4 ms·
“Typo leak” exposes millions of US military emails to Mali web operator
- nouryqt 3y agohttps://archive.is/0vhxP https://archive.is/0vhxP
- nubinetwork 3y ago> Zuurbier has been collecting misdirected emails since January in an effort to persuade the US to take the issue seriously. He holds close to 117,000 misdirected messages — almost 1,000 arrived on Wednesday alone. In a letter he sent to the US in early July, Zuurbier wrote: “This risk is real and could be exploited by adversaries of the US.” > Control of the .ML domain will revert on Monday from Zuurbier to Mali’s government, which is closely allied with Russia. When Zuurbier’s 10-year management contract expires, Malian authorities will be able to gather the misdirected emails. The Malian government did not respond to requests for comment. Oops.
- trustingtrust 3y agoA temporary solution would be to block all traffic of email to ml domain on computers and vpn used by the military and respond with an error. If anyone outside military computers and emails is sending such classified information this is a bigger problem and not just a typo issue. Update: missed the part that this is incoming emails problem from non military.
- gilbertbw 3y agoIt sounds like they already do: > He said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”. One of the examples is a hotel booking confirmation, which would come from a third party.
- devrand 3y agoAccording to the article the issue is non-military originating emails. They used an example of a doctor’s office sending x-rays to a patient but mistyped the TLD.
- ElectricalUnion 3y agoWeird because the USA top level domain is supposed to be .us, with that being one of the first country code top level domains.
- jabroni_salad 3y agoIt's my understanding that .gov and .mil were brought over from when those were independent networks, pre-internet.
- hgsgm 3y agoNow do .com, .org, and .net, which are all part of US.
- richij 3y agoNo they're not.
- eindiran 3y agoFrom Wikipedia for .com: > The domain was originally administered by the United States Department of Defense, but is today operated by Verisign, and remains under ultimate jurisdiction of U.S. law. .edu holds US-centric requirements today. Not sure about .org, .net, etc. [0] https://en.wikipedia.org/wiki/.com https://en.wikipedia.org/wiki/.com [1] https://en.wikipedia.org/wiki/.edu https://en.wikipedia.org/wiki/.edu
- lolinder 3y agoThis is still a valid suggestion because a lot of the emails are from long-running government contractors. They may not be able to solve all of them, but requiring government contractors to block .ml domains in their email systems would be a start.
- TazeTSchnitzel 3y agoIf .mil is typoed to .ml (Mali), I suppose it's also typoed to .il (Israel), but I imagine that worries the DoD less.
- hamster77 3y ago[flagged]
- ActionHank 3y agoFWIW that didn't read as particularly negatively. US and Israel are military allies, they would worry less about this sort of leak.
- skellyclock 3y agoIsrael used to be listed as an advanced persistent threat against the United States.
- slavboj 3y agoIsrael conducts a large amount of spying on the USA and exports a large volume of military tech to China, but for domestic political reasons the DoD likes to ignore them as a threat.
- hgsgm 3y agoIsrael spies for its own interests, which, per US gov foreign policy, align with US interests. Similar to France and UK.
- Spooky23 3y agoIsrael’s interests wrt the US are complicated. Israeli politicians campaign in the US. There’s a lot of mutual personal, commercial and government interests between the two countries that often are out of alignment with official positions. France also has a complicated relationship and does more adversarial spying.
- 3y ago
- Am4TIfIsER0ppos 3y agoConspiracy theory time: deliberate acts to provide Casus Belli for American invasion. Along the lines of Colin Powell's vial of anthrax at the UN or the "baby incubators" statements from a Kuwaiti princess a decade earlier. The article states "closely allied with Russia" and the current establishment desires to punish anyone who doesn't distance themselves from Russia. The emails might be nothing sensitive to the state but they can just lie and say "Mali is deliberately intercepting emails meant for the military". Well that wouldn't even be a lie because someone did set up something to catch emails going to dot-ml which were meant for dot-mil. A nice war helps also helps with elections at home.
- boveus 3y agoI would put my money on a junior enlisted / junior officer not paying attention when they type the email to book their hotel over a government conspiracy to generate a Casus Belli to invade Mali of all places.
- causi 3y agoWhy would the US want to invade Mali?
