You are only browsing one thread in the discussion! All comments are available on the post page.

Return

SugarApplePie ,
@SugarApplePie@beehaw.org avatar

Emails sent from the .MIL domain to the .ML addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients," Gorman said.

So they aren’t actually making it to the .ml addresses? I can’t tell if I’m not understanding something properly or someone is lying or what

middlemuddle ,

That’s only for emails sent from the .mil domain. Emails sent from other domains don’t have the same filters in place. The issue is that plenty of other domains are attempting to send emails to the .mil domain and are actually sending to the .ml domain. The article only confirms a filter is in place for .mil users, so it’s entirely possible that .gov users have no such filter. Plenty of government workers with .gov domains would be trying to send sensitive info to .mil users. Or government contractors, who would have a whole bunch of possible domains, would be trying to send to the .mil domain and failing.

It’s a pretty big, and stupid, breach, but I’m not sure how you get everyone who’s not part of your closed system to ensure they’re typing out .mil correctly.

jarfil ,
@jarfil@beehaw.org avatar

What I don’t get, is why would anyone send any sensitive info unencrypted.

middlemuddle ,

That wouldn’t really make a difference here, I don’t think. A standard encrypted email just ensures that only the intended recipient can open it. Since the addressed recipients were the .ml domain, the emails would still be accessible by the wrong people.

jarfil ,
@jarfil@beehaw.org avatar

Email encryption is kind of broken, but kind of in a good way: if you don’t have the recipient’s key, then you can’t send an encrypted email. Since there would be no reason for senders of sensitive info intended for .mil receivers, to have the key for an equivalent receiver at a .ml domain, the emails would just fail to send, stopping any leak before it happened.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • [email protected]
  • All magazines