Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Justin Schuh

@jschuh@infosec.exchange
  • Open on infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

0 Followers
0 Following
25 Posts
Joined November 07, 2022
Twitter:
https://twitter.com/justinschuh
Github:
https://github.com/jschuh
Bluesky:
https://bsky.app/profile/justinschuh.com

Posts

Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jan 03, 2026
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @agl@infosec.exchange
@agl@infosec.exchange As I said elsewhere, I'm really going to miss the Pax Americana. I won't deny that it was imperfect and unevenly distributed. But damn, it sure seems a whole lot better than whatever this thing is that we're blindly stumbling into.
10
0
3
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Oct 26, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @troed@ioc.exchange
@troed@ioc.exchange Turns out the attacker initiated account recovery over the phone using stolen personal information. The link was the last step, which had to be clicked from a device Amazon already recognized for that account. And the firehose of spam was to bury the alert emails Amazon was sending.
2
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Oct 26, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @jschuh@infosec.exchange
Gmail account appears to be fine, but the Amazon account has definitely been hijacked. Looks like the attacker texted a link that the neighbor clicked on this morning, and that completed some sort of account ownership transfer. Neighbor assures me they just clicked the link and didn't enter anything. They just landed on an Amazon page that said their account had been successfully transferred to someone else (they have a screenshot of the hijacker's email address). They've been on the phone with Amazon trying to get it resolved, but if the description is correct it sure seems like there's a vulnerability on Amazon's end here. At exactly the same time the SMS was sent the neighbor's Gmail account got hit with a firehose of thousands of spam messages persisting for several hours, which is why they thought the Gmail account was hacked (and also why they clicked the Amazon phishing link from the SMS). Does this sort of thing sound familiar to anyone?
3
2
3
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Oct 26, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

Neighbor just called asking for help because their Gmail account was hijacked and now they're locked out (and the hijacker chained off that to other accounts). I'm heading over in a bit to help. This is the will be my first experience with the process from the consumer perspective.

12
4
1
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Oct 05, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@fugueish@wandering.shop Indeed.

0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Oct 05, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@fugueish@wandering.shop I have thoughts... that I'm going to keep to myself.

1
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jul 01, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @AlesandroOrtiz@infosec.exchange
@AlesandroOrtiz@infosec.exchange Thing is I have no interest in changing my email provider or adding new services. I'm really just looking for a drop-in replacement for my domain service.
0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jul 01, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @sgraham@mstdn.social
@sgraham@mstdn.social Thanks. I'll take a look at it.
0
0
1
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jul 01, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@_dm@infosec.exchange Yeah, looking for more of a drop-in replacement in a single service.

infosec.exchange

dm (@_dm@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 30, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

I just determined that plus addressing on email forwards broke with the transition from Google Domains to Squarespace (i.e. forwarding foo@bar.com to myfoobar@gmail.com used to also forward foo+tag@bar.com to myfoobar+tag@gmail.com). This means I'm now missing a bunch of emails, because as a general rule I would create a custom plus address with a relevant tag anytime I registered an email.

So now I'm wondering if anyone has thoughts on a way to get this working in Squarespace. I added a wildcard email rule as a stopgap, but even that requires 24-48 hours to take effect.

Alternatively, does anyone have any good recommendations on domain hosting providers that support email forwarding with plus addressing?

5
5
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 07, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

Anyone familiar with truv.com for employment verification? All I know so far is that it bootstraps off an HTTP URL with a massive unique identifier (of course you get a cert error if you try to force HTTPS). That just takes you to a landing page, which requires installing an app to do literally anything.

Seems kinda concerning that a one-time event like employment verification would require installing an app. And then there's the obvious question of why they have an app at all, since you're not going to be pinging payroll providers from on-device.

The whole thing just seems insanely sketchy.

