Snowden Used Social Engineering To Get Classified Documents
cold fjord sends this news from Reuters:
"Edward Snowden used login credentials and passwords provided unwittingly by colleagues ... to access some of the classified material he leaked. ... A handful of agency employees who gave their login details to Snowden were identified, questioned and removed from their assignments. ... Snowden may have persuaded between 20 and 25 fellow workers at the NSA regional operations center in Hawaii to give him their logins and passwords by telling them they were needed for him to do his job as a computer systems administrator. ... People familiar with efforts to assess the damage to U.S. intelligence caused by Snowden's leaks have said assessments are proceeding slowly because Snowden succeeded in obscuring some electronic traces of how he accessed NSA records. ... The revelation that Snowden got access to some of the material he leaked by using colleagues' passwords surfaced as the U.S. Senate Intelligence Committee approved a bill intended in part to tighten security over U.S. intelligence data. One provision of the bill would earmark a classified sum of money ... to help fund efforts by intelligence agencies to install new software designed to spot and track attempts to access or download secret materials without proper authorization.'"
Lifting a little corner of the veil over the monstrous crimes of imperialism! Only a workers revolution will put an end to imperialist barbarism!
UNITE with the Campaign for a Free Internet because today, our future begins with tomorrow!
Anyone working in the security field who gives up their password is an idiot, and should be fired.
Not only does the NSA have your data, probably any other organization interested in it is able to obtain it from them.
upon the advice of my lawyer, i have no sig at this time
In other news, there are a lot of stupid employees at the NSA regional operations center in Hawaii.
If the NSA had trained its employees competently, they wouldn't be so naive as to give their login passwords to anyone, even an admin.
Genocide Man -- Life is funny. Death is funnier. Mass murder can be hilarious.
As someone who has been a sysadmin for years, I can say, unequivocally, I never ask people for their passwords. If I need access to your account, I can have it. If I really need to do an end to end test, I can probably do it by swapping out your password hash and then restoring it so I never need your password. If that can't be done, i will change it and then reset it so you have to change it again.
Yet... despite this... from time to time people just.... send me their passwords.
"Account X on machine Y with password Z can't login, can you check it?"
So no shock at all here.
"I opened my eyes, and everything went dark again"
I'm getting really sick of this shit over and over....
We've finally concluded that Snowden is no hero, by some a traitor, for others a dupe...and we're over it...
The media fucked up reporting this **from day 1**
We knew this in **2006** NSA has massive database of Americans' phone calls
yet there was no public outcry...
then the big one...PATRIOT ACT
full text of the Patriot Act has been reported on and available to anyone with an internet connection or library card since 2001...
I'm sick of Snowden's puppet masters having free reign of the news...we need smarter editors!
Thank you Dave Raggett
And there's some reason to believe that there isn't--then Snowden purposely used social engineering to fool colleagues into giving him their passwords. Do the ends justify the means? He's exposed the NSA's domestic spying, but now the wave's continuing onward and we're getting our normal espionage practices exposed. Are we allowed to ask if doing so does indeed put us more at the mercy of Russia, China, their actors, and Al Qaeda? At what point does this process stop? At what point does the good that was done become overshadowed by the potential harm?
Here's to hot beer, cold women, and Glaswegian kisses for all.
Not funny, but arguably well deserved.
If your job is to work with sensitive data which has extremely limited access, providing someone with your password is an epic lapse in judgement, or a downright lack of understanding of basic security protocol.
If the NSA doesn't have a training course which loudly tells you to never give your passwords to anyone, they're idiots. If you didn't listen to that training and do give your password, then you have no business safeguarding sensitive data.
Two different things, really. In their minds, the surveillance was legal and authorized (which, from their perspective is probably technically true). But completely failing to adhere to security policy means that you can't really be trusted.
I should think if you fall for social engineering at the NSA, you've completed a huge faux pas and demonstrated you might be the weakest link.
Hell, most companies routinely do phishing tests and the like, and failing that will get you onto the remedial information security policy -- and repeated lapses might lose you your job. I get fake phishing emails from our security department all the time -- and everyone I report right back to them and get told "congratulations, you did what we hoped you would".
I work in the private sector, and I take security very seriously. I'm often the one making the most noise about security, to the point that I preface many things with "look, I know I say this a lot, but ...". How someone in the NSA could be so stupid as to do this boggles the mind.
Lost at C:>. Found at C.
Who has been telling the truth since June? Snowden.
I am amazed that so many are taking this sniff-test-doubtful story at face value and debating whether the engineered sysadmins should be fired or shot.
Ain't it funny how these "sources" might layer on a bit of devious sociopathy, to try to make Snowden fit the role of criminal wrecker?
Among the principals (NSA, GHCQ, executive branch, most politicians, Snowden) it is pretty much only Snowden's testimony and participation that hasn't been full to the gills with half-truths, contradictions, lies and attempts at character assassination.
Oh and how devious:
"People familiar with efforts to assess the damage to U.S. intelligence caused by Snowden's leaks have said assessments are proceeding slowly because Snowden succeeded in obscuring some electronic traces of how he accessed NSA records."
Read: "You ought to believe that Snowden did more than totally embarrass us, but he is so devious that you'll ave to take that on faith!"
"Sources said". Blech
NO CLEMENCY FOR FEINSTEIN
The question regarding whether Edward Snowden is a hero, or not, requires more time for the world to judge.
However one thing is clear - Edward Snowden, and what he has done so far, with his expose of the dirty secrets of the so-called "democratic countries", shows that the guy does believe in the ideal of democracy.
Contrast this to those untold millions of power-craving freaks who have helped NSA/GCHQ (amongst others) putting up massive surveillance systems to spy on their own people in supposedly democratic countries, Edward Snowden shines.
When compared to the enormous spook complex , Edward Snowden stands out like a tiny, lonely beacon.
However tiny that beacon is, what Edward Snowden has accomplished, for the freedom of the world, should not be forgotten.
The submitter of TFA, Mr. Cold Fjord, has been very actively astroturfing Slashdot by launching all kinds of accusations towards Edward Snowden, from all angles.
We must be awared that, had it not because of Edward Snowden, we wouldn't have known so much of the despotic schemes perpetrated by those democratic governments .
In conclusion, even if Edward Snowden is not (yet declared) a hero, I still owe my sincerest thank to him !
Muchas Gracias, Señor Edward Snowden !