Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

DesMoinesDem

(1,569 posts)
Wed Mar 4, 2015, 01:34 PM Mar 2015

Revealed: Clinton’s office was warned over private email use


Revealed: Clinton’s office was warned over private email use
State Department cybersecurity source says Clinton aides ignored concerns

State Department technology experts expressed security concerns that then–Secretary of State Hillary Clinton was using a private email service rather than the government’s fortified and monitored system, but those fears fell on deaf ears, a current employee on the department’s cybersecurity team told Al Jazeera America on Tuesday.

The employee, who spoke on the condition of anonymity for fear of losing his job, said it was well known that Clinton’s emails were at greater risk of being hacked, intercepted or monitored, but the warnings were ignored.

“We tried,” the employee said. “We told people in her office that it wasn’t a good idea. They were so uninterested that I doubt the secretary was ever informed.”

...

“That’s reason for serious concern because the State Department’s email system is presumably secured and monitored for threats to national security to a level that whatever Hillary Clinton was using that she set up herself likely is not,” said J. Alex Halderman, a University of Michigan cybersecurity expert whose most recent paper demonstrated how easily hacked and deceived certain airport body scanners are. “It’s possible she had some kind of special protection in place, but in the absence of any other information, I would be very worried.”

...


http://america.aljazeera.com/articles/2015/3/3/govt-cybersecurity-source-clintons-office-warned-private-email-use.html
37 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Revealed: Clinton’s office was warned over private email use (Original Post) DesMoinesDem Mar 2015 OP
Thanks for the information. mylye2222 Mar 2015 #1
That's because she was running her own bootleg ISP nichomachus Mar 2015 #2
"Bootleg ISP?" That's funny. nt msanthrope Mar 2015 #6
Hi DemocratSinceBirth Mar 2015 #17
"I doubt the secretary was ever informed." nichomachus Mar 2015 #3
As much as we can rationalize implications which validate our biases... LanternWaste Mar 2015 #7
Whatever that word salad means nichomachus Mar 2015 #10
This message was self-deleted by its author 1000words Mar 2015 #4
I'm sure the NSA has all of her communications in their 'data collection and storage' of every sabrina 1 Mar 2015 #5
Not to mention nichomachus Mar 2015 #8
Get it all out of your system now, because if she's our nominee ... 11 Bravo Mar 2015 #19
Anonymous employee, and a cyber security expert absent of info. JaneyVee Mar 2015 #9
Hillary suppressed release of her undergraduate thesis when she became 1st lady HereSince1628 Mar 2015 #11
After the Wikileaks dump, Snowden, CIA spying on congress, etc., I don't really see how they can DanTex Mar 2015 #12
There is no way you're not doing a comedy bit. You think her private email DesMoinesDem Mar 2015 #13
If it's set up correctly, then yes. Do you know much about computer security? I doubt it. DanTex Mar 2015 #14
I know a great deal about data security--enough to know you're out of your league. DisgustipatedinCA Mar 2015 #15
Somehow I doubt that.... DanTex Mar 2015 #16
Somehow I don't. Bring what you have to me. DisgustipatedinCA Mar 2015 #21
LOL. Ten thousand dollars! Right now! Let's bet!!!!! Sorry, Mitt, but I'm not Rick Perry. DanTex Mar 2015 #22
So you think I'm a liar and I think you're an idiot. We're off to a good start. DisgustipatedinCA Mar 2015 #24
You must have missed the Mitt Romney debate reference. I stopped challenging random people to bets DanTex Mar 2015 #25
There is a lot we agree on, but we come to very different conclusions. DisgustipatedinCA Mar 2015 #26
I was mostly civil, fair enough. Thanks for the civil response. DanTex Mar 2015 #29
Thanks, DanTex. Have a good evening. nt DisgustipatedinCA Mar 2015 #30
By the way, remember that vulnerability scan I mentioned? DisgustipatedinCA Mar 2015 #32
It says "B" when I click on that link. DanTex Mar 2015 #33
It's changed in the last 2 hours. They're discussing the change on slashdot DisgustipatedinCA Mar 2015 #34
Hmm. Looks like they upgraded something since Saturday. DanTex Mar 2015 #37
They should have all State Department employees set up their own home email servers. DesMoinesDem Mar 2015 #18
No, that would be a bad idea. Most of the employees wouldn't know how to do it. DanTex Mar 2015 #20
Yep, I'm clueless. Says the guy that thinks your home server is more secure DesMoinesDem Mar 2015 #27
Well, depends how the private server is set up and managed. DanTex Mar 2015 #28
+1, that is just comedy. Marr Mar 2015 #31
Secure against what is the question. In terms of external threats, State is more secure, no question stevenleser Mar 2015 #35
Warning: Don't use the cone of silence. hunter Mar 2015 #23
Really??? maxrandb Mar 2015 #36

nichomachus

(12,754 posts)
3. "I doubt the secretary was ever informed."
Wed Mar 4, 2015, 05:14 PM
Mar 2015

So she's not in control of her staff. Not good leadership qualities. But then, she's never been in a position of leadership. No experience.