4
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · May 22, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @parkern@infosec.exchange
@parkern@infosec.exchange Yeah, I assume that's going to be the argument, but in practice I think that's kinda garbage (hence my "wrong-headed" comment above). The design still requires Apple to get a running history of coarse location data. Plus the devices are constantly pinging cell towers. And with some regularity they have to send back fine-grained data to Apple, just to refresh their global WPS database. So, in practice I can't imagine there's any real privacy benefit to the Apple customers, and the tradeoff is a huge privacy compromise for literally everyone else. It's just a very destructive form of privacy narcissism.
0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · May 22, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @parkern@infosec.exchange
@parkern@infosec.exchange Wow... this one is just... wow. I'm assuming it was either debugging/bootstrapping behavior that got left in. Or maybe it was a very wrong-headed "privacy" scheme where iPhones will beacon back to Apple less because they calculate a fix based on Apple sharing everyone else's location information publicly. But damn, it's still surprising to see something like this, and they must have been doing it for years.
2
1
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Apr 19, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@_dm@infosec.exchange It seems like we're both at a similar place on this. No easy answers. And no good way to influence the parties with real agency in the conflict.

Honestly though, it's refreshing to be in a conversation where I'm not getting labelled either "genocidal" or "antisemitic," just because I'm not comfortable with any of the grossly oversimplified positions.

Thanks for that.

infosec.exchange

dm (@_dm@infosec.exchange) - Infosec Exchange

1
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Apr 19, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@_dm@infosec.exchange Don't want to belabour the point on the protest itself. I'll just say that I agree they were very successful at getting press coverage, but I doubt they get any substantive change from it, and it's unclear to me what they were even trying to accomplish.

Resurrecting my ~20yr old government contracting memories:

1. I can't say anything is impossible, but I just cannot square IDF opsec/classification with allowing any of that sort of activity on a cloud provider. Accepting that, I think you may be underestimating the degree to which Israel can afford to host their own specialized capability on air-gapped networks (or rely on the US providing it).

2. Agree on the BDS movement, which is at least morally and logically consistent in this case. But then they should just come out and say it so that debate can be aired.

FWIW, even though I completely support Israel's right to exist, I'd say I'm anti-zionist and have plainly referred to it as an apartheid state for maybe a decade now. Although, I've generally made pains to distinguish it in degree from e.g. South African apartheid or Jim Crow.

I've also historically been against BDS because I thought there were more effective ways to end the apartheid. But as the situation gets increasingly worse I'm definitely less confident in that position.

infosec.exchange

dm (@_dm@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Apr 19, 2024
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

@_dm@infosec.exchange Agreed on the first part. This is the predictable outcome of civil disobedience. And while I have my own thoughts on the effectiveness of their approach, I regardless respect their conviction to do it.

Regarding Nimbus, it just looks like a generic cloud services contract with the Israeli government. And there's no world in which the Israeli military lets anything remotely operational sit on cloud services—it's just too much of an opsec risk.

But governments are complex interlinking collections of organizations. So, if you're providing generic cloud services in an omnibus contract, you're gonna get all manner of administrative and support data, including from military, law enforcement, etc. So, I expect there's a very fuzzy line here that people are interpreting differently based on where they're coming from.

(Side note: I do not miss my days of having to be aware of government contracting.)

