TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How the US defense secretary circumvents official DoD communications equipment

472 点作者 Harvesterify22 天前

28 条评论

beloch21 天前
The other members of the five eyes had better be careful about what they share with the U.S. while this is going on.<p>Public key encryption, like Signal uses, offers good security for most purposes. e.g. It&#x27;s fantastic for credit card transactions. The problem with using it for transmitting state secrets is that you can&#x27;t rely on it for long-term secrecy. Even if you avoid MITM or other attacks, a message sent via Signal today could be archived in ciphertext and attacked ten years from now with the hardware&#x2F;algorithms of ten years in the future. Maybe Signal&#x27;s encryption will remain strong in ten years. Maybe it will be trivial to crack. If the secrets contained in that message are still sensitive ten years from now, you have a problem.<p>Anything sent with Signal needs to be treated as <i>published</i> with an unknown delay. If you&#x27;re sharing intelligence with the U.S., you probably shouldn&#x27;t find that acceptable.
评论 #43857149 未加载
评论 #43855339 未加载
评论 #43854404 未加载
评论 #43856523 未加载
评论 #43854487 未加载
评论 #43856926 未加载
评论 #43854878 未加载
评论 #43859481 未加载
评论 #43858086 未加载
评论 #43856503 未加载
评论 #43854400 未加载
评论 #43856340 未加载
评论 #43856925 未加载
评论 #43854916 未加载
评论 #43854415 未加载
TaurenHunter21 天前
The sheer hypocrisy<p><a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;us-news&#x2F;2016&#x2F;sep&#x2F;02&#x2F;hillary-clinton-emails-laptop-thumb-drive-archive-missing" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;us-news&#x2F;2016&#x2F;sep&#x2F;02&#x2F;hillary-clin...</a><p><a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;us-news&#x2F;2016&#x2F;jul&#x2F;05&#x2F;fbi-no-charges-hillary-clinton-email-investigation" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;us-news&#x2F;2016&#x2F;jul&#x2F;05&#x2F;fbi-no-charg...</a><p>Also:<p><a href="https:&#x2F;&#x2F;www.fbi.gov&#x2F;news&#x2F;press-releases&#x2F;statement-by-fbi-director-james-b-comey-on-the-investigation-of-secretary-hillary-clinton2019s-use-of-a-personal-e-mail-system" rel="nofollow">https:&#x2F;&#x2F;www.fbi.gov&#x2F;news&#x2F;press-releases&#x2F;statement-by-fbi-dir...</a><p>&quot;To be clear, this is not to suggest that in similar circumstances, a person who engaged in this activity would face no consequences. To the contrary, those individuals are often subject to security or administrative sanctions. But that is not what we are deciding now.&quot;
评论 #43861349 未加载
评论 #43865046 未加载
评论 #43875176 未加载
评论 #43865200 未加载
评论 #43858305 未加载
Ajedi3221 天前
Valid concerns about op-sec and personal responsibility aside, I think this is another example of why &quot;security at the expense of usability comes at the expense of security&quot;. Official DoD communications equipment sucks, so people use the less secure, more usable encrypted communications platform when they feel they can get away with it.<p>Maybe the DoD should work on developing some internal Android and Signal forks that focus on adding additional critical security controls without impacting usability. There&#x27;s an obvious desire path here.
评论 #43858423 未加载
评论 #43860037 未加载
评论 #43876397 未加载
评论 #43859025 未加载
standardUser21 天前
If you&#x27;re going to put a guy in charge who is completely unqualified and has a history of alcohol abuse you should at least make sure he&#x27;s competent. It&#x27;s actually very grating to see someone operating at this highest level of authority and treating it like its beneath them. It feels like we&#x27;re watching history get written by the most entitled and inept among us.
评论 #43854258 未加载
评论 #43854016 未加载
评论 #43854682 未加载
评论 #43854069 未加载
评论 #43870898 未加载
评论 #43862498 未加载
评论 #43861059 未加载
评论 #43854402 未加载
评论 #43856191 未加载
评论 #43854747 未加载
评论 #43856302 未加载
评论 #43854488 未加载
mmooss21 天前
Let&#x27;s pretend you work for a non-US state intelligence agency. How would you find Hesgeth&#x27;s personal computer in his office on the public Internet? A genuine thought experiment.
评论 #43853920 未加载
评论 #43854828 未加载
评论 #43856234 未加载
评论 #43854434 未加载
评论 #43854660 未加载
评论 #43858341 未加载
lwansbrough21 天前
I think a pretty good show would be something written like West Wing, where everyone takes themselves very seriously, but with rampant, blatant incompetence. Like, not funny at all. Nothing tongue in cheek, no winks to the audience. A drama of morons.<p>Get me inside the minds of these freaks.
