Defense Dept didn't protect social media accounts, left stream keys out in public
- Reference: 1757440435
- News link: https://www.theregister.co.uk/2025/09/09/us_dod_exposed_keys/
- Source link:
This was revealed by The Intercept's most recent [1]investigation , published on Monday, which found that the Pentagon for years posted stream keys on its Defense Visual Information Distribution Service (DVIDS) website.
According to the department, this security hole has since been closed.
[2]
"The practice of uploading stream keys publicly on DVIDS has since been fixed," a Defense Department official told The Register . "New stream keys have been implemented and will no longer be shared the old way. Any remaining cached info that would show stream keys would be old and out of date."
[3]
[4]
The DVIDS website is open to the public and doesn't require an account to browse, and it hosts military and administration videos, along with a schedule of upcoming webcasts. Up until this week, it also exposed some stream keys to its Facebook, YouTube, and X channels, leaving its livestreams open to account takeovers:
For example, Twitter stream keys were posted for the U.S. Cyber Command change of command ceremony live stream in 2018. X and YouTube keys were also posted for last year's West Point commencement ceremony. More recently, the stream keys for the department's X, YouTube, and Facebook accounts were posted in the hours leading up to a livestream of Defense Secretary Pete Hegseth giving burgers to the National Guard in Washington, D.C. in August.
These keys weren't hard to find, we're told, and could be seen by browsing the portal's sequentially-numbered webcast URLs, or Googling "stream key" and "DVIDS."
[5]Pentagon ends Microsoft's use of China-based support staff for DoD cloud
[6]Hegseth signs flying memo to expand military use of cheap drones in oddball video
[7]Pentagon declares war on 'outdated' software buying, opens fire on open source
[8]Signalgate lessons learned: If creating a culture of security is the goal, America is screwed
They also aren't supposed to be made public. [9]Google calls them "your YouTube stream's password and address," and [10]Facebook warns : "Don't share your stream key. Anyone who has access to it can stream video from your page."
To be fair to the current administration, this security oversight appears to have started before Trump 2.0 took office.
But considering the Pentagon security snafus that have happened under Defense Secretary Pete Hegseth's watch, including [11]using China-based employees to support Microsoft Azure cloud services deployed by the DoD (this practice [12]just ended late last month), and - lest we forget - [13]Signalgate , it seems to be par for the course. ®
Get our [14]Tech Resources
[1] https://theintercept.com/2025/09/08/department-of-war-defense-stream-keys-hackers-livestream-hack-security/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMCjeZrfVMhPMUteye4SYgAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2025/08/29/pentagon_ends_microsofts_use_of/
[6] https://www.theregister.com/2025/07/11/hegseth_signs_flying_memo_to/
[7] https://www.theregister.com/2025/05/06/us_dod_software_procurement/
[8] https://www.theregister.com/2025/04/25/signalgate_lessons_learned_if_creating/
[9] https://support.google.com/youtube/answer/9854503?hl=en#zippy=%2Cstream-key
[10] https://www.facebook.com/fbgaminghome/creators/getstarted
[11] https://www.theregister.com/2025/08/08/exwhite_house_cyber_and_counterterrorism/
[12] https://www.theregister.com/2025/08/29/pentagon_ends_microsofts_use_of/
[13] https://www.theregister.com/2025/04/25/signalgate_lessons_learned_if_creating/
[14] https://whitepapers.theregister.com/