infosec.exchange

dm (@_dm@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 25, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @opendna@mastodon.sdf.org
@opendna@mastodon.sdf.org Thanks, I appreciate that. And yes, it's been maddening to watch all this and continue having the same conversation since it all started back in 2015. The media coverage has been awful, and there's been no shortage of politicians and former IC personnel asserting things that are just patently untrue.
1
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 24, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @opendna@mastodon.sdf.org
@opendna@mastodon.sdf.org No. It doesn't matter if you're the original classification authority or not. You've still broken the law if you didn't follow the mandated process in EO 13526 for handling classified material. That's literally what Deutch and Petraeus both got charged for—even though they were the respective classification authorities for the marked material that they leaked. But as I explained in the original post, none of that applied to Clinton. I don't care about the non sequiturs regarding her schedule. The critical detail in her case is that she forwarded emails from a FOUO system—which by definition does not handle classified material. Thus her use of a personal email account was never relevant in any discussion of potential mishandling of classified material, and she in fact had a reasonable assumption that no classified material would be present in the emails she received. That's why I noted that her case barely had anything at all to do with handling of classified material. And I honestly don't care what's been claimed by supposed former IC personnel. The vast majority of commentary around this has been blatantly wrong the whole time. That's why I wrote a post explaining the facts of the situation.
2
1
1
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 24, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @opendna@mastodon.sdf.org
@opendna@mastodon.sdf.org EO 13526¹ literally designates the classification authorities and defines the "uniform system for classifying, safeguarding, and declassifying national security information" that they all must comply with. Your whole premise that “each department has its own Classified system” is just pure nonsense, and the rest of your comments are a bit of non-sequitur plus implicit admission that you didn’t actually read the post you’re replying to. This rampant sort of confidently-wrong-reply-guy bullshit is why Mastodon has never really clicked with me. It's also why I won’t be wasting any more of my time in a back and forth over this. _ ¹ https://obamawhitehouse.archives.gov/the-press-office/executive-order-classified-national-security-information
0
1
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 16, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @uptill3@hacked.af
@uptill3@hacked.af Sorry, but that's all just a bit nonsensical. As I explained in the original post, the EO lays out the classification framework, and the courts rely on that framework to delineate violations of the law. The law also lays out some basic foundations (notably intent) and hits constitutional limits, which is why random people don't get prosecuted for handling publicly leaked classified. However, go take a look at the active case against Julian Assange, who's facing a whole raft of Espionage Act charges specifically for his active involvement in leaking classified. As for why congress doesn't need clearances to access classified, it's because EO 12333 specifically exempts them, in favor of directly managing their access (anything else would be an administrative nightmare). However, the whole reason why the Gravel v. United States precedent exists is because the DoJ was quite serious about charging Gravel and his aide under the Espionage Act for mishandling classified. Anyway, I'm kinda getting the impression I'm being trolled here. So, I'm just going to leave it at this, and respond no further.
6
1
1
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 16, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @uptill3@hacked.af
@uptill3@hacked.af I'm not sure why you have that impression, but none of that is correct. EOs are often a critical step in executing laws, and at present neither the relevant EOs nor the underlying statute make exceptions for elected officials. The DoJ does have a policy against charging a sitting president for anything, and it would be very difficult to prove an Espionage Act case against a former president for any actions they took while in office. That's why they're charging Trump only for what he did after leaving office. But there's no law, and nothing in the constitution that forbids it. The courts have also found certain applications of the Espionage Act to be unconstitutional. So, perhaps you were thinking of Gravel v. United States (1972), which held that the "Speech or Debate" clause indemnifies members of both houses for statements made from the floor, while in session. But that's actually a very narrow exception, and in any other context the liability for them is the same as anyone else. As for why NARA likely hasn't retrieved all the documents yet, it's because they still don't know exactly what Trump has and where. If they knew that, I'm sure they would have already raided every location and grabbed everything. But since Trump is a former president they're being extremely cautious and giving him an unprecedented level of deference. Were it anyone else he'd already be incarcerated, and likely giving up the remaining documents in hopes of some additional leniency on his sentence.
6
1
2
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 16, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @Nonya_Bidniss@mas.to
@Nonya_Bidniss@mas.to I was framing the common case for most installations that house SCIFs. I've also spent time in SCIFs with less typical forms of 24/7 monitoring and security, but I didn't see a point in getting that deep into the weeds.
2
0
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Jun 16, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange

The Difference Between How Trump, Biden, Pence, and Clinton Mishandled Classified Information

I should first state where I’m coming from (because #IANAL). I served in the US intelligence community from 1996-2004, first as an enlisted Marine, and then as a federal employee at NSA and later CIA. I worked on watchfloors and did ops, but most of that career was spent managing and/or securing classified systems. I was trained at the Fort Washington¹ facility in qualifying SCIFs², had my classified courier card for years, and in my time saw a few classified mishandling cases up close.

Next is a bit of background on how classified information handling works. In the 99.99% case, classified docs are only ever handled in SCIFs (which have fence-lines and armed guards). Printed documents are marked with their classification level, and when not in use everything is locked in a properly rated safe, managed with access logs. Classified computer systems are rated to the maximum level of classified allowed, and also secured when not in use. Systems at different classification levels are air-gapped to prevent leakage (technically it’s more complicated, but accurate for this discussion).

The last bit of background is the legal framework for classified document handling. There actually is no law defining classified information or handling processes. Rather, there’s the 1917 Espionage Act³, plus 100 years of legal precedent and executive orders (most recently EO 13526⁴). The Espionage Act refers to a very broad category of “information respecting the national defense” and makes illegal the dissemination of this information through either “willful intent” or “gross negligence.”

The key point is that the law applies to a broad category of information, and the EOs build a framework for identifying such information and how to securely handle it. This is also the main basis that the courts use to delineate violations of the law, which is why classified mishandling is prosecuted under the Espionage Act.

