bolha.us is one of the many independent Mastodon servers you can use to participate in the fediverse.
We're a Brazilian IT Community. We love IT/DevOps/Cloud, but we also love to talk about life, the universe, and more. | Nós somos uma comunidade de TI Brasileira, gostamos de Dev/DevOps/Cloud e mais!

Server stats:

252
active users

#opsec

30 posts18 participants1 post today
Continued thread

The review also will “review compliance with classification & records retention requirements,” Stebbins wrote. He requested that the #Defense Dept designate 2 points of contact within 5 days, with work done both in Washington & at the headquarters of US Central Command in Tampa, Florida.

The #Defense Dept inspector general’s office said Thurs that it will scrutinize top #Trump admin officials’ use of #Signal, an unclassified messaging app to coordinate a highly sensitive #military operation last month in Yemen, complying with a request from #Republicans & #Democrats in #Congress.

#Trump #NationalSecurity #OpSec #SignalGate
washingtonpost.com/national-se

The Washington Post · Inspector general to scrutinize Trump team’s Signal chatBy Dan Lamothe

🚨 OPSEC Disaster at the Top: How Michael Waltz Just Compromised U.S. National Security—AGAIN! 🤦🏻‍♂️ 🤬

While the Trump administration lectures about digital security, National Security Adviser Michael Waltz has been using Gmail to coordinate military operations and sharing after-action strike reports in Signal group chats that accidentally included a journalist.

Let’s be clear:
・Personal Gmail was used to discuss weapons systems & troop movements
・Israeli surveillance was exposed—jeopardizing a key intelligence partnership
・Sensitive coordination went through Signal, not JWICS
・Waltz, who attacked Hillary Clinton for email practices, is now guilty of worse

This is not a technical mistake. It’s a policy failure, a hypocritical breach, and a serious threat to U.S. operational integrity.

If you lead in national security, you do not get to bypass your own secure systems. And you certainly don’t blame “legacy contacts” when you get caught.

Accountability isn’t partisan. It’s essential.

👉 washingtonpost.com/national-se

The Washington Post · Waltz and staff used Gmail for government communications, officials sayBy John Hudson
Continued thread

Data #security experts have expressed alarm that US #NationalSecurity professionals are not…[just]…using the govt’s suite of secure encrypted systems for work communications such as JWICS, the Joint Worldwide Intelligence Communications System.

Most concerning, however, is the use of personal email, which is widely acknowledged to be susceptible to hacking, spearfishing & other types of digital compromise.

Continued thread

The use of personal email, even for unclassified materials, is risky given the premium value foreign #intelligence services place on the communications & schedules of senior govt ofcls, such as the #NationalSecurity adviser, experts say.

…Waltz has also created & hosted other #Signal chats w/Cabinet members on sensitive topics, including on #Somalia & #Russia’s war in #Ukraine, said a senior #Trump admin official.

Continued thread

#MikeWaltz has had less sensitive, but potentially exploitable information sent to his #Gmail, such as his schedule & other work documents, said ofcls, who, like others, spoke on the condition of anonymity to describe what they viewed as problematic handling of information. The ofcls said Waltz would sometimes copy & paste from his schedule into #Signal to coordinate meetings & discussions.

Continued thread

A snr #MikeWaltz aide used the commercial email service for highly technical conversations w/colleagues at other govt agencies involving sensitive #military positions & powerful #weapons systems relating to an ongoing conflict, acc/to emails reviewed by WaPo. While the #NSC official used his #Gmail account, his interagency colleagues used govt-issued accounts, headers from the email correspondence show.

#Facebook #opsec #fail - rave "banter" group puts up video of a good looking young lass in England at a petrol station who ended up with empty baggie that held her #partydrugs stuck to her back as she fills up the car. Registration mark of car in full view.

To be fair some lads *did* point out sharing the video could be problematic, but *no-one* picked up on the fact they've essentially grassed her up for potential #DUI (any cop or bootlicker now has her vehicle number plate)

British intel intern pleads guilty to smuggling top secret data out of protected facility.

Nothing about this makes sense.

1. A 25 year old intern.

No shade to interns but seems a bit old.

2. Intern had access to top secret intel.

Again nothing against interns, but give them access to top secret intel?

3. Intern uploaded top secret intel to a hard drive connected to his personal computer?

Why is anyone allowed to bring a personal phone int a facility that accesses top secret intel? Ever hear about a SCIF?

Either the story is missing a ton of facts or the British GCHQ had terrible operational security.

therecord.media/british-intern

therecord.mediaBritish intel intern pleads guilty to smuggling top secret data out of protected facilityHassan Arshad, 25, admitted to transferring sensitive material from an agency computer at GCHQ headquarters.