NSA Suggested Clinton Use A $4,750 Windows CE PDA (arstechnica.com)
An anonymous reader writes from an article on Ars Technica: When former Secretary of State Hillary Clinton was pushing to get a waiver allowing her to use a BlackBerry like President Barack Obama back in 2009, the National Security Agency had a very short list of devices approved for classified communications. The General Dynamics' Sectera Edge and L3 Communications' Guardian were the two devices built for the Secure Mobile Environment Portable Electronic Device (SME PED) program. They were the only devices anyone in government without an explicit security waver (like the one the president got, along with his souped-up BlackBerry 8830) could use until as recently as last year to get mobile access to top secret encrypted calls and secure e-mail. At the time Clinton was asking for a phone, only the Sectera Edge was available (the Guardian was running behind in development) and it required multiple server-side and phone-side e-mail additions, desktop synchronization software, and other supporting products. The "Executive Kit" version of the Edge, priced for government purchase at $4,750, included: Type 1 Sectera Edge (GSM or CDMA) device plus: Executive Carry Case, Leather Holster Travel Charger, Red/Black USB Cables, Vehicle Charger, Earbud, Stylus 10-pack, microSD Card with User Manual, Spare Battery, Privacy Shield 4-pack, Antivirus Software, Apriva Email Client and Perpetual Rights fee and Office Suite for Windows CE.
It's totally safe; we totally can't hack it. Don't get one of those cheap devices, or an iPhone, because we'd be screwed.
"No.. I know better than the NSA. I'll use what *i* want and there's nothing you can do about it!"
And so far... shes right about that last part..
So, the NSA basically told Clinton; Fuck you.
Nice. Personally I hate her, but the NSA should have more respect for the Secretary of State FFS.
Clinton didn't want to read her email on a computer in her SCIF...she wanted her BlackBerry. It was good enough for everyone else in the government, but it wasn't good enough for her.
I'm having trouble locating the exact requirements the device had to fulfill to satisfy the SME PED program; but depending on what levels of physical tamper resistance and software quality assurance were involved, $4,750/unit for a fairly low volume device might actually be a pretty decent price.
Mainstream winCE devices were pretty much extinct, or in the later stages of twitching and gasping, by 2009; but as a point of comparison you could find yourself spending ~$500 for a high-end Pocket PC device back in the 2005ish period, sometimes without any sort of cellular connectivity and obviously without the SCIF mode and keyfill ports and stuff. Prices for equivalent hardware had certainly fallen in the mass market by 2009; but I'm guessing that this thing's development time left it with hardware much more akin to that of older models than to that of whatever cellphones were hot off the presses in 2009.
If the requirements were more about knowing how to land contracts and tick feature checkboxes, then the price is on the high side. If the "trusted" label on various parts of the device, and whatever modifications to stock WinCE were necessary to get safe coexistence of the high and low security sides of the device, imply a substantial amount of very exacting software development; then I'm actually more surprised that they cost that little.
Anyone know how these are supposed to stack up in EAL/CC/FIPS140-2 terms or any other measures that would be more helpful in drawing comparisons than membership in a group that only one other device was ever part of?