Slashdot Mirror


Military Bans Removable Media After WikiLeaks Disclosures

cgriffin21 writes "The Pentagon is taking matters into its own hands to prevent the occurrence of another WikiLeaks breach with removable media ban, preventing soldiers from using USB sticks, CDs or DVDs on any systems or servers. The directive prohibiting removable media followed the recent publication of more than 250,000 diplomatic cables, which were leaked to whistleblower Web site WikiLeaks at the end of last month by a military insider."

54 of 346 comments (clear)

  1. horse by florescent_beige · · Score: 5, Insightful

    barn

    --
    Equine Mammals Are Considerably Smaller
    1. Re:horse by Tynin · · Score: 2

      All the same, if they are serious about security of their data, not allowing any writable / removable media on there facility just makes sense. On top of that, they should weld the cases on all of the workstations shut, disable pretty much all IO ports except for a physically permanent connection for the keyboard, mouse, monitor, and network cable. Monitoring to see if any new writable media becomes available on the workstation would be a good next place to flag for further investigation.

    2. Re:horse by cytg.net · · Score: 5, Interesting

      Indeed.
      I had a conversation with a high ranking officer a few years back who boldy calimed that their systems was 100% secure, nothing i could do.. When i explained my attack vector would be to phone in and pretend to be from support and ask him to stick in the usb-dongle (wich he had in his mail) and plug it into the secure line .. well he (or she) pretty much had a revelation ... omg is it that simple. no it is not. and yes it is. It is that simple to someone as hardcore to the art of data theft as you are to the art of war.

    3. Re:horse by jpmorgan · · Score: 4, Funny

      Oh, I don't know about that. The US military still has a lot of horses left.

    4. Re:horse by blair1q · · Score: 4, Informative

      Except that long ago there was a directive from the Pentagon not to allow removable media to be used for secure systems.

      My guess is that they relaxed that for field units because some deployed systems have no networking attached and sneakernet is all they could use. And somehow that idea ended up meaning you could use removable media on network-attached systems, and eventually nobody even noticed when someone slipped a CD-RW into a machine with access to the entire database of classified information relating to the Iraqi and Afghani theaters of operation.

      That someone is currently in jail, because, physical means or no, it was still illegal to take the information from the secure area without authorization, and to give it to uncleared people.

    5. Re:horse by DeadDecoy · · Score: 5, Interesting

      The problem is that security tends to be more of a human problem than a technical problem. A person can easily hide a usb stick somewhere on their person, and in the event that fails, take screenshots with a camera or write notes down. The first step is not to take away the usb stick, but to give the individual in question the training and incentive not to leak information in the first place. The training might include don't open any wierd attachments, browse to unauthorized sites, or use io devices from an unverified source. The incentives might include monitoring of sensitive material, legal repercussions, and, God-forbid, not implementing stupid policies that are morally questionable. Assenge noted in an interview that the purpose of Wikileaks wasn't to start a revolution but to make it easier for (morally)good companies to do business and to make it harder for (morally) bad companies to do business. The same could be said for government. Hire a trustworthy+competent staff don't be a jackass and you'll be less of a target, or at least implement fewer inane 'security' measures.

    6. Re:horse by jd · · Score: 5, Interesting

      The problem is not the decision, so much as that allowing insecure mechanisms (in violation of NSA Security Information notices, Common Criteria instructions for the levels required for secret information and Federal Information Processing Standards, I should add) was not only bloody stupid to begin with, it was in violation of US law regarding the handling of classified information.

      Instead of prosecuting Manning, who at worst is guilty of far less than the Lockheed-Martin officials who publicly sold the plans for the current stealth fighters, one should ask why his actions were even possible in the first place. FIPS standards for secure platforms and NSA publications expressly prohibit the capability to transfer files to insecure formats. It is illegal, under US law, to install or use non-compliant systems for Government purposes. This means that giving Manning the computer violated US law. Do you see anyone charged with violating such US laws? I don't.

