At her recent press conference, Clinton assured America that her personal email server was secure, that there had never been any security breaches and in fact it was “at a location” guarded by the Secret Service as if Spetsnaz ninjas might attack. Nothing to worry about here folks, time to move on.
Except that is not true.
Clinton’s email was extremely vulnerable. This is not a partisan attack; it is technology.
Clinton’s Email Domain was Accessible Over the Internet and Cell Phones
Online security company Venafi TrustNet has the world’s largest database of digital certificates and associated metadata, allowing it to go back in time and identify how digital certificates were used in the past, a kind of forensics capability for IT security. Here’s what they found on the now-infamous clintonemail.com server, and it is not good.
Using non-intrusive Internet scanning tests routinely performed throughout by IT security teams (meaning foreign intelligence agencies have them too), Venafi learned the Clinton server was enabled for logging in via web browser, smartphone, and tablets. That automatically makes it vulnerable to interception, as the information Clinton was sending and receiving abroad was traveling via other nations’ web infrastructure and open-air cellular networks.
Clinton’s email log-in page was also hung out on the web all pink and naked, meaning anyone who stumbled on it could try and log in, or employ the standard array of password hacking and brute force attacks against it, much like they could with your Gmail account.
Had Clinton used a legitimate State Department email account, none of this would have been a problem. Unclassified State accounts can be accessed only one of three ways (for security purposes!) A) From inside a State Department facility; B) Using a State Department-issued Blackberry running exclusively on a State Department-owned server or C) Using a one-time code generated by a physical fob device hand-carried by a State employee. No web access. No straight-line cell access. Nope.
Luckily all her communications were encrypted so someone couldn’t just pluck them from the air like some rube sitting in Starbucks using the public WiFi, right? Wrong.
No Encryption
Oops. Clinton’s email traffic was not encrypted for the first three months of her term as Secretary of State.
But luckily Clinton stayed around Washington for that time, right?
Travels with Hillary
Wrong. State Department records show during her first three months in office Clinton had her walking shoes on. Among the 19 locations visited were spying hotspots like China, South Korea, Egypt, Israel, Palestine, a NATO event and a meeting in Switzerland with her Russian counterpart.
But how could she know she was at risk? Well, her own State Department says this about China:
Security personnel carefully watch foreign visitors and may place you under surveillance. Hotel rooms (including meeting rooms), offices, cars, taxis, telephones, Internet usage, and fax machines may be monitored onsite or remotely, and personal possessions in hotel rooms, including computers, may be searched without your consent or knowledge. Business travelers should be particularly mindful that trade secrets, negotiating positions, and other business-sensitive information may be taken and shared with local interests.
Now we’ll grant you that Hillary’s hotel room was closely guarded, but go back and re-read that warning, the part about how electronic communications might be monitored remotely.
Clinton Unclassified
Well, heck, Clinton claims none of the 30,000 some work emails were classified, so what?
Leaving aside exactly what Clinton had to say 30,000 times that somehow never crossed the line into classified, it seems there must have been some sensitive information tucked in there somewhere. For example, the one, single Clinton (unclassified) email that has been released was entirely redacted by the State Department, including Clinton’s personal server email address. The multi-months State Department review process now underway on Clinton’s turned-over emails is designed to redact sensitive information.
So there is something to hide. Too bad it appears likely that the Chinese government has access to information on Clinton the American people can’t be trusted to see.
There’s more.
Spoofing the Secretary
Without a security certificate and encryption for three months, Clinton’s server would not have been uniquely identified as being clintonemail.com and therefore could have been spoofed, allowing attackers to more easily trick an unsuspecting user of the site to hand over their username and password. She was also running a standalone Microsoft Windows Server, which is very vulnerable to attack, with at least 800 known trojans/spyware in existence that can steal keys and certificates. If the credentials on the server were compromised in those first three months (nah, the Chinese and the Israelis would never try that) then the next four years of encryption might have meant nothing.
But don’t worry. Clinton’s most recent digital security certificate was issued by GoDaddy. The domain’s blank landing page is hosted by Confluence Networks, a web firm in the British Virgin Islands, which is sorta a foreign country.
Questions of the Candidate
So, would some reporter please ask Hillary Clinton these two questions:
Where was the NSA? Where was the State Department’s Diplomatic Security technical security staff? Did they just miss all this, or did they report it to Clinton’s staff and were ignored?
What is the price America paid for your personal convenience?
