← Back to context

Comment by vscode-rest

1 day ago

Gross misunderstanding of the threat model.

Phishing is not the problem here. Your laptop isn’t getting SIPR emails with links to fake login screens.

Being drunk at the bar/club/social event and telling that very interested lady a bit too much is probably the better example

Still not as bad as being susceptible to blackmail or bribes

I think you’re misunderstanding the threat model for why security clearance cares about impaired judgment of your off time, too. There’s more to these people’s lives than when they’re on the clock (figuratively speaking). Getting compromised anywhere is a problem.

  • I think you’re right. These are human systems always fighting the prior battle. Nowadays, it’s probably true that the threat from digital hygiene exceeds any intention to leak. The way that’s demonstrated is by the Secretary of Defense misusing Signal instead of being one level smarter and intuitively making the right messaging choice. The system is very much ready to build a preternaturally superimposing file on Pete Hegseth. But the system as a substitute for imagination is not elaborated to improve itself.

They don’t ask about any of that. If in a drunken blackout you find a USB drive on the subway and plug it in, the system is concerned about the blackout state and not the USB. It’s self preservation depends on telling the difference between incompetence and deception.