      --
      It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
    7. Re:horse by Maxo-Texas · · Score: 5, Insightful

      And the next step is to not say "We are firmly for position X" in public while saying "We agree, we are against position X" in private.

      The bald faced lies tend to make honest humans want to rat them out periodically.

      --
      She was like chocolate when she drank... semi-sweet at first and then increasingly bitter.
    8. Re:horse by The+Mighty+Buzzard · · Score: 2

      Rank has nothing to do with security clearance is why. Privates with a signal MOS deal with classified material every single day.

      --
      Violence is like duct tape. If it doesn't solve the problem, you didn't use enough.
    9. Re:horse by The+Snowman · · Score: 5, Interesting

      A person can easily hide a usb stick somewhere on their person, and in the event that fails, take screenshots with a camera or write notes down.

      Removable media, cameras, or phones with cameras are not and have not been allowed in SCIFs for as long as I remember. Old fashioned paper and pencil is difficult to detect, as are meat memory devices.

      The first step is not to take away the usb stick, but to give the individual in question the training and incentive not to leak information in the first place.

      No, that does not work. You have to choose who you trust, which is why DSA performs investigations for all military personnel before granting clearances. Security managers interview personnel and ask questions, looking for warning signs. Someone could have a pristine history and list of contacts but still want to do harm: asking the right questions can tip off the people in charge of security. Also, as I saw on Dateline the other night with regards to corruption in the Iraqi police force, paying people a livable wage helps them not to betray you when given a carrot in the form of money, or the satisfaction of fucking with you (e.g. giving documents to Wikileaks).

      Security is a tough business. The government needs tens of thousands of people in the intelligence community across all four branches of the military and civilians in various DOD organizations: people from all walks of life, all ages, ethnic groups, geographic locations, etc. No matter how careful they are, there will be leaks. Their goal is to detect internal threats early, and to minimize damage.

      For example, when working in a classified environment, everyone is watching not only what they are doing, but keeping an eye on everyone else. Maybe someone left their SIPRNET terminal unlocked and left for the bathroom: probably just careless, but it is important to have coworkers keep an eye out for innocent errors and help correct them. Maybe someone really is trying to steal data: coworkers need to question that person why they are not following approved and document security procedures. Maybe there is a legitimate reason for putting data on removable media: couriers do exist even in the current era of high speed private networks such as SIPRNET.

      Finally, by limiting the data each person has, a breach can be localized. For example, if an image analyst steals satellite imagery, odds are that person does not have access to lists of informants, even if it is classified at the same level. That lessens the impact of a leak.

      The real failure with that kid that leaked to Wikileaks is the human factor: nobody paid attention, asking him why he was not following procedures. Someone gave him access to far more data than he needed to do his job. Forget the USB drive restrictions, the DOD needs to crack down on basic security training and protocol.

      --
      24 beers in a case, 24 hours in a day. Coincidence? I think not!
    10. Re:horse by nharmon · · Score: 4, Insightful

      He was a SP4 who was demoted to PFC because he assaulted an officer. The question isn't why a PFC had access to sensitive information. The question is why someone with demonstrated behavioral problems still had a secret clearance.

    11. Re:horse by DesScorp · · Score: 2

      The problem is that security tends to be more of a human problem than a technical problem.

      In the Pentagon's case, it's a problem of many humans. Too many people have secret clearances or better, and "need to know" isn't enforced vigorously enough in many units. The General Accounting Office says there are over 3 million people with a "secret" level clearance in the US. There's no excuse for that.

      --
      Life is hard, and the world is cruel
    12. Re:horse by mwvdlee · · Score: 3, Insightful

      I'm sure the military had a ban on leaking information too.
      Why would they think a ban on removable media works any better?

      --
      Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    13. Re:horse by Max_W · · Score: 2

      Why have secrets in the first place? Why not to train soldiers not to laugh and joke when they shoot at people from a helicopter? Maybe follow some sort of an engagement procedure?

