News: 1702404011

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Discord in the ranks: Lone Airman behind top-secret info leak on chat platform

(2023/12/12)


There was only one US Air National Guardsman behind the leak of top-secret US military documents on Discord, but his chain of command bears some responsibility for letting it happen on their watch.

The US Air Force reached that conclusion in an August [1]report [PDF] made public yesterday into the actions of Airman 1st Class Jack Teixeira, who was [2]arrested in April on suspicion that he had stolen and shared classified military documents on a private Discord server that later found their way to the wider internet – and, presumably, into the hands of foreign governments.

According to the USAF's investigation, Teixeira was the only person directly involved in the leaks, which he began sharing with his fellow Discorders as early as February 2022.

[3]

Teixeira was a member of the 102nd Intelligence Wing (102 IW), working as a computer/IT specialist until his arrest. His work performing systems maintenance on the Joint Worldwide Intelligence Communication System (JWICS), classified as a Top Secret-Sensitive Compartmented Information (TS-SCI) platform, gave him the ability to "view intelligence content and analysis ... on those systems," the USAF said.

[4]

[5]

While Teixeira appears to have acted alone, there were as many as four occasions in which he displayed warning signs that members of his unit recognized yet failed to act upon.

Per the USAF report, Teixeira "was observed viewing intelligence content on TS-SCI websites" in August 2022, and while his supervisor was informed, the incident wasn't otherwise documented.

[6]

A month later he was again spotted viewing intelligence documents while writing information on a Post-It note. While Teixeira was confronted, told to shred the note, and the incident was documented in writing, "it was never verified what was written on the note or whether it was shredded." Neither the Post-It incident nor the August incident were reported to security officials, the USAF found.

[7]US military battling cyber threats from within and without

[8]US Navy sailor admits selling secret military blueprints to China for $15K

[9]US, NATO military plans leak: Actual war strategy or pro-Kremlin shenanigans?

[10]US govt IT help desk techie 'leaked top secrets' to foreign nation

In October 2022, "Teixeira asked very detailed questions and even attempted to answer questions using suspected TS-SCI information he did not have a need to know," the USAF said. His supervisor was informed of "suspected intelligence-seeking behavior" and Teixeira was told to cease and desist his intelligence deep dives. Again, the incident was documented but no security official was informed.

It wasn't until January 2023 that higher-level unit leadership was made aware of Teixeira's behavior when he was caught viewing intelligence content yet again and his supervisor decided to inform squadron leadership.

A "substantially minimized" version of leadership concerns were passed to security officials, but no copies of the memorandums for record "or an accurate description of the security concerns" were included.

"As a result, additional available security actions were not taken and no further inquiry or investigation occurred," the report found. Had Teixeira's leadership, particularly three people in his direct chain of command, come forward "the length and depth of the unauthorized disclosures may have been reduced by several months."

[11]

In addition to the direct leadership failure to stop Teixeira's actions, the USAF report found several systemic failures in his unit's structure that contributed, including a lack of supervision of the night shift on which Teixeira served. Additional failures included no permissions controls to monitor print jobs (Teixeira allegedly printed documents), inconsistent "need to know" guidelines, and a failure to properly consider information on background checks.

Air Force takes action

Along with Teixeira's imprisonment and pending trial, 15 Air National Guard leaders have been [12]disciplined for their failure to act, ranging from non-commissioned officers all the way up to high-ranking leadership.

Colonel Sean Riley, 102 IW commander, was relieved of his command, while Colonel Enrique Dovalo, 102nd Intelligence, Surveillance and Reconnaissance (ISR) Group commander, received "administrative action for concerns with unit culture and compliance with policies and standards."

Commanders previously suspended during the Teixeira investigation were permanently removed, and the entire 102nd ISR Group has been taken off mission and its duties reassigned.

The USAF has also undertaken reforms to its need-to-known and classified data access standards, the branch reported.

"Every Airman and Guardian is entrusted with the solemn duty to safeguard our nation's classified defense information. When there is a breach of that sacred trust, for any reason, we will act in accordance with our laws and policies to hold responsible individuals accountable," said Secretary of the Air Force Frank Kendall. ®

Get our [13]Tech Resources



[1] https://www.af.mil/Portals/1/documents/2023SAF/UD_ROI_-_11_Dec_23.pdf

[2] https://www.theregister.com/2023/04/13/alleged_pentagon_leaker_arrested/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXjmGe7KbORbeuK5kqiU8gAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXjmGe7KbORbeuK5kqiU8gAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXjmGe7KbORbeuK5kqiU8gAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXjmGe7KbORbeuK5kqiU8gAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/08/01/us_military_cybersecurity/

[8] https://www.theregister.com/2023/10/11/us_navy_china_spy/

[9] https://www.theregister.com/2023/04/07/us_military_plans_leak/

[10] https://www.theregister.com/2023/09/21/it_help_desk_guy_arrested/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXjmGe7KbORbeuK5kqiU8gAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.315aw.afrc.af.mil/News/Article-Display/Article/3613314/results-of-investigation-into-a1c-texieras-unit-following-unauthorized-disclosu/

[13] https://whitepapers.theregister.com/



Competency assumption

Peter Prof Fox

Somehow we assume that high-up people in spooky organisations [HEY REGISTER! STOP FORCING MY SPELLCHECKER TO en-US] are sharp. Of course not. They're box-tickers with confined roles that appeal to narrowly motivated people with both eyes on a clean record. Promotion for an actual achievement is unheard of. We all know what 'management' is so where it's institutionalised don't be shocked.