With all of that out of the way, it’s time to look at each of these cases of classified mishandling. I’ll start with Clinton’s case first, because it’s the weirdest, in that it only barely involves classified data handling. That might seem confusing given all the press coverage in 2016, but the most accurate description of what Clinton did is that she forwarded emails from her official DoS (Department of State) email account to a personal account. The critical thing here is that because her DoS account was on a FOUO (For Official Use Only⁵) system, directly connected to the public Internet, those emails never should have contained any classified information. FOUO systems may contain sensitive information, but are explicitly not for handling classified information.

Accepting that, sometimes classified information leaks to a FOUO system. This tends to happen one of two ways, the first of which is usually in preparing briefings/reports for a lower classification level. It’s common to pull some of that information from classified documents, declassify as needed, and then transfer that to a lower classification system. Sometimes mistakes are made in this process and (now invalid) classification markings are left in the downgraded document. That explains the classification markings found in a few of Clinton’s emails⁶.

Classified information can also leak without being marked, if the substance of discussion simply includes information that would be considered classified. This is why it was reported that Clinton had 2,100 classified email threads⁷. Because, all of her emails were sent to the classification authorities at all of the intelligence agencies, and they reviewed everything, flagging anything they would have viewed as classified. FWIW, I doubt that any senior national security official’s FOUO inbox would make it through this process without coming away similarly flagged (but that's its own very long discussion).

With that context, here’s the first critical thing to understand about Clinton’s emails: The classified information leak was independent of her forwarding her official email to her personal email address. This is because any classified information she received was already leaked on the FOUO systems that the emails were coming from. So, the classified mishandling situation is the same regardless of whether Clinton’s email had remained on the FOUO DoS server or on a machine in Clinton’s basement. Neither are authorized for handling classified information.

So, then what was wrong with Clinton forwarding her FOUO emails to a personal address? Mainly it comes down to the government’s obligations regarding records retention and the mandatory security baseline for the systems they manage. Those are both extremely good reasons for why Clinton shouldn’t have forwarded her emails, but they don’t really have anything to do with classified information handling.

And to be fair to Clinton, since she was using a FOUO system, she had a reasonable expectation that she wasn’t receiving any emails containing classified information. So, unless she personally introduced the classified information into the discussions that got retroactively flagged, it’s entirely possible that she never even mishandled classified herself. Rather, she may have simply had additional copies of emails that had already leaked to FOUO systems. (FWIW, I don’t expect to ever find out the answer to this.)

This gets to the legal repercussions of what Clinton did. Once again, IANAL, but I did see cases of similar infractions. And as long as the offending party cooperated, there was very little in the way of repercussions. About the worst case would be junior enlisted getting slapped with non-judicial punishment⁸ because their commander wanted to make an example of them. But outside of that, pretty much anyone else in the same situation would just be told to stop, or at worst get a minor slap on the wrist.

Either way, I cannot imagine what grounds someone could even be prosecuted over if they're simply forwarding emails from a FOUO account, to their personal account, for the purposes of accessing their email from another device. Moreover, the scope and depth of the Clinton investigation would normally have been reserved for someone stealing actual marked classified information or otherwise bridging classification levels between systems. Clinton genuinely received more scrutiny and greater repercussions than pretty much anyone else in her situation would have. None of this is to say that what Clinton did was a good thing, but it genuinely was far less than it's usually made out to be.

Now, on to Biden and Pence, which are nearly identical cases of classified mishandling. Remember several paragraphs back about the 99.99% case? Well, that’s not the White House, because that place is just weird. It has a mess of spaces cleared for handling classified, and uncleared people endlessly circulating about—some of whom literally live there! The whole thing is a security nightmare, and they should ban printed classified just as a precautionary measure.

That’s why I’m not surprised that Biden and Pence wound up with marked classified papers mixed in with their other documents. TBH I’m surprised it doesn’t happen more often. But that sort of thing is also why the statute sets the bar at “willfully” or “negligent.” Both Biden and Pence did exactly the right thing in notifying the appropriate custodian of the mistake, turning over everything, and complying fully with investigations. It was all by the book, and no one would ever be charged for something like this.