      Why not train diplomats not to call insulting names and make cynical remarks? But use instead the whole register of great English language to express a thought.

      And USB memory sticks could be used then. Why not? A USB memory stick is a great tool nowadays for information and communication worker. It is like forbidding a carpenter to use a hammer, because someone used it to hit people on a head. Not possible to produce a chair without a hammer.

      Besides, how to forbid? OK, not USB memory stick. Sorry, but my digital photo-camera have 32 GB internal memory. 32 GB! It is 5 HD movies. Can I use a photo-camera? Mobile phone? MP3 player?

      If soldiers cannot use such devices, which are part of the modern global culture, they will become even more savage.

    14. Re:horse by Drantin · · Score: 3, Insightful

      I think you meant to respond to The Snowman... But either way, he wasn't saying you got your definitions wrong, but that you got the direction wrong... NIPR -> SIPR has always been just fine (although the media, once connected to the SIPR side, is no longer allowed to be attached to the NIPR side) but SIPR -> NIPR has never been allowed...

      --
      Actio personalis moritur cum persona. (Dead men don't sue)
    15. Re:horse by Serious+Callers+Only · · Score: 2

      Since when has honestly had any place in government?

      The question is not does it, but should it. You talk as if honesty should never be required of governments and we should just accept them being corrupt and secretive.

      If a government habitually lies, honest people will feel a motivation to leak when the gap between private reality and public pretension becomes too large. They may be naive, they may be punished after the fact, and they may find it difficult to work around your measures, but it will never be impossible, because security depends on the people who are overseeing it. All the security measures in the world aren't going to help if you can't trust your people, which is why the best policy is honesty.

      Security is also inconvenient; at a certain level of perfect security, it makes your organisation non-functional, so it will never be total because there is always pressure to relax security to increase efficiency (as happened in this case with these cables).

      This is I believe the intended effect of the wikileaks disclosures from Assange's point of view - to confront government with the choice between efficiency or security, and make them see that it is better to be as honest as possible.

    16. Re:horse by Anonymous Coward · · Score: 2, Informative

      Security is a tough business. The government needs tens of thousands of people in the intelligence community across all four branches of the military and civilians in various DOD organizations

      There's five branches of the military. Coast Guard ships larger than 110' have SIPRNET access just as Navy vessels do.

  2. Revival of the floppy disk! by LiquidCoooled · · Score: 5, Funny

    Thank god they didn't ban floppy disks.

    I knew these bad boys would come in handy one day!

    --
    liqbase :: faster than paper
    1. Re:Revival of the floppy disk! by Anonymous Coward · · Score: 2, Funny

      The problem is that they've read the evil overlord list and are padding all files to 1.45 MB in size...

  3. Nothing to see... by Frosty+Piss · · Score: 4, Informative

    This applies to SIPRNET machines, and specifically personal CDs, DVD, etc. The thing is, this has always been the rule. At least everywhere I've worked with SIPRNET access (Air Force).

    --
    If you want news from today, you have to come back tomorrow.
    1. Re:Nothing to see... by bill_mcgonigle · · Score: 5, Informative

      Back in the day when Microsoft was advertising Windows NT 3.51 was C2-certified, we looked into the docs and one of the requirements on whatever PS/2 it was that was certified was that the floppy disk drive be removed. And off the network.

      The thing here is Manning brought a RW cd inside his CD player, and only then snuck it into his PC. Then, he snuck it out in his CD player. I suppose if he was smart he burned track 1 with music so he could 'prove' it was a music CD.

      The problem here is that a random private in Iraq had access to State Department cables from (e.g.) Honduras. Need-to-know-basis isn't a new idea, this was a major FU by the governing security body.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    2. Re:Nothing to see... by fluffy99 · · Score: 5, Informative

      This applies to SIPRNET machines, and specifically personal CDs, DVD, etc. The thing is, this has always been the rule. At least everywhere I've worked with SIPRNET access (Air Force).