评论 #43855902 未加载
评论 #43855915 未加载
评论 #43860857 未加载
评论 #43855714 未加载
评论 #43857392 未加载
coryfklein21 天前
The contrast betweeen<p>a) beaurocrats&#x27; real comms setups (3 <i>telephones</i>, four monitors all sitting on the desk – versus mounted on arms&#x2F;wall) full of clutter and sitting on an anachronism of a wood desk<p>and b) what you&#x27;d see in any &quot;spy&quot; movie with dark-mode graphics displaying fancy l33t charts displayed on quad-monitor setups mounted on arms, probably in a low-light setting and the beaurocrat doesn&#x27;t look at the &quot;small&quot; monitors himself, his cronies do that, the only monitor he looks at is the single 136&quot; on the wall used for teleconferencing with villains<p>is hilarious
评论 #43858128 未加载
purpleidea21 天前
I can only imagine two possible explanations:<p>1) He is avoiding some sort of corrupt signals intelligence folks from knowing what he&#x27;s working on.<p>2) He is avoiding the government catching him in some corruption by avoiding the official records act.<p>Anything else?
评论 #43855184 未加载
评论 #43854876 未加载
bunnie21 天前
I feel bad for the Signal devs. If they weren&#x27;t personally targets for state level actors before, they are now.<p>Say what you want about the usability of DoD home grown solutions, but it was a military system backed up by military budgets and guns - civilians are less likely to be collateral damage in an attack against these systems.<p>Now, all the civilians using Signal are potential splash damage casualties in a military conflict.<p>I also suspect Signal does not have the budget, staffing, or desire to serve as a front line soldier in a cyber war; but this exposes them to military-grade risks, whether they like it or not.
评论 #43859887 未加载
wmf21 天前
If some tech geniuses wanted to improve government efficiency, one thing they could do is create secure yet easy to use collaboration software. Maybe give the app a catchy one-letter name.
评论 #43864479 未加载
Waterluvian21 天前
Somewhat related: does there exist a technology where I can encrypt something in a manner that it can only be decrypted after a specific future date? If theoretically possible, what would it take for something like that to exist? ie. &quot;We&#x27;d need an authority to broadcast some ongoing pseudorandom number generator that can be trusted&quot; or whatnot.
评论 #43856435 未加载
评论 #43856685 未加载
评论 #43862588 未加载
评论 #43856394 未加载
nneonneo21 天前
Site’s being hugged hard - mirror: <a href="https:&#x2F;&#x2F;archive.is&#x2F;kMZ2A" rel="nofollow">https:&#x2F;&#x2F;archive.is&#x2F;kMZ2A</a>
netbioserror21 天前
I&#x27;m simply going to point out the blaringly obvious that has somehow missed the armchair commentariat for this whole narrative debacle:<p>1) DoD and other departments have either tacitly or explicitly approved the use of Signal for internal matters for several years now, with proper opsec.<p>2) You cannot govern exclusively from a SCIF, hence 1.
评论 #43858426 未加载
评论 #43856776 未加载
评论 #43857039 未加载
评论 #43862234 未加载
评论 #43856737 未加载
insane_dreamer21 天前
Since NSA Waltz just got fired for this, shouldn&#x27;t Hesgeth as well?
pessimizer21 天前
They&#x27;re just going to keep hammering this dude until he bombs Iran, then MSNBC will say that he&#x27;s finally grown into the role of a statesman and learned to make the hard choices.
Havoc21 天前
I get that he’s senior but surely someone else signed off this farce?