 

LanternWaste

(37,748 posts)
7. As much as we can rationalize implications which validate our biases...
Wed Mar 4, 2015, 05:27 PM
Mar 2015

As much as we can rationalize implications which validate our biases, regardless of how much of it is merely creative allegation and speculation, we certainly will... and pretend it's fact to further secure our imaginations.

Response to DesMoinesDem (Original post)

sabrina 1

(62,325 posts)
5. I'm sure the NSA has all of her communications in their 'data collection and storage' of every
Wed Mar 4, 2015, 05:21 PM
Mar 2015

American's phone calls, emails and whatever other means of communications they once thought was private.

They were after all, collecting the same data on Merkel and other World Leaders.

A lot of people here tried to defend that gross violation of the 4th Amendment rights of US citizens.

For what should be obvious reasons.

The fear eg, that it could use such information for nefarious purposes, such as in a case like this.

Maybe our law makers have to suffer the consequences of their support for those Anti-Consitutional practices by government agencies before they finally wake up and do something to restore our Constitutional rights.

nichomachus

(12,754 posts)
8. Not to mention
Wed Mar 4, 2015, 05:28 PM
Mar 2015

The Russians, Germans, Israelis, Anonymous, Pakistan, etc.

I'm sure they had all were able to get access to her homebrew system.

11 Bravo

(23,928 posts)
19. Get it all out of your system now, because if she's our nominee ...
Wed Mar 4, 2015, 07:13 PM
Mar 2015

you're going to either have to develop a new schtick, or seek a website more in tune with your political leanings.

HereSince1628

(36,063 posts)
11. Hillary suppressed release of her undergraduate thesis when she became 1st lady
Wed Mar 4, 2015, 06:03 PM
Mar 2015

there is a lot of smoke and mirror stuff to try to make it look like situation normal, but no one had actually asked the college library to NOT lend library copies of student thesis until that happened.

I am not saying HRC has done something wrong, based on what I know when I hit "post my reply" I don't know anything that suggests she did something wrong...I am just saying that people who wish to can construe a string of dots that could make her look worried about being in control of her tracks.

DanTex

(20,709 posts)
12. After the Wikileaks dump, Snowden, CIA spying on congress, etc., I don't really see how they can
Wed Mar 4, 2015, 06:09 PM
Mar 2015

claim that government databases are secure. If a private server is set up correctly by someone skilled, it would be more secure than a big government agency's email system.

 

DesMoinesDem

(1,569 posts)
13. There is no way you're not doing a comedy bit. You think her private email
Wed Mar 4, 2015, 06:39 PM
Mar 2015

is more secure than the State Department? She needed to set up an email server herself to protect herself from the CIA and NSA? You can't be serious.

DanTex

(20,709 posts)
14. If it's set up correctly, then yes. Do you know much about computer security? I doubt it.
Wed Mar 4, 2015, 06:42 PM
Mar 2015

The weaknesses are mostly the humans involved, not the algorithms. But even if you don't know that, it should be obvious from the Wikileaks and Snowden incidents that government data is not safe.

 

DisgustipatedinCA

(12,530 posts)
21. Somehow I don't. Bring what you have to me.
Wed Mar 4, 2015, 07:19 PM
Mar 2015

I don't claim expertise in many areas, because I'm not an expert in many areas. Therefore, when I do make that claim, I mean exactly what the motherfuck I say, and I'm ready to back that up with a very large and public wager, proceeds going to the DU. Let me know when you're ready.

DanTex

(20,709 posts)
22. LOL. Ten thousand dollars! Right now! Let's bet!!!!! Sorry, Mitt, but I'm not Rick Perry.
Wed Mar 4, 2015, 07:21 PM
Mar 2015

I'll believe you know the first thing about computer security when you say something intelligent on the topic. Which hasn't happened yet.

The thing is, if you were the expert you claim to be, then you would be able to set up a secure email server. Obviously, you can't. So you're not.

