When Your Threat Model Is Being a Moron (www.404media.co)
from ForgottenFlux@lemmy.world to technology@lemmy.world on 26 Mar 16:35
https://lemmy.world/post/27420122

One of the most basic tenets of cybersecurity is that you must “consider your threat model” when trying to keep your data and your communications safe, and then take appropriate steps to protect yourself.

This means you need to consider who you are, what you are talking about, and who may want to know that information (potential adversaries) for any given account, conversation, etc. The precautions you want to take to protect yourself if you are a random person messaging your partner about what you want to eat for dinner may be different than those you’d want to take, if, hypothetically, you are the Secretary of Defense of the United States or a National Security Advisor talking to top administration officials about your plans for bombing an apartment building in Yemen.

#technology

threaded - newest

WhatAmLemmy@lemmy.world on 26 Mar 16:53 next collapse

This is one of the greatest headlines in the history of tech journalism.

sp3tr4l@lemmy.zip on 26 Mar 22:12 collapse

Its actually perfect. No notes. No possible improvements.

This deserves some kind of award.

Nougat@fedia.io on 26 Mar 17:06 next collapse

I recall hearing that professional poker players hate playing against novices, because novices are so unpredictable. It's really hard to plan a defense against someone(s) who are so incompetent that you have no idea what's going to happen.

NocturnalMorning@lemmy.world on 26 Mar 17:20 next collapse

That’s why I win at poker. I don’t know what I’m doing, so I’m always putting most of my chips in, whether I have nothing, or a pair of 2s.

SpaceNoodle@lemmy.world on 26 Mar 17:34 next collapse

That’s probably why you lose at poker, too.

SexualPolytope@lemmy.sdf.org on 26 Mar 21:24 collapse

That’s why drunk poker is so much fun lol. (Note: Don’t bet too much money. And only play with friends, if possible.)

rabber@lemmy.ca on 26 Mar 19:43 collapse

I actually got kicked out from a poker club in college because of this. I wasn’t “playing properly”.

Bishma@discuss.tchncs.de on 26 Mar 17:09 next collapse

By 2028 “alcoholic idiot” will be the only condition still protected by the ADA.

SpaceNoodle@lemmy.world on 26 Mar 17:35 collapse

Finally, the recognition I deserve

Ulrich@feddit.org on 26 Mar 17:27 next collapse

Your threat model is being authoritarian + a moron.

They’re using Signal with disappearing messages instead of official channels because they don’t want their conversations documented for accountability. It’s the same shit they relentlessly blasted Hillary for.

I was most disappointed when I read that he left the group chat. Missed opportunity for some top-class trolling:

We are good on OPSEC

Are you really tho? 👀 🥸 😱

SpaceNoodle@lemmy.world on 26 Mar 17:35 next collapse

He was running better OPSEC than the morons in charge.

marlowe221@lemmy.world on 26 Mar 21:01 collapse

Well, the bar was low…

T156@lemmy.world on 26 Mar 20:43 collapse

I was most disappointed when I read that he left the group chat. Missed opportunity for some top-class trolling:

Although that may have had him arrested/raided for accessing most secret information he lacks clearance for, so leaving upon finding out it was the real thing and not a joke group was the better move.

Ulrich@feddit.org on 26 Mar 20:47 next collapse

He didn’t “access” anything, it was sent directly to him.

Traister101@lemmy.today on 26 Mar 23:04 next collapse

But that obviously wouldn’t stop them from having him disappeared. Heck I don’t even think that’s off the table now

Ulrich@feddit.org on 26 Mar 23:07 collapse

Probably not, especially now that he’s leaking the previously undisclosed classified information (that the people involved insisted was not classified). But them’s the brakes when you’re a journalist.

jubilationtcornpone@sh.itjust.works on 29 Mar 14:00 collapse

Remember when the Governor of Missouri tried to have a guy arrested for notifying the state of Missouri that they had a breach in one of the state websites, making peoples PII publicly visible?