      Close. It applies to SIPRNET and ALL removable media. If you have a legitimate requirement to use removable media it now must be authorized by your commanding officer in writing and you must have a procedure in place that uses two-person integrity.

    3. Re:Nothing to see... by Frosty+Piss · · Score: 2

      Unless they ban all USB devices...

      All USB devices were banned on both NIPRNET and SIPRNET earlier this year. WiFi and Blue-Tooth have certainly never been used with SIPRNET.

      --
      If you want news from today, you have to come back tomorrow.
    4. Re:Nothing to see... by gatkinso · · Score: 4, Interesting

      Years ago we filled the USB ports of SIPRnet nodes at our site with crazy glue.

      --
      I am very small, utmostly microscopic.
    5. Re:Nothing to see... by IgnoramusMaximus · · Score: 2

      No, but none of the wikileaks leakers were serious spies. It will stop your average to semi-above average joe.

      True but laws of probability work against you here. If Wikileaks ethos catches on (as it seems to amongst a lot of people) there will be always a few who combine the will and the skill set. So the only long term defense will be removal of more and more features from these systems combined with restricting access to smaller and smaller subsection of data for each user - which will of course cripple the human resources more and more ...

      Hence my joking Fallout reference.

      This in fact was always the cornerstone of Soviet intelligence apparatus. Unlike the US which focused on more and more sophisticated and convoluted technology, they focused on people as the inevitable weak link, with the assumption that technological measures are essentially useless in the face of questionable loyalties of people with clearance ...

    6. Re:Nothing to see... by spitzak · · Score: 2

      Is it possible nowadays to get a read-only CD/DVD drive? It would seem that would solve this problem pretty well.

      However I don't think I have seen a read-only drive in a long time...

    7. Re:Nothing to see... by LordSnooty · · Score: 2

      Why does the SIPRNET client allow full export of data? The problem lies here, does it not? I'm presuming here that Manning did not use some kind of screen scrape technique. As an intelligence analyst it doesn't follow that he would have low-level access to the database.

    8. Re:Nothing to see... by ogdenk · · Score: 2

      BS..... they require a simple app to generate the correct key for the hash given that an awful lot of service techs and/or support personnel have. Most have been reverse engineered and scripts written that are floating around on the net.

      A lot of these can be beaten with a simple paperclip on the read lines of the small flash chip on the board which forces them to take a shit and let you reset the password with a utility. Most have beaten the paper clip attack now but it still worked on Dell D6x0-series machines not all that long ago.

      The HDD locks can be more of a pain in the ass.

    9. Re:Nothing to see... by Anonymous Coward · · Score: 3, Informative

      SIPRnet doesn't have a client, per se, as it uses normal internet tools and programs over a secure /network/. We use IE 7/8 most of the time on Windows Vista in the Army, as we just fielded it (Vista) last year. I suppose we'll be getting 7 about 4 years after 8 is released...

      SIPRnet is US Federal Agency wide. It isn't limited to any one organization, and they each have their own policies on who gets to use it, how they use it, what systems are allowed access, and what software is allowed on those systems. You will frequently find situations where one agency (say NGIA) has setup, for example, a Google Earth server with classified imagery, but another agency (say the US Army) won't allow the Google Earth client on their machines and forces their personnel to use their own "approved" servers, clients, and data. Coordination of policy on the SIPRnet is about the same as you see elsewhere in the Federal Government... which is to say, nearly non-existant.

      Anyway, the vast majority of info on SIPRnet is on normal websites without any particular extra security beyond being on a secure network. In my time on the network, I never went looking for any diplomatic cables or large archives of anything in particular, but I suppose they might be out there, from what I've seen of various agencies setups. There /are/ sites that have further protection, but they are the exception in my experience.

      I think a lot of the problem with private Manning's case is many SIPR site admin's reliance on the network being "secure" and not further protecting their data. As far as need to know... yes, in theory that's the situation everywhere, but in most cases, it isn't practiced on SECRET classified material nearly as often as TOP SECRET.