Ensuring improper use will occur 101

Mike 137

From the report: " IT specialists in the 102 ISS, including A1C Teixeira, were encouraged to receive weekly intelligence briefings to better understand the mission and the importance of keeping the classified networks operating. This “know your why” effort was improper in that it provided higher level classified information than was necessary to understand the unit’s mission and created ambiguity with respect to questioning an individual’s need to know. "

This is an identical problem to that which allows Manning to exfiltrate sensitive information to Wikileaks.

Documented rules restricted users of SIPRNet from attaching removable drives or media, the policy states " Linking a computer with access to the SIPRNet to the Internet or to any other computer or media storage device that has not been approved for use with SECRET information is a serious security violation. Once any media storage device such as a CD or thumb drive has been connected to a computer with access to the SIPRNet, it becomes classified at the SECRET level. It must be protected accordingly and shall not be used on any unclassified computer. ".

Nevertheless it emerged at the investigation that known staffers operated largely unmonitored and were allowed personal use of the supposedly secret system. I quote from the [1]investigation transcript : " Defense (Coombs): How was it enforced? Lim: No. You trusted people. ”.

[1] http://alexaobrien.com/archives/1735

Re: Ensuring improper use will occur 101

t245t

@Mike 137 ..

And don't put a CD burner on your “secret” information computer

Doctor Syntax

Having the entire chain of command disciplined or fired! is an interesting experiment It has to be called that as it's certainly not the norm. If it was the norm the deterrence effect we'd see some improvements in security.

JWICS: protected secure terminals ?

t245t

The salient question should be how nobody noticed until Teixeira posted the info to Discord, for bragging rights.

[1]Cyber War: The Next Threat to National Security and What to do About It:

“Access to these terminals is more restricted because of their location, but the information flowing on the network still has to go across fiber optic cables and through routers and servers, just as with any other network. Routers can be attacked to cut communications. The hardware used ... can all be compromised at the point of manufacture of later one. Therefore we cannot assume that even this network is reliable.”

[1] https://indianstrategicknowledgeonline.com/web/Cyber%20War%20-%20The%20Next%20Threat%20to%20National%20Security%20and%20What%20to%20Do%20About%20It%20%28Richard%20A%20Clarke%29%20%282010%29.pdf

Re: JWICS: protected secure terminals ?

DS999

They can't possibly monitor everyone's access to classified documents to determine if someone is accessing something that their clearance allows them to access but they don't have any need to access. Or that if they access something they do have a need to access that they are misusing it - until there is evidence of that misuse reported like happened when it was posted on Discord.

How do you expect them to have found out what he was doing before it was posted on Discord? Assign an agent to everyone with a security clearance to monitor every bit of information they access using that clearance? (Note: that may be feasible someday with 'AI', but not today...best they could do is a small random sampling)

Fear is a clumsy tool

AVR

Partly though it was fear of the security protocols which prevented the security protocols being used:

A smaller

number of unit members had a more complete picture of A1C Teixeira’s intelligence-seeking

behaviors and intentionally failed to report the full details of these security concerns/incidents as

outlined in DoD security policies, fearing security officials might “overreact.”

This is a long-standing problem in the security services where the official protocols are nasty enough that people avoid letting them be triggered even when they should. The context I'd read about it involved blackmail but I think Teixeira's treatment by his co-workers is the same problem exhibiting a different way. Probably there needs to be a middle ground where there are consequences enough to be useful (maybe moving him away from classified info for a start?), without years or even decades of imprisonment being likely.

THE LESSER-KNOWN PROGRAMMING LANGUAGES #18: FIFTH

FIFTH is a precision mathematical language in which the data types
refer to quantity. The data types range from CC, OUNCE, SHOT, and
JIGGER to FIFTH (hence the name of the language), LITER, MAGNUM and
BLOTTO. Commands refer to ingredients such as CHABLIS, CHARDONNAY,
CABERNET, GIN, VERMOUTH, VODKA, SCOTCH, and WHATEVERSAROUND.

The many versions of the FIFTH language reflect the sophistication and
financial status of its users. Commands in the ELITE dialect include
VSOP and LAFITE, while commands in the GUTTER dialect include HOOTCH
and RIPPLE. The latter is a favorite of frustrated FORTH programmers
who end up using this language.