BONUS: By claiming her server was secure, Clinton threw down the gauntlet to America’s geek and hacker communities, who do not take kindly to their moms pretending to know their business. Big tactical mistake…
Copyright © 2020. All rights reserved. The views expressed here are solely those of the author(s) in their private capacity.
chuck nasmith said...
1Hillary is Bogus…Hope some have a Bingo with the Bonus!
03/13/15 12:58 PM | Comment Link
John Poole said...
2Hillary knows she’ll eventually need an all encompassing presidential pardon to avoid prison. That is why she needs to be POTUS.
03/13/15 1:09 PM | Comment Link
Rich Bauer said...
3“Where was the State Department’s Diplomatic Security technical security staff?”
Surfing child porn sites apparently.
03/13/15 2:05 PM | Comment Link
chuck nasmith said...
4Stop bashing her. Killary is a grandma, a women.She will nuture U.$. Free Chelsea(and others)!
03/13/15 2:42 PM | Comment Link
wemeantwell said...
5Why does Chelsea Clinton need to be free?
(Kidding, I get it)
03/13/15 2:44 PM | Comment Link
chuck nasmith said...
6(Correction)… She Nouri$he$.
03/13/15 2:45 PM | Comment Link
chuck nasmith said...
7My Bonus statement of the day. Real Patriots will work to have the Patriot Act expire. Go to work or do not pass go,or collect $200, etc..
03/13/15 2:52 PM | Comment Link
Rich Bauer said...
8Talk about a corrupt monopoly:
https://snowdenarchive.cjfe.org/greenstone/cgi-bin/library.cgi
03/13/15 2:54 PM | Comment Link
bloodypitchfork said...
9Peter said:
“For example, the one, single Clinton (unclassified) email that has been released was entirely redacted by the State Department, including Clinton’s personal server email address.”
Oh, haven’t you heard? It’s been high tech “un-redacted”. It was a reply to Bill. It said.. “Listen you no good, cheating, pig sucking lying sack of shit. I’d rather have a ménage à trois with McCain and Bohner before I’d ever fuck you again.”
God I love high tech.
03/13/15 3:39 PM | Comment Link
John Poole said...
10Some ethical cyber Robin Hoods are stealing secrets from the all powerful ruling class in hopes the serfs rebel. They must be baffled why the serfs are very leery of such booty instead of being grateful. Oh, I forgot this is ‘Murika.
03/13/15 3:53 PM | Comment Link
chuck nasmith said...
11MY mug, and last comment for awhile. http://www.Daily.com/news/edward-snowden-rally-nyc-interviews-photos/ Enjoy! Have a nice day. Wage Peace…
03/13/15 4:19 PM | Comment Link
chuck nasmith said...
12-http:// might work or google it. Back to work.
03/13/15 4:26 PM | Comment Link
Lisa said...
13Baba Yaga, redux (arrrgh.)
Can’t we see her decked out in her girl-crush Aung San Suu Kyi Nehru jacket again?
She looked much twinklier and happier then.
03/13/15 8:39 PM | Comment Link
bloodypitchfork said...
14Meanwhile, even our good ole Post Office is keeping track on everyone who visits a post office.
http://kdvr.com/2015/03/11/mysterious-spy-cameras-collecting-data-at-post-offices/
Yes Senator Church, we’ve hit the bottom of the abyss. Sorry…no one listened. But hey…at least …the US doesn’t torture.
We outsource it.
https://firstlook.org/theintercept/2015/03/13/cia-director-explains-u-s-outsources-terror-interrogations/#respond
Ya know..I’m just glad my dad, who, as a member of the PBY crew that discovered the Japanese fleet heading towards Midway during WWll, didn’t live to see the nation he fought for, become a putrid, festering perineal abscess on the ass of humanity.
03/14/15 12:05 PM | Comment Link
Did Spam Filtering Service Have Full Access to Clinton Emails? | Ghosts of Tom Joad - Peter Van Buren said...
15[…] know that Clinton’s server was fully unencrypted for her first three months of overseas travel. It is unclear exactly when after that encryption was […]
03/19/15 1:16 AM | Comment Link
Clinton Lied about Location of Email Server | Ghosts of Tom Joad - Peter Van Buren said...
16[…] noted previously that Clinton’s earliest server ran for three months of her overseas travel without encryption, and that her use of a commercial spam filter service left her emails viewable to that […]
03/20/15 12:28 PM | Comment Link