    10. Re:Nothing to see... by Facegarden · · Score: 5, Insightful

      ...The problem here is that a random private in Iraq had access to State Department cables from (e.g.) Honduras. Need-to-know-basis isn't a new idea, this was a major FU by the governing security body.

      Apparently the reason they did that was that the 9/11 commission said it was *too much* secrecy that left us unable to prevent 9/11. They said that if more people had seen all the little signs, it would have been more likely that someone spoke up. So then the military responded by allowing more people in the military access to that information.

      The real problem is that we keep doing a bunch of secret shit in private, and then tell the public "don't worry, everything is fine, the war is going great, things are totally cool." The public knows they were getting smoke blown up their ass, and they wanted the truth. So, they found it. The military is creating a market for the truth by keeping it from us.

      In this day and age, if you deprive people of information, they're only going to want it more. The whole method of "damage control" that the US govt has been doing in the middle east is just flat out ineffective. I really wish they would just tell us the fucking truth. Then there'd be nothing interesting in these cables, and a lot fewer people would get away with fucked up behavior.
      -Taylor

      --
      Worldwide Military budgets: $2100 billion. Worldwide Space Exploration budgets: $38 billion. Really, world? Really?
    11. Re:Nothing to see... by htdrifter · · Score: 2

      That's what the Tempest standard is for. It dates from the late 70s/early 80s when they banned all removable anything.
      The guy they busted was an intelligence analyst. That might explain his access. If the information was secret or higher then it shouldn't be available to someone working alone on an office desktop. The entire incident doesn't make much sense.

      Everything I've seen from that leak has been been in the media before. No where is the classification level mentioned.

      Wall St firms have better security than this. All access to sensitive information is logged, and passed on to security. If the access isn't legitimate then you're out the door at minimum.

    12. Re:Nothing to see... by whereiswaldo · · Score: 2

      You'd also better prevent your users from plugging in devices onto the wired and wireless network.

      And disable bluetooth.

      The user could also open the case up and plug in a hard drive.

      Well, you'll never plug all the holes.

    13. Re:Nothing to see... by gatkinso · · Score: 2

      It seems as if you have never worked in an accredited environment.

      An AIS (computer) that hosts classified information cannot have wireless capability. No wireless NIC, No bluetooth. Yes they issue waivers for this all the time, which is stupid. In that case the wireless device is to be physically shorted out (which many people don't do they simply disable in the BIOS which is also stupid).

      Yes you could crack the case and get at the hard drive (which is also marked classified), good luck doing that unnoticed in a SCIF. Many times the machine itself is locked in a rack - you don't have the key. You don't have the BIOS password, and the machine is supposed to have case intrusion detection enabled. (And of course many do not).

      A big problem is the accreditation process which is artificially complex. It is not more than a cottage industry: made overly complex by so called IA (information Assurance) experts who claim only THEY can properly do this task (much like an FSO in the clearance realm). They obscure the process, make it totally non-transparent, withhold info... just to preserve their job. The paperwork is astounding.

      They have taken a fairly straight forward technical task and turned it into something ugly, unwieldy, and ineffective.

      --
      I am very small, utmostly microscopic.
  4. A sure way to prevent it. by www.sorehands.com · · Score: 4, Informative

    It is really hard to ban removable media given that you can attach a phone and it becomes a USB drive.

    Using Windows Terminal Server, or Aqua Connect on the Mac
    you can prevent anyone from using a USB device, as the data will be on a server, presumably locked away from users.

    1. Re:A sure way to prevent it. by fuzzyfuzzyfungus · · Score: 2

      Concealing USB mass storage devices is trivial. They come in virtually any shapes and sizes(at the small end, limited largely by the smallest thing that falls reasonably close to the spec for a USB connector) and not too infrequently bundled with other devices(ie. "powerpoint presenter" widget that has an RF remote that is also a flash drive to store the presentation, various novelty crap, etc.) Further, all sorts of common, innocuous devices act as USB MSC devices when plugged in.

