16 votes

The CIA's communications with sources suffered a catastrophic compromise from 2009 to 2013

2 comments

  1. [2]
    Deimos
    Link
    This is a pretty remarkable article from last week, I didn't realize that Yahoo News was doing any journalism like this. The most interesting part to me: There are some potential ways of...

    This is a pretty remarkable article from last week, I didn't realize that Yahoo News was doing any journalism like this.

    The most interesting part to me:

    In fact, the Iranians used Google to identify the website the CIA was using to communicate with agents. [...] ...once the Iranian double agent showed Iranian intelligence the website used to communicate with his or her CIA handlers, they began to scour the internet for websites with similar digital signifiers or components — eventually hitting on the right string of advanced search terms to locate other secret CIA websites. From there, Iranian intelligence tracked who was visiting these sites, and from where, and began to unravel the wider CIA network.

    There are some potential ways of identifying related sites by looking for common unique components shared between the sites' HTML/JS/CSS. I've done some things like this myself in an anti-spam context in the past, and I can absolutely see it being a vulnerability that wasn't recognized.

    8 votes
    1. sublime_aenima
      Link Parent
      I started laughing when I read that last week since the Iranians just had a bunch of propaganda sites and accounts banned across lots of social media. Seems the new group forgot to learn from the...

      I started laughing when I read that last week since the Iranians just had a bunch of propaganda sites and accounts banned across lots of social media. Seems the new group forgot to learn from the past.

      2 votes