Finally, we get to Trump. His case is highly unusual, but not at all complicated. The indictment⁹ provides mounds of evidence that he “willfully” took large quantities of classified material with him when he left the White House. After NARA (National Archives and Records Administration) contacted him about returning the missing classified material, he chose to lie, evade, and then turn over only some of the stolen documents. Eventually the FBI had to raid Mar-a-Lago to recover 300+ additional classified documents, and it’s still unclear whether everything has been recovered.

The whole point here is that the Trump case is genuinely unprecedented in just how crazy it is. The volume and scope of the theft puts it in league with espionage cases that land people in prison for decades. Even worse, the whole crime is documented with recordings, corroborating witnesses, and pretty much everything a prosecutor could dream of.

While I'm at it I should also quickly knock out some of the more common attempts I’ve seen to dismiss the criminality of Trump’s situation, so here goes:

Are the classified documents in fact Trump’s property? No. The Presidential Records Act is entirely clear on this¹⁰.

Could Trump have declassified these documents already as president? No. EO 13526 sets out the classification process, and if he wanted to expand it to include psychic declassification he had to write a superseding EO laying out such a process.

Does it matter that Trump doesn’t appear to be an agent of a foreign power? No. Just ask Petraeus¹¹ or Schulte¹²; you break the law when you willfully take the information and risk dissemination to those not cleared for access.

Does it matter that Trump stored the information in a locked room? Accepting that a resort with random people ambling about is laughably unsafe, the fact is that there are clear regulations for storage and transport of classified material, and Trump was so far outside the bounds of those that the tiny measures he took are immaterial.

TL;DR: Literally anyone else who did what Trump did would already be sitting in federal prison for at least a decade. Trump is getting an unheard of level of special treatment—entirely to his own benefit! There’s simply no comparison to what Clinton, Biden, or Pence did. The most appropriate comparisons for Trump’s case all involve people currently serving long federal prison sentences… or people who already died in prison.
_
¹ https://en.wikipedia.org/wiki/Interagency_Training_Center
² https://en.wikipedia.org/wiki/Sensitive_compartmented_information_facility
³ https://en.wikipedia.org/wiki/Espionage_Act_of_1917
⁴ https://en.wikipedia.org/wiki/Executive_Order_13526
⁵ https://en.wikipedia.org/wiki/For_Official_Use_Only
⁶ https://www.politico.com/blogs/under-the-radar/2016/07/hillary-clinton-classified-emails-error-225194
⁷ https://www.usnews.com/news/politics/articles/2016-02-29/state-dept-wins-dispute-over-clinton-email-on-north-korea
⁸ https://en.wikipedia.org/wiki/Non-judicial_punishment
⁹ https://www.justice.gov/storage/US_v_Trump-Nauta_23-80101.pdf
¹⁰ https://en.wikipedia.org/wiki/Presidential_Records_Act
¹¹ https://en.wikipedia.org/wiki/David_Petraeus#Criminal_charges_and_probation
¹² https://en.wikipedia.org/wiki/Joshua_Schulte

778
59
617
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Apr 14, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @ian@mckellar.social
@ian @Popehat @mmasnick @nilay_patel Because lawyers and PR can't cook up a reasonable set of responses in a vacuum. They need to be informed by at least some semblance of a trust and safety team. That's why I interpret the years of Substack failing so miserably at this to mean that for all intents and purposes they simply don't have a trust & safety team.
5
1
0
0
Open post
jschuh
Justin Schuh @jschuh@infosec.exchange · Apr 14, 2023
Justin Schuh
@jschuh@infosec.exchange

Stay-at-home dad. Expect a mix of infosec (plus privacy and safety), 3D printing, and some US politics. You're probably following me because of my old job.

infosec.exchange
Replying to @Popehat@mastodon.social
@Popehat @mmasnick @nilay_patel I feel like I get it. From my own experience the worst thing that can come out of this kind of interview is to get pinned down saying something that turns into a really bad headline. So, he just stuck to the canned line that the lawyers and PR cooked up. The thing is that it's really not very hard to avoid getting pinned down without completely faceplanting like he did. But that would require being at least somewhat versed in trust and safety concerns, and being able to point to some actual efforts Substack is making in that space. IMHO the complete failure at that is why this interview was so bad. Because it reinforces all the other evidence that Substack is simply ignoring trust and safety almost entirely as a concern.
7
1
0
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:40:55 UTC