NSA chief leaks info on data sharing tech: It's SharePoint

Spies really are just like us


The NSA has admitted that the organization's use of Microsoft SharePoint allowed an unnamed sysadmin to leak information.

In what can be perceived as either a ringing endorsement of SharePoint's "collaborative power", or a depressing admission that, yes, spooks use the same infuriating software as we do, NSA chief General Keith Alexander indicated recent leaks came from a sysadmin being given SharePoint privileges.

"This leaker was a sysadmin who was trusted with moving the information to actually make sure that the right information was on the SharePoint servers that NSA Hawaii needed," Alexander says in response to a question by The Washington Post about the threat of insider leaks given the Buckshot Yankee penetration in 2008 and WikiLeaks, which we take to be a reference to the Hawaii-based mega-leaker Edward Snowden.

The leaks represented "a huge break in trust and confidence," Alexander said, who currently leads an organization famed for its various unpopular programs that monitor the communications of basically everyone in the world, and intercept communications at any time in any place for reasons that are never stated.

Keith "break in trust and confidence" Alexander proceeded to observe that the fact a sysadmin was able to then distribute this SharePoint info outside of the NSA meant that "there's issues we've got to fix there."

The problem, Alexander noted, is that after 9/11 the NSA had a "need to share" information with other agencies about threats. (This sharing did not and has not extended to the American civilians whom the NSA is meant to guard rather than spy on.) The leader of the mass interception organization pointed to measures the NSA is introducing to make sure that sysadmins cannot leak information to the public, such as working in pairs and making it difficult to download information.

But this could be difficult. "As you may know, sysadmins need removable media to do their job," Alexander said. We reckon moving off of SharePoint could be a start, especially since research into attacking the software was due to be presented at this year's DEF CON conference. ®

Similar topics


Other stories you might like

  • Software Freedom Conservancy sues TV maker Vizio for GPL infringement

    Companies using GPL software should meet their obligations, lawsuit says

    The Software Freedom Conservancy (SFC), a non-profit which supports and defends free software, has taken legal action against Californian TV manufacturer Vizio Inc, claiming "repeated failures to fulfill even the basic requirements of the General Public License (GPL)."

    Member projects of the SFC include the Debian Copyright Aggregation Project, BusyBox, Git, GPL Compliance Project for Linux Developers, Homebrew, Mercurial, OpenWrt, phpMyAdmin, QEMU, Samba, Selenium, Wine, and many more.

    The GPL Compliance Project is described as "comprised of copyright holders in the kernel, Linux, who have contributed to Linux under its license, the GPLv2. These copyright holders have formally asked Conservancy to engage in compliance efforts for their copyrights in the Linux kernel."

    Continue reading
  • DRAM, it stacks up: SK hynix rolls out 819GB/s HBM3 tech

    Kit using the chips to appear next year at the earliest

    Korean DRAM fabber SK hynix has developed an HBM3 DRAM chip operating at 819GB/sec.

    HBM3 (High Bandwidth Memory 3) is a third generation of the HBM architecture which stacks DRAM chips one above another, connects them by vertical current-carrying holes called Through Silicon Vias (TSVs) to a base interposer board, via connecting micro-bumps, upon which is fastened a processor that accesses the data in the DRAM chip faster than it would through the traditional CPU socket interface.

    Seon-yong Cha, SK hynix's senior vice president for DRAM development, said: "Since its launch of the world's first HBM DRAM, SK hynix has succeeded in developing the industry's first HBM3 after leading the HBM2E market. We will continue our efforts to solidify our leadership in the premium memory market."

    Continue reading
  • UK's ARIA innovation body 'hasn't even begun to happen' says former research lead

    DARPA imitator not doing much after two years of Johnson government

    Updated The UK's efforts to copy US government and military innovation outfit DARPA are stalling, according to a leading figure in research and development.

    Appearing before the Science and Technology Committee, Sir John Kingman, former chair of UK Research and Innovation, told MPs this morning that ARIA – the Advanced Research and Invention Agency – was a good example of departmental research spending that could be cut, sidelined or delayed.

    "A very high-profile example would be ARIA, which has been this big plan for the Boris Johnson government, and yet here we are a few years into the Johnson government and it still hasn't even begun to happen," he told MPs.

    Continue reading

Biting the hand that feeds IT © 1998–2021