STRATEGIC MEMORANDUM
SUBJECT: Clinton Email Security Strengths Contrast Federal Security
TO: Interested Parties
FROM: Isaac Wright, Executive Director, Correct The Record
DATE: Wednesday, March 11, 2015
In the recent public debate over former Secretary of State Hillary Clinton’s email practices, two important points must be made clear even as pundits and partisans seek to sensationalize a “security” angle in their public discussions. These fundamental facts should not be overlooked or ceded in discussions: 1) Clinton’s email was secure and 2) the Federal Government’s email systems have experienced noted security problems.
The contrast between the levels of security is striking when examined, even as pundits try to second-guess the level of security of Clinton’s email system.
Clinton’s Email Was Secure
- As Hillary Clinton said of her email system yesterday, “It had numerous safeguards. It was on property guarded by the Secret Service. And there were no security breaches. So, I think that the — the use of that server, which started with my husband, certainly proved to be effective and secure.”
- Clinton’s email was not hacked, even after it was made public by the infamous hacker “Guccifer” discovered it after hacking a separate private account of someone corresponding with Clinton.
- No clintonemail.com messages were included in the Wikileaks incident, unlike thousands of emails from State Department servers.
In Contrast, Federal Government Email Has Noted Security Problems
-
In 2013, the Federal Government incurred almost 61,000 cyber attacks and security breaches.
- Hackers took personally identifiable information about 100,000 people from the Energy Department.
- Hackers took sensitive information about the nation’s 85,000 dams from the Army Corps of Engineers.
- Unclassified White House computer networks were breached by hackers thought to be working for the Russian government.
- Chinese hackers gained access to some of the databases of the Office of Personnel Management.
- Chinese hackers “breached the federal weather network” maintained by the National Oceanic and Atmospheric Administration.
- United States Postal Service computers were hacked, compromising employee information.
- The Nuclear Regulatory Commission reported being hacked three times in recent years.
-
Hacking was an issue at the State Department before Clinton was Secretary of State.
- In 2006, hackers breached State Department security.
- In 2008, a cable outlined “spearphishing” attacks on the State Department by China.
- Hacking continued to be an issue in the Federal Government while Clinton was at the State Department. In 2010, Clinton dealt with the fallout of more than 250,000 stolen State Department cables during the Wikileaks controversy.
- Hacking has continued to be an issue at the State Department. The State Department’s email system was hacked in fall 2014. The State Department continued to weed out hackers three months after the department’s email system was breached.
I have provided more detailed background, below.
Clinton’s Email was Secure
Hillary Clinton: The email system “certainly proved to be effective and secure.” “Well, the system we used was set up for President Clinton’s office. And it had numerous safeguards. It was on property guarded by the Secret Service. And there were no security breaches. So, I think that the — the use of that server, which started with my husband, certainly proved to be effective and secure.” [Hillary Clinton press conference, 3/10/15]
Clinton’s email was not hacked even after it was made public. “Gawker first reported on Clinton’s email address in 2013 and filed a FOIA request for all of the Secretary of State’s correspondence with former Clinton staffer Sidney Blumenthal — whose emails had been hacked by Guccifer — through her personal email address. (Officials have cited the fact that Clinton’s email remained safe during the Blumenthal hack as evidence that her personal email was no less secure than a government-issued one.)” [New York Magazine, 3/3/15]
No clintonemail.com messages were included in the Wikileaks incident, unlike thousands of emails from State Department servers. “I have advocated many times against allowing senior government officials to use personal email accounts and this applies to Secretary Clinton as much as anyone else. It is not secure enough. However, Al Jazeera (not exactly an impartial media outlet when it comes to U.S. foreign policy) contends that State Department email systems were insecure as well. They quote a former presidential innovation fellow, Clay Johnson, as saying that State Department official email was compromised as part of the WikiLeaks/Chelsea Manning debacle. Therefore, he contends, she might have been advised to use her personal email. There is some limited plausibility to that claim, at least in that no clintonemail.com messages were included in the Manning dump, unlike thousands of emails from State Department servers.” [ZDNet, 3/5/15]
U.S. Government was Vulnerable to Hacking
In 2013, the federal government incurred almost 61,000 cyber attacks and security breaches. “There were almost 61,000 cyber attacks and security breaches across the entire federal government last year according to a recent Obama administration report. And the number of cyber incidents involving government agencies has jumped 35 percent between 2010 and 2013, from roughly 34,000 to about 46,000, according to another recent report by the Government Accountability Office.” [CNN, 12/19/14]
- Hackers took personally identifiable information about 100,000 people from the Energy Department. “Last July, hackers hit the Energy Department and took personally identifiable information from more than 100,000 people ‘that could be used to damage the financial and personal interests of many individuals,’ according to a post-mortem report by the department’s inspector general. The data included names; dates and places of birth; social security and bank account numbers; and information about their education and disabilities, according to the report. The hack cost the government almost $4 million in credit monitoring fees and lost productivity.” [CNN, 12/19/14]
