TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Typo leak” exposes millions of US military emails to Mali web operator

151 pointsby cafemachiavellialmost 2 years ago

10 comments

nouryqtalmost 2 years ago
<a href="https:&#x2F;&#x2F;archive.is&#x2F;0vhxP" rel="nofollow noreferrer">https:&#x2F;&#x2F;archive.is&#x2F;0vhxP</a>
nubinetworkalmost 2 years ago
&gt; Zuurbier has been collecting misdirected emails since January in an effort to persuade the US to take the issue seriously. He holds close to 117,000 misdirected messages — almost 1,000 arrived on Wednesday alone. In a letter he sent to the US in early July, Zuurbier wrote: “This risk is real and could be exploited by adversaries of the US.”<p>&gt; Control of the .ML domain will revert on Monday from Zuurbier to Mali’s government, which is closely allied with Russia. When Zuurbier’s 10-year management contract expires, Malian authorities will be able to gather the misdirected emails. The Malian government did not respond to requests for comment.<p>Oops.
globalise83almost 2 years ago
Not sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same. Still won&#x27;t prevent every instance, but they can probably prevent 80% of the most sensitive emails by doing this for 20% of people who communicate with them.
评论 #36760350 未加载
评论 #36759460 未加载
评论 #36760589 未加载
评论 #36758667 未加载
评论 #36758459 未加载
评论 #36760129 未加载
评论 #36759216 未加载
neilvalmost 2 years ago
The cause isn&#x27;t just a &quot;typo&quot;. Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`.<p>Also, not only did they set up something specifically to capture the emails that they knew weren&#x27;t intended for them (incidentally preventing the senders&#x27; own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content of some of the diverted emails that they knew were sensitive and not intended for them.<p>I can&#x27;t tell from the article whether they&#x27;ve finally disabled this diversion of the emails. Nor whether they had a plan to scrub all copies of the emails before it&#x27;s out of their control, maybe offering US diplomats&#x2F;officials a deadline to get a copy if they want it<p>Also, if they&#x27;re now acting in good faith, and interfacing with US officials, I wonder who leaked this situation to the press, and why.
评论 #36759927 未加载
评论 #36762025 未加载
TazeTSchnitzelalmost 2 years ago
If .mil is typoed to .ml (Mali), I suppose it&#x27;s also typoed to .il (Israel), but I imagine that worries the DoD less.
评论 #36758154 未加载
评论 #36758345 未加载
评论 #36758634 未加载
评论 #36757927 未加载
screamingninjaalmost 2 years ago
The title gives the impression that one typo led to the leaking of millions of emails from the US military servers, which is not the case here.<p>- Presumably each typo led to one leak. &quot;Typos leak emails&quot; would be more appropriate in that case.<p>- Are they really &quot;US military emails&quot; if they originated from elsewhere and one of the intended recipients was on the &#x27;.mil&#x27; domain? Apparently &quot;emails sent directly from the .mil domain to Malian addresses are blocked before they leave the .mil domain&quot;.
GoblinSlayeralmost 2 years ago
If those emails weren&#x27;t encrypted, they weren&#x27;t secret.
评论 #36758816 未加载
评论 #36759454 未加载
评论 #36758708 未加载
htrpalmost 2 years ago
@dang.... should probably correct the title to say Typos vs Typo<p>The current title implies that its a single keystroke misconfiguration that is causing this when instead it&#x27;s lots of people just not typing the e-mail correctly.
评论 #36758399 未加载
trustingtrustalmost 2 years ago
A temporary solution would be to block all traffic of email to ml domain on computers and vpn used by the military and respond with an error. If anyone outside military computers and emails is sending such classified information this is a bigger problem and not just a typo issue.<p>Update: missed the part that this is incoming emails problem from non military.
评论 #36757748 未加载
评论 #36757402 未加载
评论 #36758516 未加载
Am4TIfIsER0pposalmost 2 years ago
Conspiracy theory time: deliberate acts to provide Casus Belli for American invasion. Along the lines of Colin Powell&#x27;s vial of anthrax at the UN or the &quot;baby incubators&quot; statements from a Kuwaiti princess a decade earlier.<p>The article states &quot;closely allied with Russia&quot; and the current establishment desires to punish anyone who doesn&#x27;t distance themselves from Russia. The emails might be nothing sensitive to the state but they can just lie and say &quot;Mali is deliberately intercepting emails meant for the military&quot;. Well that wouldn&#x27;t even be a <i>lie</i> because someone did set up something to catch emails going to dot-ml which were meant for dot-mil.<p>A nice war helps also helps with elections at home.
评论 #36757753 未加载
评论 #36758527 未加载
评论 #36758336 未加载
评论 #36758307 未加载