 

DisgustipatedinCA

(12,530 posts)
24. So you think I'm a liar and I think you're an idiot. We're off to a good start.
Wed Mar 4, 2015, 07:43 PM
Mar 2015

I can't cover $10,000, but I can certainly cover $500. But before we get to that, let's back up. I made no claims about an email server one way or another. If you'll attempt to read my post again, you may be able to see that my claim was expertise in data security. As it happens, I can set up a pretty secure email server, and I can do a lot to secure the perimeter too. But I can also run vulnerability scans that show me 150-200 new sev4/sev5 vulnerabilities popping up on a weekly basis. And I can remediate and mitigate those vulnerabilities on 150 servers, 25 routers, 60 switches, and 20 firewalls. I know I can, because that's EXACTLY WHAT THE FUCK I DO FOR A LIVING.

Here's a little knowledge for you to internalize: setting up a "secure email server" is not a static event. It's an ongoing event that must be kept up to snuff on a weekly (if not daily) basis. While an individual can choose to be very proactive and keep a server environment secured on a continual and ongoing basis, that almost never happens when a consultant is called in to implement the server in the first place.

You have made the claim that setting up one's own email server and maintaining it is, on balance, more secure than a large IT staff taking care of the same tasks. Ergo, you're out of your league. You've apparently never seen how an enterprise runs. I congratulate you on reading your O'Reilly book, but that's just not the same thing as managing a data security program that mandates internal and external audits, penetration tests, vulnerability remediation, and disaster recovery testing.

I am by trade a network engineer, and I manage an infrastructure group (which to you means servers, network equipment, and voice over-) at a financial institution, and I am subject to everything I've listed above, and then some. I have a CSO and security department watching what my department does. I have an internal audit group that does the same thing from a different perspective. I have outside auditors come in twice a year to poke holes in my network and see what they can see, and that's all in preparation for federal OCC examiners who come in once a year for the real deal. That's my claim to data security expertise, and I'll stand behind that.

Again, if you believe that an individual running an email server is more secure than a robust IT department doing the same, you haven't the faintest goddamned idea of what you're talking about. With regard to Hillary Clinton, I haven't really weighed in much on the issue. I don't think she's breaking any laws. I just think she was really stupid to run an email server out of her house. Tell me something, wise one. If she had such a shit-hot tech setting up her email server and getting the static/symmetrical connection, why on god's green earth didn't that shit-hot tech anonymize the WHOIS record so that it didn't...you know...trace directly back to the fucking Secretary of State's home address? Go ahead and answer that one for me, sport.

And do let me know about that wager. DU could use the money. But do remember, I NEVER make a bet without being ready to win.

DanTex

(20,709 posts)
25. You must have missed the Mitt Romney debate reference. I stopped challenging random people to bets
Wed Mar 4, 2015, 07:55 PM
Mar 2015

when I was about 14. You'll grow out of it some day too.

Anyway, it looks like we agree that if a private server is set up (and managed, I left that out, you are right) correctly, then it will indeed be more secure than the state department's network.

Since you work with big systems, surely you understand that securing a large network is much, much, much more difficult than securing a single server. You also understand that the biggest risks that organizations face are not from the protocols themselves, but from the humans involved. It just takes one person to, say, start using Dropbox for work-related activites. And even that's assuming that there aren't any adversaries or leakers on the inside, something that is all but guaranteed to happen at the state department.

The NSA, probably the most security-savvy organization in the world, just suffered a massive breach. That is how difficult it is to secure systems that have a lot of users. Every single one of them is a vulnerability. This is the very reason why organizations like the one you work at need to have groups of IT experts. Well, one of the reasons. The other reason is that their computer systems do a lot more than just email.

Which brings us back to the original point. A single computer running nothing but an email server can be made more secure than the state department's or even the NSA's computer network.

 

DisgustipatedinCA

(12,530 posts)
26. There is a lot we agree on, but we come to very different conclusions.
Wed Mar 4, 2015, 08:07 PM
Mar 2015

I really don't particularly want a fight with you, but I'm not a big braggart about expertise--again, there are lots of areas where I'm not an expert, and a couple of areas where I am. That doesn't make me special; it just means I have a day job I'm pretty good at.

Regarding the conclusion, I'll always believe that a robust and continual data security program is the best way to keep any server secure, because it's one of those things that someone is assigned to do on a regular and recurring basis, i.e., "it's my job and I've got to do it if I want to get a raise, keep my job, etc". I understand what you're saying about the complexity of larger implementations, but I don't happen to agree. However, I would like to climb down off my high horse and bid you peace. Thanks for the civil reply.

EDITED to Add: you were mostly civil. And no, I won't learn to stop challenging "random" people with wagers. I come from an era where random actually meant random. I do have kids, so I understand the newer context too, but in no way did I randomly choose you. On three different occasions, from 2001 to now, on DU, I've challenged people to a bet. This always involved people making technical claims I KNEW with certainty were not correct. Those wagers have never happened, because we more or less came to an understanding the way you and I have more or less come to an understanding. There was nothing random about my choice, and I'll likely do it again one of these days if I feel compelled. Thanks.