      Using them covertly is an entirely different matter, though. Unless the OS recognizes the device, reads the device IDs, loads the appropriate driver, and mounts the volume r/w, your device is a paperweight. That is the obvious area that the military should be focusing on. In pretty much any modern OS, a system that logs all devices connected/disconnected from any bus, with timestamp and present user, if any, and refuses to mount MSC devices/unexpected volumes without authentication shouldn't be all that difficult. Even a defense contractor could probably get something going, given 3-5 years and $100 million...

  5. epoxy by CohibaVancouver · · Score: 2

    It's used to be the case that some companies would squirt epoxy into the USB ports on devices - Doesn't really work any more as many devices no longer have PS2 mouse and keyboard ports.

    1. Re:epoxy by DrSlinky · · Score: 2

      It's used to be the case that some companies would squirt epoxy into the USB ports on devices - Doesn't really work any more as many devices no longer have PS2 mouse and keyboard ports.

      Um, dude... That stuff may have been sticky, but it sure wasn't epoxy!

    2. Re:epoxy by aztracker1 · · Score: 2

      Thin client + terminal server would work (linux or windows) then disable remote clipboard via policy... won't matter if the terminal has usb ports... at least not as much.

      --
      Michael J. Ryan - tracker1.info
  6. Re:Old news and misleading title by ColdWetDog · · Score: 4, Funny

    According to TFA (which I just read) it WAS part of policy (after a bunch of worms) then it got dropped because it was hard to move data around (duh) and now it's back again with the acknowledgment that it's going to be harder to move data around. (duh).

    So I still don't get it - somebody finds something on SIPRNET. The copy it to a USB drive and give it to somebody else off the secured network, then plug it back into the 'secured' network again next week when the newest bunch of porn shows up? Sounds most secure.

    Maybe they just ought tweet everything. At least the 140 character limit should slow people down a bit.

    --
    Faster! Faster! Faster would be better!
  7. I've worked in classified areas in aerospace, and USBs have been disabled since the first USB equipped PCs showed up. In then early days I think they actually removed the USB interface chip. Now it's disabled in software.

  8. Don't worry, it's never the "small guy's" machine by Opportunist · · Score: 5, Informative

    Here's a little story from back when I was the "IT security guy" (they didn't want to shell out the wage for a CISO, I guess) of a large, very security conscious company.

    Of course, no machine had USB ports or CD drives (not that CD drives could have allowed any software to leave the machine, but hey), nothing you could plug on parallel ports or serial ones, no floppy drives, no nothing. No way to plug anything into those machines that could remotely be used to transfer any data out of them.

    But of course, some people are more important than others, and some people have privileges. Needed or not. One department head needed to be able to use USB drives. It was actually a fairly level headed person and he was quite security conscious, was aware of the risks and able to handle it, and given enough pressure on the CEO he was finally allowed to use USB drives. This was actually still a fairly acceptable move. It was necessary for him and did increase his ability to work well and efficiently, and he could handle the additional responsibility and the risk was manageable and low enough to be acceptable.

    But then the invariable laws of the office privilege and status bullshittery set in. Because it is impossible that Department Head A gets something and Dufus B doesn't. I guess it's not hard to guess what happened next. Of course, all managers on this level had to be allowed to use USB drives, need them or not. And this was NOT acceptable anymore. Some of them were too dumb to actually plug an USB drive into their machine without causing a repair incident. But they had to get it, need it or not, but it's simply impossible that one of them gets a privilege and the others don't.

    So do not fear, people. Sooner or later this rule will be softened up and erode away because some people will have to have "privileges". Without being able to handle them.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  9. Re:That's gonna be kinda hard with USB by fuzzyfuzzyfungus · · Score: 2

    The port may be universal; but the drivers aren't. Nor is automatically mounting a volume as r/w on insertion. Physical disabling is crude and only for the most absolutely paranoid of situations; but software based disabling of all but the really clever covert channel stuff should be relatively simple...

