123
submitted 1 year ago by Odusei@lemmy.world to c/news@lemmy.world

Some of the emails reportedly contained sensitive information such as passwords, medical records and the itineraries of top officers.

top 10 comments
sorted by: hot top controversial new old
[-] Mic_Check_One_Two@reddthat.com 52 points 1 year ago* (last edited 1 year ago)

That’s what we in the cybersec business call an “oopsie daisy I made a little fucky-wucky”.

For real though, this isn’t a problem yet. The TL;DR is that Mali has a top-level domain “.ml”. Just like “.co.uk” for the UK. And the military uses the domain “.mil”. So lots of emails accidentally get sent to “[Military email]@[Military email server].ml” instead of sending to .mil.

So a bad actor could simply set up an e-mail server with .ml domains that mirror the military’s .mil ones, and start collecting all of those mis-addressed emails.

So why isn’t it an issue yet? Because we had a contract with Mali to manage their domain. They literally signed administrative rights for the .ml domain over. So the US was able to basically set up their own .ml mirrored sites, to capture all of those mis-addressed emails. They have captured thousands throughout the years, because military members keep misaddressing their emails. Supposedly containing all kinds of sensitive data. Everything from medical records to troop movements and equipment inspection reports.

But that contract ends this week, so Mali could 100% start registering their own domains when that contract expires and domain registrations begin expiring.

[-] Frog-Brawler@kbin.social 12 points 1 year ago

Sounds like the military should consider migrating from .mil to something like .usmil

[-] Mic_Check_One_Two@reddthat.com 19 points 1 year ago

Or simply set rules to disallow any emails sent to a .ml domain. It’s not a perfect solution because legitimate emails could get caught in the filter. But it would prevent the issue of mis-addressed emails.

[-] dm_me_your_feet@lemmy.world 12 points 1 year ago* (last edited 1 year ago)

I doubt the number of US military who legitimately needs to email .ml addresses is that big. Block it for everyone minus known ppl who deal with mali stuff (and have been briefed on the issue). Sort out the ones you missed on day 0. Worst case some legitimate mail to mali gets delayed - whatever. If its urgent, i hope they have better comms channels than email. For external contractors, send them an email with vague threats of consequences if they leak (and instructions to fix their address books). Some mail will still be missent, but this should mitigate most of it.

[-] Burninator05@lemmy.world 2 points 1 year ago

This is the simple answer so you know it won't happen.

[-] Frog-Brawler@kbin.social 1 points 1 year ago

Yea that’s cheaper than my plan. Good call.

[-] SomethingBurger@lemmy.world 7 points 1 year ago

Or mil.us. .mil and .gov should be removed, and the US should use subdomains for their government sites, just like all other countries.

[-] Matt_Shatt@lemmy.world 2 points 1 year ago

Note to self: set up a usmail domain!

[-] lemmy_nightmare@sh.itjust.works 5 points 1 year ago

Thanks for the explanation ☺️

[-] mewpichu@lemm.ee 4 points 1 year ago

What I don't understand is my company set things up to give everyone an alert every time they're sending something to a non company domain. Why aren't there any protections like this in place?

load more comments
view more: next ›
this post was submitted on 17 Jul 2023
123 points (98.4% liked)

News

22948 readers
5696 users here now

Welcome to the News community!

Rules:

1. Be civil


Attack the argument, not the person. No racism/sexism/bigotry. Good faith argumentation only. This includes accusing another user of being a bot or paid actor. Trolling is uncivil and is grounds for removal and/or a community ban.


2. All posts should contain a source (url) that is as reliable and unbiased as possible and must only contain one link.


Obvious right or left wing sources will be removed at the mods discretion. We have an actively updated blocklist, which you can see here: https://lemmy.world/post/2246130 if you feel like any website is missing, contact the mods. Supporting links can be added in comments or posted seperately but not to the post body.


3. No bots, spam or self-promotion.


Only approved bots, which follow the guidelines for bots set by the instance, are allowed.


4. Post titles should be the same as the article used as source.


Posts which titles don’t match the source won’t be removed, but the autoMod will notify you, and if your title misrepresents the original article, the post will be deleted. If the site changed their headline, the bot might still contact you, just ignore it, we won’t delete your post.


5. Only recent news is allowed.


Posts must be news from the most recent 30 days.


6. All posts must be news articles.


No opinion pieces, Listicles, editorials or celebrity gossip is allowed. All posts will be judged on a case-by-case basis.


7. No duplicate posts.


If a source you used was already posted by someone else, the autoMod will leave a message. Please remove your post if the autoMod is correct. If the post that matches your post is very old, we refer you to rule 5.


8. Misinformation is prohibited.


Misinformation / propaganda is strictly prohibited. Any comment or post containing or linking to misinformation will be removed. If you feel that your post has been removed in error, credible sources must be provided.


9. No link shorteners.


The auto mod will contact you if a link shortener is detected, please delete your post if they are right.


10. Don't copy entire article in your post body


For copyright reasons, you are not allowed to copy an entire article into your post body. This is an instance wide rule, that is strictly enforced in this community.

founded 1 year ago
MODERATORS