DanTex

(20,709 posts)
29. I was mostly civil, fair enough. Thanks for the civil response.
Wed Mar 4, 2015, 08:23 PM
Mar 2015

I continue to believe that a private email server can be set up and managed, without extraordinary difficulty, to be more secure than the state department's network, for the reasons I outlined in the last post. But I'm glad we got to a reasonable agree-to-disagree point. I understand what you are saying about people making technical claims who don't have a clue.

Whether Hillary actually set up the server securely is a another question. Your point about the WHOIS is an indication that she didn't. Although, given that her house is guarded by secret service, one could make the argument that the physical threat level is very low. On the other hand, if it were me, I would rent some rack space somewhere instead of having the physical server in her home, not for security reasons, but for uptime.

Anyway, good talking to you.

 

DisgustipatedinCA

(12,530 posts)
32. By the way, remember that vulnerability scan I mentioned?
Tue Mar 10, 2015, 12:09 PM
Mar 2015

I use Qualys at work. Just found this on Slashdot:

https://www.ssllabs.com/ssltest/analyze.html?d=mail.clintonemail.com

The server was not secure, so it earned an "F".

DanTex

(20,709 posts)
37. Hmm. Looks like they upgraded something since Saturday.
Tue Mar 10, 2015, 07:02 PM
Mar 2015

Still, not convinced that it was a big security risk, especially compared to the State Department's system, which after Snowden and Manning we know is insecure.

It looks like that site grades the security of web servers, not email servers specifically (though that raises the question of why the web server was even running). And also, seems to me that some of those weaknesses are only weaknesses depending on how clients connect. For example, correct me if I'm wrong, but support for SSL 2.0 isn't a huge problem as long as nobody actually uses SSL 2.0 on the client side.


Still, it doesn't look good that they had a poorly configured web server running.

 

DesMoinesDem

(1,569 posts)
18. They should have all State Department employees set up their own home email servers.
Wed Mar 4, 2015, 07:13 PM
Mar 2015

Much more secure. LOL. The State Department has foreign intelligence trying to hack it constantly. They have a lot of people making sure they don't succeed. And you think some home server is more secure. I have no words. That is beyond stupid.

DanTex

(20,709 posts)
20. No, that would be a bad idea. Most of the employees wouldn't know how to do it.
Wed Mar 4, 2015, 07:17 PM
Mar 2015

It would also be a huge waste of resources. Very bad idea.

The only thing hilarious -- well, there are two. The first is how utterly clueless you are about computer security. And the second is that you are singing the praises of the government's security in the wake of two truly enormous leaks. Of course! That could never happen again. So secure! LOL.

 

DesMoinesDem

(1,569 posts)
27. Yep, I'm clueless. Says the guy that thinks your home server is more secure
Wed Mar 4, 2015, 08:15 PM
Mar 2015

than the State Department and who thinks the greatest security threat at the State Department is the NSA and CIA. Thanks for the laughs.

DanTex

(20,709 posts)
28. Well, depends how the private server is set up and managed.
Wed Mar 4, 2015, 08:21 PM
Mar 2015

But if done correctly, then yes, absolutely. Just one machine that does nothing but email is much easier to secure.

And, no, the greatest threats to the State Department aren't the NSA and the CIA. Not sure where you got that from.

And, yes, you are clueless.

 

stevenleser

(32,886 posts)
35. Secure against what is the question. In terms of external threats, State is more secure, no question
Tue Mar 10, 2015, 03:24 PM
Mar 2015

about it. But that is not the entire threat picture. Internal threats are responsible for a huge percentage of data breaches.

The one thing she doesnt have to worry much about regarding a server in her home is internal threats.

http://www.csoonline.com/article/2134056/network-security/report-indicates-insider-threats-leading-cause-of-data-breaches-in-last-12-months.html

maxrandb

(15,364 posts)
36. Really???
Tue Mar 10, 2015, 03:50 PM
Mar 2015

An anonymous-unnamed source says he worked in IT and says it was "well known" that the emails could be hacked, etc., etc., etc.,---and that's somehow translated as "Revealed: Clinton's Office was warned"????

Ya know..."some" have said that's complete and total bullsh$#, while "others" have "confirmed" that stories like this are compete and total bullsh$#, meanwhile, "someone" who is an expert on complete and total bullsh$#, confirmed that this was quite possibly the largest pile and foulest smelling bullsh$# they had ever encountered

and let me tell you, this "expert" certainly knows his bullsh$#.

This is what passes for news?

Latest Discussions»General Discussion»Revealed: Clinton’s offic...