[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Let her cry

The Secret Version of the Bible You’re Never Taught - Secret History

Rocker defames Charlie Kirk threatens free speech

Paramount Has a $1.5 Billion South Park Problem

European Warmongers Angry That Trump Did Not Buy Into the ‘Drone Attack in Poland’

Grassley Unveils Declassified Documents From FBI's Alleged 'Political Hit Job' On Trump

2 In 5 Young Adults Are Taking On Debt For Social Image, To Impress Peers, Study Finds

Visualizing Global Gold Production By Region

RFK Jr. About to DROP the Tylenol–Autism BOMBSHELL & Trump tweets cryptic vaccine message

Elon Musk Delivers Stunning Remarks At Historic UK March

Something BIG is happening (One Assassination Changed Everything)

The Truth About This Piece Of Sh*t

Breaking: 18,000 Epstein emails just dropped.

Memphis: FOUR CHILDREN shot inside a home (National Guard Inbound)

Elon Musk gives CHILLING WARNING after Charlie Kirk's DEATH...

ActBlue Lawyers Subpoenaed As House GOP Investigation Into Donor Fraud Intensifies

Cash Jordan: Gangs EMPTY Chicago Plaza... as Mayor's "LET THEM LOOT" Plan IMPLODES

Trump to send troops to Memphis

Who really commands China’s military? (Xi Jinping on his way out)

Ghee: Is It Better Than Butter?

What Is Butyric Acid? 6 Benefits (Dr Horse says eat butter, not margarine!)

Illegal Alien Released by Biden Admin Beheads Motel Manager In Dallas,

Israel Wants to Unite Itself by Breaking the World -

Leavitt Castigates Journalists To Their Faces Over Lack Of Iryna Zarutska Killing Coverage

Aussie Students Spend The Most Time In School, Polish Kids The Least

Tyler Robinson, 22, Named As Suspect In Charlie Kirk Assassination

How They Control the World and Their Secret Weapon

Newmont Pulls Out of Canada, Delists TSX

Eva Vlaardingerbroek's Warning: Elites Plan to Make Humans Immortal in the Cloud

The $7.9 Trillion Company You've Never Heard Of


Neocon Nuttery
See other Neocon Nuttery Articles

Title: The White House's impending email security disaster
Source: Kos
URL Source: http://www.dailykos.com/story/2007/3/28/112424/169
Published: Mar 28, 2007
Author: Vyan
Post Date: 2007-03-28 12:29:33 by ...
Keywords: None
Views: 469
Comments: 9

Yesterday my boss - who isn't the most net savvy guy in the world - got an email from Paypal claiming that there was a problem with his credit card, so he logged into his account and updated his information.

Today he discovered an unexplained withdrawal for $2,600 from his Checkcard account. This is just minutes after I'd taken a look at this suspicious email and discovered that it didn't come from Paypal at all and instead directed the user to a domain called http://dancesforlifes.com which featured a facimile of the paypal login and html code that then sent his Id, Password and credit card information to a Gmail address.

Oh shit!.

All of this I mention just to point out that email security is not a joke and that many people will go to great lengths to get at the sensitive information we'd prefer to protect. Oh, and it appears that some of the staff of the White House have switched from the secure wh.gov server to using not just the RNC, but personal email accounts!.

From Thinkprogress.

Via Muckraker, U.S. News reports that "just a week after E-mails in the U.S. attorneys case became a main focus of congressional Democrats probing the firings, several aides said that they stopped using the White House system except for purely professional correspondence."

"We just got a bit lazy," said one aide. "We knew E-mails could be subpoenaed. We saw that with the Clintons but I don't think anybody saw that we were doing anything wrong."

But rather than use RNC accounts, "they have subsequently bought their own private E-mail system through a cellular phone or Blackberry server. When asked how he communicated, one aide pulled out a new personal cellphone and said, ‘texting.’"

As was pointed out in the Recommended Diary by citizen92 earlier this week, allowing their communications to be stored on unsecured non-government servers is a major security threat simply waiting to be exploited. All someone needs to do is crack the password and they're in.

