News: 1757440435

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Defense Dept didn't protect social media accounts, left stream keys out in public

(2025/09/09)


The US Department of Defense, up until this week, routinely left its social media accounts wide open to hijackers via stream keys - unique, confidential identifiers generated by streaming platforms for broadcasting content. If exposed, these keys can allow attackers to output anything they want from someone else's channel.

This was revealed by The Intercept's most recent [1]investigation , published on Monday, which found that the Pentagon for years posted stream keys on its Defense Visual Information Distribution Service (DVIDS) website.

According to the department, this security hole has since been closed.

[2]

"The practice of uploading stream keys publicly on DVIDS has since been fixed," a Defense Department official told The Register . "New stream keys have been implemented and will no longer be shared the old way. Any remaining cached info that would show stream keys would be old and out of date."

[3]

[4]

The DVIDS website is open to the public and doesn't require an account to browse, and it hosts military and administration videos, along with a schedule of upcoming webcasts. Up until this week, it also exposed some stream keys to its Facebook, YouTube, and X channels, leaving its livestreams open to account takeovers:

For example, Twitter stream keys were posted for the U.S. Cyber Command change of command ceremony live stream in 2018. X and YouTube keys were also posted for last year's West Point commencement ceremony. More recently, the stream keys for the department's X, YouTube, and Facebook accounts were posted in the hours leading up to a livestream of Defense Secretary Pete Hegseth giving burgers to the National Guard in Washington, D.C. in August.

These keys weren't hard to find, we're told, and could be seen by browsing the portal's sequentially-numbered webcast URLs, or Googling "stream key" and "DVIDS."

[5]Pentagon ends Microsoft's use of China-based support staff for DoD cloud

[6]Hegseth signs flying memo to expand military use of cheap drones in oddball video

[7]Pentagon declares war on 'outdated' software buying, opens fire on open source

[8]Signalgate lessons learned: If creating a culture of security is the goal, America is screwed

They also aren't supposed to be made public. [9]Google calls them "your YouTube stream's password and address," and [10]Facebook warns : "Don't share your stream key. Anyone who has access to it can stream video from your page."

To be fair to the current administration, this security oversight appears to have started before Trump 2.0 took office.

But considering the Pentagon security snafus that have happened under Defense Secretary Pete Hegseth's watch, including [11]using China-based employees to support Microsoft Azure cloud services deployed by the DoD (this practice [12]just ended late last month), and - lest we forget - [13]Signalgate , it seems to be par for the course. ®

Get our [14]Tech Resources



[1] https://theintercept.com/2025/09/08/department-of-war-defense-stream-keys-hackers-livestream-hack-security/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2025/08/29/pentagon_ends_microsofts_use_of/

[6] https://www.theregister.com/2025/07/11/hegseth_signs_flying_memo_to/

[7] https://www.theregister.com/2025/05/06/us_dod_software_procurement/

[8] https://www.theregister.com/2025/04/25/signalgate_lessons_learned_if_creating/

[9] https://support.google.com/youtube/answer/9854503?hl=en#zippy=%2Cstream-key

[10] https://www.facebook.com/fbgaminghome/creators/getstarted

[11] https://www.theregister.com/2025/08/08/exwhite_house_cyber_and_counterterrorism/

[12] https://www.theregister.com/2025/08/29/pentagon_ends_microsofts_use_of/

[13] https://www.theregister.com/2025/04/25/signalgate_lessons_learned_if_creating/

[14] https://whitepapers.theregister.com/



There was an old Indian belief that by making love on the hide of
their favorite animal, one could guarantee the health and prosperity
of the offspring conceived thereupon. And so it goes that one Indian
couple made love on a buffalo hide. Nine months later, they were
blessed with a healthy baby son. Yet another couple huddled together
on the hide of a deer and they too were blessed with a very healthy
baby son. But a third couple, whose favorite animal was a hippopotamus,
were blessed with not one, but TWO very healthy baby sons at the conclusion
of the nine month interval. All of which proves the old theorem that:
The sons of the squaw of the hippopotamus are equal to the sons of
the squaws of the other two hides.