- Hackers took sensitive information about the nation’s 85,000 dams from the Army Corps of Engineers. “Another troubling incident happened last January when hackers hit the Army Corps of Engineers and took sensitive information about the nation’s 85,000 dams. That data included their location, condition and potential for fatalities if the dams were to be breached, according to a report by Sen. Tom Coburn, the ranking Republican on the Senate Homeland Security Committee.” [CNN, 12/19/14]
- Unclassified White House computer networks were breached by hackers “thought to be working for the Russian government.” “Hackers thought to be working for the Russian government breached the unclassified White House computer networks in recent weeks, sources said, resulting in temporary disruptions to some services while cybersecurity teams worked to contain the intrusion. White House officials, speaking on the condition of anonymity to discuss an ongoing investigation, said that the intruders did not damage any of the systems and that, to date, there is no evidence the classified network was hacked.” [Washington Post, 10/28/14]
- Chinese hackers “gained access to some of the databases of the Office of Personnel Management.” “Chinese hackers in March broke into the computer networks of the United States government agency that houses the personal information of all federal employees, according to senior American officials. They appeared to be targeting the files on tens of thousands of employees who have applied for top-secret security clearances. The hackers gained access to some of the databases of the Office of Personnel Management before the federal authorities detected the threat and blocked them from the network, according to the officials.” [New York Times, 7/9/14]
- Chinese hackers “breached the federal weather network” maintained by the National Oceanic and Atmospheric Administration. “Hackers from China breached the federal weather network recently, forcing cybersecurity teams to seal off data vital to disaster planning, aviation, shipping and scores of other crucial uses, officials said. The intrusion occurred in late September but officials gave no indication that they had a problem until Oct. 20, said three people familiar with the hack and the subsequent reaction by the National Oceanic and Atmospheric Administration, which includes the National Weather Service. Even then, NOAA did not say its systems were compromised.” [Washington Post, 11/12/14]
- United States Postal Service computers were hacked, compromising employee information. “In classified briefings Oct. 22 and Nov. 7, the U.S. Postal Service told members of Congress that it had been hacked. The service made the information public Monday. The Washington Post reported China may have been involved in the cyberattack, citing anonymous sources. USA TODAY was unable to confirm the report. Postal Service spokeswoman Sue Brennan told USA TODAY the ‘issue is still under investigation.’ In its statement, the post office said some USPS computers were hacked and some employee information was compromised.” [USA Today, 11/10/14]
- The Nuclear Regulatory Commission reported being hacked three times in recent years. “The U.S. Nuclear Regulatory Commission was ‘successfully hacked’ three times in recent years in attacks involving tainted emails, according to an internal investigation on cyber attacks at the agency, Nextgov.com reported on Tuesday. At least two of the attacks originated overseas, according to the report obtained by Nextgov, a rare public report with details of a cyber attack on the energy sector. The publication said it obtained a copy of a report by the NRC’s Office of the Inspector General, which reviewed 17 suspected breaches from 2010 to 2013.” [Reuters, 8/19/14]
The State Department’s email system was hacked in fall 2014. “The U.S. State Department on Monday said its unclassified email systems were the victim of a cyber attack in recent weeks, around the same time as White House systems were breached, but no classified data was compromised.” [Reuters, 11/17/14]
- The State Department continued to weed out hackers three months after the department’s email system was breached. “Three months after the State Department confirmed hackers breached its unclassified email system, the government still hasn’t been able to evict them from the department’s network, according to three people familiar with the investigation. Government officials, assisted by outside contractors and the National Security Agency, have repeatedly scanned the network and taken some systems offline. But investigators still see signs of the hackers on State Department computers, the people familiar with the matter said. Each time investigators find a hacker tool and block it, these people said, the intruders tweak it slightly to attempt to sneak past defenses.” [Market Watch, 2/19/15]
- “Each time investigators find a hacker tool and block it, these people said, the intruders tweak it slightly to attempt to sneak past defenses.” “Government officials, assisted by outside contractors and the National Security Agency, have repeatedly scanned the network and taken some systems offline. But investigators still see signs of the hackers on State Department computers, the people familiar with the matter said. Each time investigators find a hacker tool and block it, these people said, the intruders tweak it slightly to attempt to sneak past defenses.” [Market Watch, 2/19/15]
In 2013, the addresses of over 170 employees were released following a hack of the State Department system. “Who’s hacking: Anonymous What’s happening: Anonymous pointed to its Operation Last Resort Arm as it announced a hack of the State Department, releasing the addresses of over 170 employees in the name of what it’s calling the US government’s ‘war on whistleblowers’, like hacker Aaron Swartz.” [Guardian, 2/20/13]