评论 #43857919 未加载
flexorium21 天前
I’m somewhat surprised to see that they use a KVM to switch between back and forth between a JWICS and SIPRNET. I would imagine it’s a special KVM as it’s essentially bridging the airgap between the two.<p>I’m guessing that’s the product in question: <a href="https:&#x2F;&#x2F;www.vertiv.com&#x2F;490454&#x2F;globalassets&#x2F;products&#x2F;monitoring-control-and-management&#x2F;secure-kvm&#x2F;secure-kvm-application-brief.pdf" rel="nofollow">https:&#x2F;&#x2F;www.vertiv.com&#x2F;490454&#x2F;globalassets&#x2F;products&#x2F;monitori...</a>
评论 #43856695 未加载
codeulike21 天前
Not a fan of the Trump administration but I imagine the official pentagon communications systems must be extremely clunky and annoying, and about 20 years behind civilian tech.<p>During the UK Covid-19 enquiry into gov decision making at that time it came to light that most of the UK cabinet were co-ordinating via Whatsapp groups. Again, I&#x27;m not a fan of Boris and Dom Cummings but this makes some sort of sense to me. I recognise the need for government teams to have quick convenient chat available to them. Things move too fast these days to wait for the next cabinet meeting or to arrange things via a series of phone calls.<p>Similarly we can look back to Obama having to fight to keep his Blackberry in 2009 <a href="https:&#x2F;&#x2F;www.nbcnews.com&#x2F;id&#x2F;wbna28780205" rel="nofollow">https:&#x2F;&#x2F;www.nbcnews.com&#x2F;id&#x2F;wbna28780205</a>
评论 #43856374 未加载
评论 #43855680 未加载
评论 #43859672 未加载
评论 #43855661 未加载
评论 #43860810 未加载
评论 #43855391 未加载
评论 #43867389 未加载
mschuster9121 天前
&gt; It is remarkable to what great lengths Hegseth went to use the Signal app, because as defense secretary he has his own communications center which is specialized in keeping him in contact with anyone he wants. This center is commonly called SecDef Cables and is part of Secretary of Defense Communications (SDC) unit.<p>... but unlike Signal, SDC respects laws requiring accurate record-keeping. And that&#x27;s why this bunch of lawbreakers want to use Signal. They want to evade any and all accountability once this administration is over.
jmyeet21 天前
Where is the &quot;but her emails&quot; crowd now? There are three main issues here:<p>1. The Defense Department bans the use of Signal for everybody else. Why is that? Why is the Secretary exempt?<p>2. As we&#x27;ve seen it&#x27;s pretty easy to add unauthorized people to what should be secure communication channels where classified information is shared; and<p>3. There are laws around the preservation of governmental records. Expiring Signal messages seems like it&#x27;s intentionally meant to circumvent these legal requirements ie it&#x27;s illegal.<p>We&#x27;re only 100 days in. We&#x27;ve got 1200 more days of this.
评论 #43855563 未加载
评论 #43853744 未加载
评论 #43856750 未加载
评论 #43853990 未加载
mcfedr21 天前
Why are your police not investigating this? The guy is actively breaking the law
评论 #43853677 未加载
评论 #43853654 未加载
评论 #43854045 未加载
评论 #43853628 未加载
JohnTHaller21 天前
Of course, there will be no consequences for his complete lack of... everything
评论 #43853438 未加载
评论 #43853810 未加载
flerchin21 天前
But what about her emails. &#x2F;s
评论 #43857009 未加载
zelon8821 天前
He should probably be investigated. He&#x27;s giving off major &quot;Russian Asset&quot; vibes.
JensRantil21 天前
Of course the guy needs to have an end-to-end encrypted direct line to the president. It&#x27;s the president that runs the show and all decisions must go through him.
Aeolun21 天前
Maybe just let the man use Signal?<p>If someone gave me a whole set of locked down _windows_ computers and a bunch of achaic phone lines and told me to use them in 2025, I’d also try to circumvent such inconvenience.
评论 #43856478 未加载
评论 #43857410 未加载
gotoeleven21 天前
My understanding is that the use of signal started during biden&#x27;s term. Is this not true?
评论 #43854051 未加载
评论 #43854891 未加载
评论 #43853657 未加载
评论 #43853790 未加载
评论 #43853707 未加载
iambateman21 天前
I wish more people, especially media writers, would start with the presumption that &quot;circumventing the state-approved security machine&quot; is a _feature_ of this administration.<p>Not to pick on this in particular – nearly all the reporting on this starts and ends with &quot;Signal is insecure&quot; as if that was all it took to be wrong. And in other eras, that was enough.<p>The man likes Signal. For better or worse, he is the Secretary of Defense...The man we&#x27;ve entrusted to help coordinate our national defense.<p>There&#x27;s so many questions I genuinely don&#x27;t have an answer for...<p>Has Congress made it illegal to use an off-brand messaging app for secure communications? _Why_ is it insecure? What is the probability that China is reading these messages in real-time? 100%? 25%? 0.2%?<p>We need to start from the presumption that the people-in-power don&#x27;t care that it&#x27;s always been done this way...in fact, they have a ton of pressure to be different. But, in some cases, these people may be willing to listen to reasonable arguments which clearly establish _why_ using Signal is unreasonably worse than using US Government Issue messaging.
评论 #43853852 未加载
评论 #43853525 未加载
评论 #43853653 未加载
评论 #43853507 未加载
评论 #43853621 未加载
评论 #43853899 未加载
评论 #43853537 未加载
评论 #43853711 未加载
评论 #43855278 未加载
评论 #43853675 未加载
评论 #43854002 未加载
评论 #43853579 未加载