  10. Which horse? by jd · · Score: 5, Interesting

    The Pentagon had to ban USB sticks, et al, internally after the biggest single security breach caused by a virus passed around and brought onto the secure SIPRNET within the Pentagon itself. It's unclear to me if the problem was the virus relaying secret information off the secure network, or what, but apparently it was labelled the single biggest security breach by the Pentagon and they're unlikely to be overplaying security holes.

    Mind you, NASA has just released secret information into the public domain by selling hard drives known in advance to contain secret information. These are drives that FAILED in-house auditing for such stuff. And prior to that, disk drives containing blueprints for the current generation of super stealth fighters were sold by Lockheed-Martin to Iran. (And people think Wikileaks did bad stuff?!?!?!?! How the hell does a bunch of personal opinions compare with giving a terrorist-funding nation plans for the top US fighters? Internal to Iran, there's the possibility they will find a weakness. Think Death Star plans. Think the Stealth Fighter shot down in Serbia. Yes, the Serbians blew up one of America's best planes, and with a cruddy cheap missile at that. On an international level, the Russians will doubtless use the plans to improve on their own airfoils and may be able to exploit the design to improve on whatever shape-based stealth they've developed so far.)

    Add to that that NASA servers have been hacked in the past to turn them into file-sharing sites. Which means that whatever classified files were in those exposed directories have been shared as well. Quite plausibly these files were protected by DES only, not triple DES or AES, as "commercially sensitive" data is classified below secret and certainly only used basic DES up until a couple of years before that breech was discovered.

    Then, back in the 90s, there was a breech at the Pentagon due to computers containing classified information being on the public Internet and having .hosts files. (NASA used .hosts files and rsh well into the current millenium and may well still do so.)

    That's four Bloody Obvious horses, with gold bridles and gem-encrusted saddles, that have walked out and were only noticed after they kicked the door down at the stablemaster's house. There may be others.

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
    1. Re:Which horse? by MacGyver2210 · · Score: 4, Interesting

      If you outlaw USB drives, only outlaws will have USB drives.

      --
      If the only way you can accept an assertion is by faith, then you are conceding that it can't be taken on its own merits
  11. Re:Separate secure channels? by Lloyd_Bryant · · Score: 2

    Has there ever been an explanation of what all the diplomatic traffic was doing going through the pentagon? Wouldn't separate channels, and perhaps distinct cryptology, whose individual security is checked and tested by the NSA be more secure in any-case?

    In the aftermath of 9/11, lack of information sharing was cited as a critical flaw that allowed the attacks to happen. So they responded with information oversharing...

    --
    Don't tell me to get a life. I had one once. It sucked.
  12. Re:Global Horses. by Artifakt · · Score: 2

    As someone who really was once an Intelligence officer, I'd like to point out that Bradley Manning was ranked Specialist 4, which is neither an NCO or commissioned rank. Until he made at least Sergeant, his need to know on anything besides possibly technical equipment specs was probably somewhere between nothing and Sgt. Schultz's "Nuuthink! Nuuthink!".

    --
    Who is John Cabal?
  13. Other ways to get data out by hawguy · · Score: 2

    It's great that they finally figured out that letting employees write secret data to a storage device is a security risk, but are they also auditing outbound communication? Will they notice if an employee emails the data to his Gmail account? Or deposits it on some hacked server somewhere? Will they notice it if he uses steganography to hide it in other data?

    Or maybe he'll use a program that converts the data to visible data that can be recorded by a camera (sure sure, cameras are against regulations, but stealing data is against regulations too...if he's a determined data thief, cameras can be hidden in all sorts of objects and body cavities). For example, a QR code can hold 4KB of alphanumeric data. If someone writes a program that displays 15 frames/second of QR encoded data and records it with a camera, that's 200MB of data every hour.

    If he's patient, he can record it as a 2400 baud data stream and record it on his MP3 player - he can steal around 10MB/hour using this method.

