back

by rdl·16y ago·view on hn ↗
I agree he's not the only one to blame.

The FSO of the SCIF where he (presumably) worked should be investigated. His CO and the rest of his chain of command should be investigated as well. The (contract investigator, most likely) who was involved in granting him his clearance, too. I'm pretty sure that all happens automatically when something like this happens -- at the very least, they need to work on making sure this doesn't happen again, but it's hard to believe they were 100% blameless in this.

The actual IT systems used by the military for secret-or-higher classified data are kind of pathetic, actually. Certain things are done well (the "air gap" model for networks, and generally the military is decent at key management, and most members granted security clearance are good about changing passwords and reporting security probes, vs. commercial environments. However, the technology itself is often windows (2k, xp, vista), and isn't exactly the best managed network in the world. To some extent being "air gapped" causes them to be lazy about other forms of security. A lot of this has to do with the exceptionally slow procurement and integration cycle of the military, but at the core, windows is just not a great solution for building an office automation system with 100% accountability for every file.

(I'm actually working on a startup that will address this market; it's a good market, but I've also been someone at personal safety risk from security violations, so it is more compelling to me than writing another fb game or ipad app.)

1 comments
I believe he did the exfiltration while in Iraq. The security environment there is quite different than what you'll find CONUS.

http://articles.latimes.com/2006/apr/10/world/fg-disks10

I'm in Baghdad.

A SCIF is a SCIF, officially (which is where JWICS would be found). Generally they rely on armed guards and 24x7 presence vs. vault doors here, but it's still within the spec.

I certainly don't disagree with you that the spec hasn't changed (24x7 armed guards, several levels of physical access control, razor wire, etc. etc.).

The de-facto reality is that it's much easier to walk in an out of a SCIF in theater with all manner of stuff (portable media, entire systems, etc.) than it is back here. And if you are where I think you are, you know that most of the SCIF space over there are just converted palaces and bungalows (or tents) with boarded up windows or tents with a jury rigged razor wire setup on top of the concrete blast barriers or the back of a Trojan Spirit Hummer parked outside of your hooch. Some places are tighter than others. But I was in plenty of places in Baghdad where I didn't even have to dig my badge out of my pocket to get on their systems.

Don't even get me started on the OPSEC surrounding access to SIPR systems. "Yes, let's bring a wireless router back from the Hajji Mart and hook it into our SIPR drop so we can bring our BALs out next to the fake pond and smoke cigars while we put together targeting packages. That's a brilliant idea!" or my personal favorite, the terrabyte shared drive full of porn that made it's way around the FOBs so everybody could make a copy onto their WSSs. Yes, that's a great use of the RAID'd SCSI disk array in that big green box.

I'd bet far worse exfiltration has happened just with the DCGS-A techs replacing broken equipment and moving hard drives in and out of the SCIFs under the watchful eye of the 20 year old contract security guys too busy playing pocket tanks to bother with the paperwork.

The "guards" are your buddies you eat with in the DFAC. If you have the proper ID you could bring a Caddillac full of blow up hooker dolls in and out of the spaces without anybody batting an eye.

It's just "different" there because of the nature of the environment. CONUS, if it takes six weeks for somebody to fill out the forms so I can get a disk burned with a single email off of my JWICS account (that contains no classified information at all)...that's fine. In theater, you just bring in the disk and burn it off, or just stick it on a thumb drive, if the 6 is awake you might toss a notice their way that you are bringing something out -- but they'll most likely be doing something else. Most of the time you don't bother. Every once in a while you bring out a whole big pile of stuff and toss it in a vehicle and bring it out by the lakes or the river and burn it all while drinking near beer.

I'll admit, in places where we're really well established, like Germany or Korea, the situation is just like in CONUS. But it really is just different there. Every so often somebody will come down on a unit hard for lax security, but once they've left the FOB, the unit reverts back to watching movies off the shared drive and playing pocket tanks pretty quickly. There's just other, external pressures that people have to think about more there that people in established duty stations don't have to worry about, like a mortar coming into your hooch.

Yeah, I've definitely seem some seriously lax sites, but it's vastly better than in 2004. The great anti-usb-flash jihad of 2008-2009 seems to have helped a lot, at least on nipr and sipr.

The mitigating factor is that someone in a deployed environment is probably more aware of the potential harm from letting slip (even unintentionally) sensitive or classified information. i.e. mortar in the hooch.

It was pretty rampant in 06 and 07 :(

> The mitigating factor is that someone in a deployed environment is probably more aware of the potential harm from letting slip (even unintentionally) sensitive or classified information. i.e. mortar in the hooch.

That does seem to be the thinking/hope. But I guess as this example shows, it's not foolproof. Also, it's hard to keep people motivated about security protocols when their on their on their nth, multiple deployment.

I think that this problem applies to this case because it's obvious that the other people at the site were not watching the house very well either.

(btw, keep your head down and good luck, I was there in 2006-2007 and learned more during my deployment there than in the entire rest of my career).

It's definitely a great learning environment -- I've been doing this about 50% from 2004 to now (I'm pretty sure this is my last trip, unless I get deployed contracts for my product, which is always possible). It's almost tempting to write a book, although for it to be interesting, it would either have to be fiction set in this environment with lots of factual details (e.g. Tom Clancy), or at least fairly fast and loose with the facts. A lot of interesting stuff wouldn't be appropriate to publish, and a lot of the hyper-accurate stuff would be boring.
Wait a minutes....rdl......just checked your profile....now I know who you are! I haven't seen much about you since '05ish, since Wired did the profile on you. I actually asked around for your outfit for a while when I was over there to see about getting sat service around BIAP in '06-'07 for a couple buildings I was in. Crazy, this Internet -- small world and all that.

> A lot of interesting stuff wouldn't be appropriate to publish, and a lot of the hyper-accurate stuff would be boring.

What's the old saying? "War is long periods of interminable boredom followed by intense moments of stark terror."

There is something really bizarre about being there that's really hard for people to understand via description or pictures or stories or articles -- taking rocket fire while standing outside a Taco Bell so you can pay $3 for a taco, not even flinching because you know it's just one of 30 or 40 attacks that day and the QRF will be in the air to handle the situation anyways, and you've waited like 3 hours in line for this taco. Then you go back and watch CNN or something and hear about the attack you were just in -- and think it's getting boring, why don't they report something else? At least that's how it was back then. It's always stuck with me you could buy a brand new 46" LCD TV and a Wii to put at the foot of your bunk and a case of frozen steaks and sunflower seeds, in an active war zone. I remember thinking, "the news is describing where I am, but I can't seem to really relate it to what I'm seeing".

I've heard it's calmed down tremendously in the last couple of years. Nowhere near "safe", but not like at the end of '06 and the beginning of '07 by any stretch.

> I'm pretty sure this is my last trip, unless I get deployed contracts for my product, which is always possible

Good luck with it. Our role there is changing very fast, wouldn't be surprised to see very few contractors/civilians over there in the next 12-18 months.