In 2010, Clinton dealt with the fallout of more than 250,000 stolen State Department cables the Wikileaks controversy. “If the hyperconnectivity of the networked world played to America’s strengths and offered opportunities to exercise smart power to advance our interests, it also presented significant new challenges to our security and our values. This became painfully apparent in November 2010, when the online organization WikiLeaks and several media outlets around the world began publishing the first of more than 250,000 stolen State Department cables, many of which contained sensitive observations and intelligence from our diplomats in the field. A junior military intelligence officer stationed in Iraq, Private Bradley Manning, downloaded the secret cables from a Department of Defense computer and gave them to WikiLeaks and its Australian leader, Julian Assange. Some celebrated Manning and Assange as champions of transparency who were carrying on a noble tradition of exposing government wrongdoing, comparing them to Daniel Ellsberg’s leaking of the Pentagon Papers during the Vietnam War. I didn’t see it that way. As I said at the time, people of good faith understand the need for sensitive diplomatic communications, to protect both the national interest and the global common interest. Every country, including the United States , must be able to have candid conversations about the people and nations with whom they deal. And the thousands of stolen cables generally showed America’s diplomats doing their jobs well, often in difficult circumstances.” [Hard Choices, 2014]
- Gates, on WikiLeaks: “Clinton had a lot of explaining to do in capitals around the world for a problem caused by the Defense Department.” “[Because of Wikileaks] Secretary Clinton had a lot of explaining to do in capitals around the world for a problem caused by the Defense Department. Both she and I noticed that once open and candid interlocutors around the world now turned silent the second they saw an American official take out pen and paper for notes.” [Gates, Robert M (2014-01-14). Duty: Memoirs of a Secretary at War (Kindle Locations 7757-7759). Knopf Doubleday Publishing Group. Kindle Edition.]
- No clintonemail.com messages were included in the Manning dump, unlike thousands of emails from State Department servers. “I have advocated many times against allowing senior government officials to use personal email accounts and this applies to Secretary Clinton as much as anyone else. It is not secure enough. However, Al Jazeera (not exactly an impartial media outlet when it comes to U.S. foreign policy) contends that State Department email systems were insecure as well. They quote a former presidential innovation fellow, Clay Johnson, as saying that State Department official email was compromised as part of the WikiLeaks/Chelsea Manning debacle. Therefore, he contends, she might have been advised to use her personal email. There is some limited plausibility to that claim, at least in that no clintonemail.com messages were included in the Manning dump, unlike thousands of emails from State Department servers.” [ZDNet, 3/5/15]
In 2008, a cable outlined “spearphishing” attacks on the State Department by China. “While the Obama administration has never publicly discussed the Chinese unit’s activities, a secret State Department cable written the day before Barack Obama was elected president in November 2008 described at length American concerns about the group’s attacks on government sites. (At the time American intelligence agencies called the unit ‘Byzantine Candor,’ a code word dropped after the cable was published by WikiLeaks.) The Defense Department and the State Department were particular targets, the cable said, describing how the group’s intruders send e-mails, called ‘spearphishing’ attacks, that placed malware on target computers once the recipient clicked on them. From there, they were inside the systems.” [NY Times, 2/18/13]
In 2006, hackers breached State Department security. “The State Department is recovering from large-scale computer break-ins worldwide over the past several weeks that appeared to target its headquarters and offices dealing with China and North Korea, The Associated Press has learned. Investigators believe hackers stole sensitive U.S. information and passwords, said U.S. officials familiar with the hacking. Whoever did the hacking reportedly tried to leave so-called back doors so they could come back later and keep intruding into the computers, CBS News correspondent Jim Stewart reports.” [CBS News, 7/11/06]
- A.P. Headline: “Hackers used e-mail to break into State Department computers.” “A break-in targeting State Department computers worldwide last summer occurred after a department employee in Asia opened a mysterious e-mail that quietly allowed hackers inside the U.S. government’s network. In the first public account revealing details about the intrusion and the government’s hurried behind-the-scenes response, a senior State Department official described an elaborate ploy by sophisticated international hackers. They used a secret break-in technique that exploited a design flaw in Microsoft software. Consumers using the same software remained vulnerable until months afterward. Donald R. Reid, the senior security coordinator for the Bureau of Diplomatic Security, also confirmed that a limited amount of U.S. government data was stolen by the hackers until tripwires severed all the State Department’s Internet connections throughout eastern Asia. The shut-off left U.S. government offices without Internet access in the tense weeks preceding missile tests by North Korea.” [“Hackers used e-mail to break into State Department computers,” AP, 4/19/07]