    Or maybe he can record it as a bit patter on a laser printer - if he can write at 100dpi reliably, thats around 100KB per piece of paper. If that can be stretched to 500dpi he'll get around 2MB per piece of paper, and will look like a grey piece of paper to the naked eye so security won't pay any attention "Oh that, it's scrap paper I'm taking home to my kids".

    How will he get such a data theft program onto the computer? Simple -- if he can't download it off the internet (perhaps a "gif" that just needs the first 128 bytes stripped off to make it an executable), he can plug in a USB keyboard dongle that acts as a keyboard and then let it type in the program for him.

    How secure *is* our secret data? Hopefully banning USB drives is just one layer and they are taking greater steps to securing who has access to such data.

  14. Re:Don't worry, it's never the "small guy's" machi by shadowofwind · · Score: 2

    The other possibility is that the whole institution will become increasingly paralyzed and unable to accomplish anything. Unlike a company, the armed forces can't actually go bankrupt. The USB ban and similar issues are already a problem for the Air Force.

  15. Why not ban covering up military mistakes? by kawabago · · Score: 2, Insightful

    The military slaughtered innocent people and covered it up. That was the reason for the leak, to shine a light on wrong doing. To prevent a future leak the military should also own up to it's mistakes and not cover up innocent accidental deaths in future. That would do more to prevent future leaks than any amount of security.

  16. Win for Wikleaks by Swampash · · Score: 2

    This action by the US Government is a clear win for Wikileaks. It is EXACTLY what Wikileaks intends for its targets to do. Wikileaks's clear publicly-stated goal is for secretive corporate and government "conspiracies" to react to leaking by restricting internal communications. http://zunguzungu.wordpress.com/2010/11/29/julian-assange-and-the-computer-conspiracy-%E2%80%9Cto-destroy-this-invisible-government%E2%80%9D/

  17. Only 1,295 cables have been published by MyNicknameSucks · · Score: 2

    Just under 1300 cables have been published; all 250,000 have most definitely NOT been published. They're being released in dribs and drabs. Source: http://213.251.145.96/cablegate.html

  18. 1989 calling - already solved. by Anonymous Coward · · Score: 4, Informative

    I worked in a defense contractor in 1989. Even back then we were forbidden to:
    - bring a camera to work.
    - have floppy drives working on any computer
    - have printers connected to any PC - printouts had to be sent to a special room.
    - use any kind of portable media (parallel port tape drives, etc).
    Of course, all our systems were on a private network - no internet access at all. Part of my job was to introduce software and tools into the network when formally requested - lots of paperwork. That's how compilers and 3rd party libraries were brought inside.

    IBM made desktops with locked sliders to prevent access to the floppy drives. I'd be shocked if those weren't still manufactured.

    Anyway - this has been solved, just forgotten.

    BTW, have you ever wondered why at least 1 Blackberry didn't have a camera? DoD users.

  19. Other methods to get data out.... by cheekyboy · · Score: 2

    1. Your monitor is at 60 hz, so flash your text or encoded bits on the screen at 30fps, and record it with your iphone HD recorder. High quality mode, or use someother small HD camera that uses little compression.

    2. Encode your documents into an audio streamed 6bit/sample with ECC. Hit play and record using your analgoue or no compression digital recorder via the Audio Out jack. This will require some small code in VB you can type in either by memory or from paper/iphone.

    If you have a monitor or audio out jack, theres your output jacks.

    --
    Liberty freedom are no1, not dicks in suits.
  20. Hmph by Greyfox · · Score: 3, Interesting
    When I was working back at Data General doing auditing of their C standard library for B2 rating documentation, the discussion of covert channels revolved around things like having an application consume more or less CPU time in order to signal applications in the non-secure domain that might be watching. There was also a nifty one about forging the return address on ICMP packets in such a way that you could send the packets to random addresses on the network and all the bounced returns would end up at a single machine.

    But yeah, banning removable media is also good...

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?