfully cracked it.
> “The best advice here is to shift your thinking from passWORDs to passPHRASES,” Snowden recommended. “Think about a common phrase that works for you. It’s too long to brute force and also make them unlikely to be in the dictionary.”
(emphasis mine)
0. http://rt.com/usa/248401-snowden-oliver-password-protection-...
> “The best advice here is to shift your thinking from passWORDs to passPHRASES,” Snowden recommended. “Think about a common phrase that works for you. It’s too long to brute force and also make them unlikely to be in the dictionary.”
(emphasis mine)
0. http://rt.com/usa/248401-snowden-oliver-password-protection-...
I expect Snowden actually advocates people use something like diceware passphrases and the journalist misunderstood.
https://en.wikipedia.org/wiki/Diceware
https://en.wikipedia.org/wiki/Diceware
That sure isn't what he said to John Oliver.
https://www.youtube.com/watch?v=yzGzB-yYKcc#t=1m30s
He mentioned "margrattethatcheris110%SEXY" - I would be totally unsuprised if someone managed to crack that.
Diceware is a great choice.
https://www.youtube.com/watch?v=yzGzB-yYKcc#t=1m30s
He mentioned "margrattethatcheris110%SEXY" - I would be totally unsuprised if someone managed to crack that.
Diceware is a great choice.
Perhaps you can come up with a reason why this is bad?
While I'm asking, perhaps you can come up with a reason that doesn't boil down to "Bruce Schneirer said XKCD method was bad"?
While I'm asking, perhaps you can come up with a reason that doesn't boil down to "Bruce Schneirer said XKCD method was bad"?
It's more that most humans are predictable most of the time. There's no reason a password cracking dictionary can't contain phrases as well, and most of the sorts of rules based permutations used against normal passwords can be extended to passphrases. Attacking a specific individual also tends to be easier - you can profile them and build targeted word and phrase lists.
XKCD is bad specifically because it is specifically talking about attacking a password via an internet based oracle rather than attacking a hash, but people generalized it. A search space of ten or twenty trillion is laughable when a few GPUs can make a billions of guesses per second against a vanilla hash algorithm.
Ultimately, if you want a password or passphrase that a computer can't guess, you should let a computer pick it for you, or if you're really paranoid, use diceware.
XKCD is bad specifically because it is specifically talking about attacking a password via an internet based oracle rather than attacking a hash, but people generalized it. A search space of ten or twenty trillion is laughable when a few GPUs can make a billions of guesses per second against a vanilla hash algorithm.
Ultimately, if you want a password or passphrase that a computer can't guess, you should let a computer pick it for you, or if you're really paranoid, use diceware.
Most likely? Any evidence to back up that claim?
I know he communicated with the journalists via PGP but do we know that all copies of the files were encrypted that way?
I'm wondering whether there's any way for journalists to verify this, and if not, why we should trust statements by the U.S. or U.K. governments on this topic, given their repeated falsehoods in the past.
Sure... the Russians and Chinese (not the same people) just happened to simultaneously break some strong encryption, and the UK just happened to discover this somehow, before anything significant happened. Perfectly propaganda.
Perhaps the next press release will claim, 'paying taxes reduces the risk of death by 42%!'
Perhaps the next press release will claim, 'paying taxes reduces the risk of death by 42%!'
Hmm. The UK has a Freedom of Information request process, much like the US (ie just as neutered). The request would be, essentially: "prove it". The hard part would be putting it in a form likely/able to be answered.
It won't be answered.
Section 23 of the Freedom of Information Act 2000:[0]
"Information held by a public authority is exempt information if it was directly or indirectly supplied to the public authority by, or relates to [...] the Government Communications Headquarters"
[0]: http://www.legislation.gov.uk/ukpga/2000/36/section/23
Section 23 of the Freedom of Information Act 2000:[0]
"Information held by a public authority is exempt information if it was directly or indirectly supplied to the public authority by, or relates to [...] the Government Communications Headquarters"
[0]: http://www.legislation.gov.uk/ukpga/2000/36/section/23
Ironically I thought the title meant "moved" as in "moved to tears".
Anyway, you know how when one person shits in the pool everyone has to get out? GCHQ, NSA, you're that person and this is your moment.
Anyway, you know how when one person shits in the pool everyone has to get out? GCHQ, NSA, you're that person and this is your moment.
Are relations between Russia and China so cozy that they'd share intelligence of this magnitude?
Alternatively, is it believable that they both miraculously broke the encryption at exactly the time?
Alternatively, is it believable that they both miraculously broke the encryption at exactly the time?
I assume this is to coverup the government's other mistakes. (http://www.theatlantic.com/national/archive/2015/06/the-hack...)
These are anonymous government sources. Can we really expect them to tell the truth? It seems more likely that these officials are exploiting the general public's lack of knowledge on this issue to turn them against Snowden and the journalists.