That’s the kind of idiots you’re dealing with here. “We added you to a group chat by mistake and it’s all YOUR fault.”

ansiz@lemmy.world on 27 Mar 11:45 collapse

The reporter is a former IDF soldier, there is no way he would face any real blowback from Trump. There is a reason they had his number to add to the group and it’s because they were already feeding him information. The Atlantic is just a left coded mouthpiece for the State Department.

MonkderVierte@lemmy.ml on 26 Mar 17:30 next collapse

about your plans for bombing an apartment building in Yemen.

Then maybe don’t.

sndmn@lemmy.ca on 26 Mar 17:30 next collapse

Another 9/11 scale fuckup is all but guaranteed, mark my words.

liverbe@lemmy.world on 26 Mar 18:09 next collapse

Yup, people are going to die, and it is going to be their fault… and they won’t care. Maybe the American people will. 🤔

bobs_monkey@lemm.ee on 26 Mar 18:46 collapse

Americans will be pissed, but at the end of the day nothing measurable will come of it. We’d have to be straight starving to get off our asses and get shit done.

crank0271@lemmy.world on 26 Mar 19:42 next collapse

And by then they’ll already have declared martial law.

Telorand@reddthat.com on 26 Mar 20:07 collapse

That’s gonna happen when a riot occurs or a protest gets violent. Presidents can do it for any length of time, and only Congress has the power to reign them in. And of course, none of them would do that, so it’s “Marshall” Law until they crown Trump or Vance emperor.

sugar_in_your_tea@sh.itjust.works on 27 Mar 00:10 collapse

I’m cool with starving, just don’t touch my internet service.

dan1101@lemm.ee on 27 Mar 12:23 collapse

But her emails, but Benghazi.

solrize@lemmy.world on 26 Mar 17:54 next collapse

Military gear generally has tons of anti-moron safeguards. Unfortunately, Signal is for civilians.

liverbe@lemmy.world on 26 Mar 18:11 collapse

Which also means these conversations were on an unapproved app on an unapproved device. Actual government phones wouldn’t be able to get Signal, right?

solrize@lemmy.world on 26 Mar 18:20 next collapse

Government secure phones are special hardware made by the NSA. They are nothing like civilian phones. Obama got the NSA to lock down his Blackberry but I doubt that is doable with today’s mainstream smartphones.

en.m.wikipedia.org/wiki/STU-III

ricecake@sh.itjust.works on 26 Mar 19:06 next collapse

I actually wouldn’t be shocked if it was possible with modern smartphones. A significant amount of money is available to be made from federal security work, and meeting the NSA criteria has benefits that extend to companies that work in the federal security space as well.

0xD@infosec.pub on 26 Mar 20:26 next collapse

As long as you can flash them, everything’s possible.

In that spirit: Fuck Apple to hell.

9488fcea02a9@sh.itjust.works on 27 Mar 12:21 collapse

The last stu-3 stopped working in 2009.

solrize@lemmy.world on 27 Mar 12:25 collapse

Yes they have different stuff now, but same idea.

darkdemize@sh.itjust.works on 26 Mar 20:49 collapse

I have a government-issued iPhone. It has Signal on it, and I have access to the appstore. It’s also not allowed to be used for anything but unclassified communication and isn’t permitted inside restricted areas.

Geobloke@lemm.ee on 26 Mar 19:39 next collapse

Can we just imagine if al Qaeda had added a journalist to their group chat regarding a bombing?

LovableSidekick@lemmy.world on 26 Mar 20:00 next collapse

MAGA Administration Secure Communication Assessment Procedure:

  1. Are you Hillary Clinton?
    ☐ Yes    ☐ No

If No, discontinue assessment and do whatever the fuck you want.

lipilee@feddit.nl on 27 Mar 12:53 collapse

this is what we used to call a “layer 8” issue