The White House is a huge target for electronic espionage by friendly and hostile foreign powers. For those of you who may have visited Washington, this may be evident when you stroll by the various embassies scattered around the city -- with their unusual sculptures of antennas and wires on their roofs. The Russians have a compound just three blocks north of the White House.

The US Government spends undisclosed amounts on countermeasures to protect its critical information and its secure networks. And it has the experts to make sure that those countermeasures are working.

But what if someone in the White House chooses to not use those counter-measures (simply to avoid leaving a subpoena-able trail of bread-crumbs) and as a results gets their password jacked?

I personally know how easy this is to accomplish. Not simply because of what happened to my boss yesterday, but because once upon a time one of best friends was a hacker. Not just any hacker - The Hacker. Kevin Mitnick and I went to High School together (he later spent several years on the run from federal authorities, I - after realizing I didn't want to go Kevin's way, went on to work for the IT department at Northrop-Grumman). Way back in the late 70's I got to see first hand how he used to create password phishing programs just like the one I described at the top of this post to access LAUSD, USC and UCLA logon accounts.

Ah, the classics never fade away it seems.

Besides the security issues, this also may blow WH claims of extended executive priviledge completely out of the water. From Josh Marshall.

"[T]his may have been too clever by half. If the president’s aides were using RNC emails or emails from other Republican political committees, they can’t have even the vaguest claim to shielding those communications behind executive privilege."

And they certainly can't use that claim to protect emails on their personal blackberry and cell phone now can they?

Oh, and by the way - other federal agencies have banned this practice for security reasons.

A reader who has a security role at a federal agency writes, "On the issue of using outside/unofficial e-mail address from official sites, the CIO at [redacted] has expressly forbade the practice for security reasons as it is all too easy to put sensitive information in an e-mail. ... Needless to say, hearing that the WH does not mandate that practice and lets [Rove] do 95% of his e-mailing from a blackberry, presumably with access to an unofficial address, is quite shocking. Still find it absolutely amazing that his clearance has not been revoked."

"Amazing" simply isn't the world for it.

Getting zapped for a couple grand is pretty bad, but just imagine how much of the nation's assets are being put a risk by these WH jackasses?

I think Fraking Criminally Negligent is a good set of words for it - how 'bout that?

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

Begin Trace Mode for Comment # 2.

#2. To: ... (#0) (Edited)

Needless to say, hearing that the WH does not mandate that practice and lets [Rove] do 95% of his e-mailing from a blackberry, presumably with access to an unofficial address, is quite shocking. Still find it absolutely amazing that his clearance has not been revoked."

There's a little bit of BS here.

Blackberries can be set up to use the enterprise's (in the case WH's) mail servers. I have little doubt that Rove's BB is tied into the WH's. Blackberries are some of the most secure wireless communications devices if properly configured. In addition, the WH has its own super-secure BB setup. While most BB communications pass through a Canadian hub before being directed to their destination, the WH has its own minihub and they completely avoid passing through Canada when doing WH BB to WH BB communications.

How do I know these little details. Well... I will not have to kill you but someone will if I tell you.

a vast rightwing conspirator  posted on  2007-03-28   13:12:38 ET  Reply   Untrace   Trace   Private Reply  


Replies to Comment # 2.

#3. To: a vast rightwing conspirator (#2)

Maybe, but emails on a private account are on some random drive in some random colo factility completely outside the control of the NSA and others in charge of the security. That is why they are saying there is a breach. It's like mailing someone a top secret document though a very secure mail system and then leaving the document laying out on a table in the mall.

...  posted on  2007-03-28 13:49:58 ET  Reply   Untrace   Trace   Private Reply  


#4. To: a vast rightwing conspirator (#2)

Besides, it deosn't matter if the Blackberry security is ten million times better than the Whitehouse security, the Blackberry channel isn't authorized for this type of communication. If it is deliberately used for secure communication, a felony security breach has been committed. The same as burying a secret document in the woods in order to keep it safe. It might actually be safe there, but the document can legally only be stored in an approved security container.

...  posted on  2007-03-28 13:52:56 ET  Reply   Untrace   Trace   Private Reply  


End Trace Mode for Comment # 2.

TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]