- Eumenes 3y agoChyna
- deleted 3y ago[deleted]
- JEDI-HACKER 3y ago[dead]
- jpoesen 3y agoMali's a Daesh hotbed. Mali has been close to Russia politically, culturally, economically, and militarily since the 1960's. Mali's welcomed Russian troops, including Wagner's, in the wake of the French pulling out. "[The Russian involvement in Mali] signals a major expansion of Russia's military interests in Africa and a strategic setback for the West. The deployment of Russian military contractors signals a profound break with France and the West." https://www.bbc.com/news/world-africa-58751423 https://www.bbc.com/news/world-africa-58751423 https://www.reuters.com/world/africa/un-security-council-ends-peacekeeping-mission-mali-2023-06-30/ https://www.reuters.com/world/africa/un-security-council-end... https://www.chathamhouse.org/2021/12/russias-presence-mali-raises-concerns https://www.chathamhouse.org/2021/12/russias-presence-mali-r... https://en.wikipedia.org/wiki/Mali%E2%80%93Russia_relations https://en.wikipedia.org/wiki/Mali%E2%80%93Russia_relations
- globalise83 3y agoNot sure much can be done here short of the US Government hijacking the .ml domain altogether via ICANN, which, if even achievable, would probably cause worse side-effects than the leaking of low-grade intelligence to Mali. Probably the best partial mitigation would be to make it a condition of doing business with the military to put a blocker on all emails to .ml domain, and for all partner militaries to do the same. Still won't prevent every instance, but they can probably prevent 80% of the most sensitive emails by doing this for 20% of people who communicate with them.
- deleted 3y ago[deleted]
- hgsgm 3y agoThe average business has no idea how to install a blocker like that. The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs. Or continue not caring about spying on random unclassified information.
- lolinder 3y agoThe average business uses G Suite or MS Office, and I'm sure that they could find the right setting if their government contract were dependent on it. That's a heck of a lot easier to pull off than migrating >1.4 million military personnel to a new email address.
- htrp 3y ago@dang.... should probably correct the title to say Typos vs Typo The current title implies that its a single keystroke misconfiguration that is causing this when instead it's lots of people just not typing the e-mail correctly.
- lolinder 3y ago@dang is a no-op, you need to email hn@ycombinator.com to recommend a change. That said, this is the original title and it makes sense to me—it's a single typo repeated many times over.
- hombre_fatal 3y agoI also read it like they did but at the same time this granularity of title management doesn’t make sense since it wastes time optimizing for people who want to comment without reading the article.
- deleted 3y ago[deleted]
- GoblinSlayer 3y agoIf those emails weren't encrypted, they weren't secret.
- paulddraper 3y agoOk thanks. But let's be real...There's a difference between having unsecured packages on your doorstep and sending packages to another address entirely.
- gonzo41 3y agoThe real secret is how any military is able to be effective under the crushing weight of the bureaucracy it seems to build around itself.
- taeric 3y agoI mean, you aren't wrong; but opsec covers things that are not necessarily secret. Just look up news on strava leaks.
- neilv 3y agoThe cause isn't just a "typo". Sounds like they went to effort to set up DNS MX records and SMTP servers for domains like `army.ml`. Also, not only did they set up something specifically to capture the emails that they knew weren't intended for them (incidentally preventing the senders' own SMTP servers from alerting the senders of the problem almost immediately), but... it sounds like they also examined the content of some of the diverted emails that they knew were sensitive and not intended for them. I can't tell from the article whether they've finally disabled this diversion of the emails. Nor whether they had a plan to scrub all copies of the emails before it's out of their control, maybe offering US diplomats/officials a deadline to get a copy if they want it Also, if they're now acting in good faith, and interfacing with US officials, I wonder who leaked this situation to the press, and why.
- moonraker 3y agoIt's impossible to know but I imagine a press leak (and further coverage by cable news and other traditional print media outlets) is the only way that members of Congress would actually care enough to hold members of the military and Department of Defense accountable so that they'll eventually find a way to resolve the issue. Whether that'll take the form of a software engineering solution or a "social engineering" solution - in the form of Congressional hearings and the like - remains to be seen.
- fanf2 3y agoThey aren’t being at all subtle about it, for example: ;; ANSWER SECTION: navy.ml. 300 IN MX 0 handle.catchemail.ml. army.ml. 300 IN MX 0 handle.catchemail.ml. Very unethical way to handle sensitive data.
- morpheuskafka 3y agoUnethical? Why should Mali have an ethical duty to respect military or intelligence of a foreign country with no alliance that could easily be their enemy some day?
- screamingninja 3y agoThe title gives the impression that one typo led to the leaking of millions of emails from the US military servers, which is not the case here. - Presumably each typo led to one leak. "Typos leak emails" would be more appropriate in that case. - Are they really "US military emails" if they originated from elsewhere and one of the intended recipients was on the '.mil' domain? Apparently "emails sent directly from the .mil domain to Malian addresses are blocked before they leave the .mil domain".