Hacker News new | ask | show | jobs
by covermydonkey 2865 days ago
Agreed.

> U.S. intelligence officers were also able to identify digital links between the covert communications system and the U.S. government itself, according to one former official—links the Chinese agencies almost certainly found as well. These digital links would have made it relatively easy for China to deduce that the covert communications system was being used by the CIA. In fact, some of these links pointed back to parts of the CIA’s own website, according to the former official.

How was this approved? This is such an obvious no-no. Would have expected a completely standalone, ring-fenced platform with absolutely no relationship to the government's known IP addresses and domains?

3 comments

What a shock. Even the CIA can be that incompetent?!
I forget where this quote is from but "the CIA would fuck up a cup of coffee"
Or the joke:

How do we know the CIA didn't kill Kennedy?

He's dead isn't he?

Joking aside they definitely played some role, at minimum by participating in the coverup.
Why are they using an off the shelf secure communication system from the Middle East? Surely something this important is a national secret and should be developed in house with your best minds.

If it's off the shelf and others are using, then they can just buy the equipment and look for flaws (like this massive one).

As I understood it, it was a system they were using in the Middle East (developed in house) and they took it to China to use. Might be wrong though.
That's crazy.

Threat model from China in terms of infosec is very different than middle East countries (except isreal perhaps).

Not that it was a good idea in either region.

I see you too read the article!
Off the shelf may also mean you dont have to smuggle it. It is much easier to hide if there is no special equipment in someone's closet. It sounds like they were using Tor.
Approved by who? Senior spies who aren't developers?

And who do you think developed this communications system they use? Given government pay scales probably relatively junior web developers trained and used to a consumer-oriented software culture in which "oh let's just drop in this convenient re-usable library" is a no-brainer.