It's getting really silly with these government sources speaking under the condition of anonymity. You would think journalists would have read, under the assumption that they lack the minimal intellect to see through the charade, some of the Snowden documents that clearly speak of using anonymous sources for more or less sophisticated psyop.
It is disconcerting how blatantly parroting the official government line without question has become SOP at "respectable" western media organizations. They are increasingly becoming propaganda outlets for the state. See also any article about Russia, NATO and the Ukraine.
These 'sources' also forgot to mention that he took 900,000 documents not 1.7 million per the official DIA analysis http://cryptome.org/2015/06/dia-snowden-vice-15-0604.pdf
If the US & UK governments really didn't want these documents ending up in Russian hands, maybe they shouldn't have, ummm, chased him to... y'know... Russia.
Is it common practice for a newspaper to essentially reprint an article from another publication, without seeking a response from the (accused) parties?
I would expect at the very least for the BBC to seek a response from Snowden/Greenwald/theGuardian/etc before publishing this article with subheadings like: >'Hostile Countries' >'Huge Setback'
I would expect at the very least for the BBC to seek a response from Snowden/Greenwald/theGuardian/etc before publishing this article with subheadings like: >'Hostile Countries' >'Huge Setback'
In the UK there is little pretense that any journalistic publication is truly objective, so the tradition is for opposing parties to use different channels in the media.
[deleted]
Dealing with the Snowden leaks has been priority #1 for these intelligence agencies. If they are desperate enough to use this kind of blatant propaganda, it frightens me to think about what their next move will be. Look for some very draconian laws to be rammed through as they try to keep the powers they've been enjoying without any challenges or oversights. And if that doesn't work: war.
It sounds to me like the implication here is --Snowden disrupted our intelligence agencies by preventing us from crucial information, therefore he harmed our government--. The assumption being that America and it's allies are entitled to all the information we are stealing through spying. When a non-American ally spies on America it's a crime, but when America spies, stopping it is a crime?
It's worth considering the idea that technological spying by procuring vulnerabilities without reporting perpetuates a technological arms race and concentrates power in the executive with no balance among other branches.
It's worth considering the idea that technological spying by procuring vulnerabilities without reporting perpetuates a technological arms race and concentrates power in the executive with no balance among other branches.
I'm sorry but what in this article suggests that US/UK intelligence agencies spying is hypocritical in any way? Sovereign states have spied on each other for hundreds of years, long before the age of computers. When they're captured they are imprisoned or executed. There isn't anything hypocritical at all about conducting counter-intelligence while also trying to spy on others.
That is not what sources in the article are claiming.
>"Well, we are told authoritatively by people in Downing Street, in the Home Office, in the intelligence services that the Russians and the Chinese have all this information and as a result of that our spies are having to pull people out of the field because their lives are in danger."
There is a line about also damaging ability to collect information, but this is a separate claim; allegedly, information in one or more of the million+ files could jeopardize lives of human intelligence people stationed in foreign countries.
>"Well, we are told authoritatively by people in Downing Street, in the Home Office, in the intelligence services that the Russians and the Chinese have all this information and as a result of that our spies are having to pull people out of the field because their lives are in danger."
There is a line about also damaging ability to collect information, but this is a separate claim; allegedly, information in one or more of the million+ files could jeopardize lives of human intelligence people stationed in foreign countries.
.."the Russians and the Chinese have all this information and as a result of that our spies are having to pull people out of the field because their lives are in danger."
If the Russians and Chinese didn't previously know their identities (allegedly via Snowden) by subsequently extracting thespies we are confirming who they were and thus the ability to identify their former networks.
Dammned if you, damned if you don't.
Who's ballsy enough to message /u/SuddenlySnowden (https://www.reddit.com/user/SuddenlySnowden).
Link to the original article that BBC gleaned from:
https://archive.is/BkuMM
https://archive.is/BkuMM
This is why he should have stuck to the domestic stuff...but nooooo
You are assuming Snowden is responsible...because the government says so? That massive security breach, of course, couldn't possibly have anything to do with this, and it absolutely isn't a case of using Snowden as the scapegoat for government incompetence. Our governments are completely trustworthy and would never lie to "their" citizens.
Annnnd Treason.
Were the snowden files encrypted? If so, maybe an attack vector was the journalists.
Or maybe we're confusing the wiki leaks insurance file with the snowden files?
Or maybe we're confusing the wiki leaks insurance file with the snowden files?
It was always a crock of shit to equate Snowden to the Pentagon Papers or the Watergate scandal, and this is why.
Snowden having that level of access and the ability to siphon off so many documents undetected virtually guarantees that Russian/Chinese moles have been doing the same (without going to the press about it, naturally) for quite some time. The idea that they don't already have the data is a crock of shit.
It seems disingenuous to use the word "authoritatively" when talking about people with a huge stake in the game, who will at no point be willing to (or needing to) verify their claim.