# Wikileaks' leaks leaked.

**URL:** <https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070>\
**Category:** Great Debates\
**Created:** [September 3, 2011, 4:39pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070 "2011-09-03T16:39:53Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [September 3, 2011, 4:39pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/1 "2011-09-03T16:39:53Z")

</div>

> **[WikiLeaks Now Victim Of Its Own Leak](https://www.npr.org/2011/09/03/140154900/wikileaks-now-victim-of-its-own-leak)**
>
> More than a quarter-million secret U.S. diplomatic cables in WikiLeaks' possession have found their way onto the Internet in an apparent inadvertent release. The cables are now available in their raw, unedited and unredacted form, potentially...

Many months ago, Wikileaks gave a trove of a quarter of a million U.S. diplomatic cables to the _The New York Times_, _The Guardian_, and other media with the understanding that they would only be released with any information that could lead to direct harm, such as source’s names, redacted.

Since then a relatively small number have been released in dribs and drabs with redactions, although I believe there have been one or two instances where the releasers have been accused of leaving in names (perhaps inadvertently) and putting individuals in danger.

Now the entire trove has been released, unecrypted and unredacted, onto the internet and thus irretrievably into the de facto public domain.

Everyone seems to be denying guilt and everyone is pointing fingers at everyone else.

I guess this is what comes from expecting an organization of leakers not to leak. :smack:

---

<div class="post-metadata">

**Author:** ![Grumman](https://avatars.discourse-cdn.com/v4/letter/g/43a26b/32.png) [@Grumman](https://boards.straightdope.com/u/Grumman)\
**Post date:** [September 3, 2011, 4:49pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/2 "2011-09-03T16:49:10Z")

</div>

> [@davidm](#):
>
> I guess this is what comes from expecting an organization of leakers not to leak. :smack:

By “an organisation of leakers”, you realise you might mean the _Guardian_, right?

It should be trivially easy to prove whether or not Leigh is responsible for the leak. Wikileaks’ story is that David Leigh’s book, _Wikileaks: Inside Julian Assange’s War on Secrecy_ contains the password to the encrypted document that was Assange’s trump card. It should be as simple as giving a page number - then anyone could buy the book (or just look it up in a bookstore), find the password and download the file to test it.

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [September 3, 2011, 5:14pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/3 "2011-09-03T17:14:06Z")

</div>

Whoever released it, there were too many people involved to be able to assume that secrets could be kept.

I’m a little confused about the business with the encrypted file and password. I know that there was an encrypted 1.4G so-called “insurance” file released onto the net. The collection that was just released is only half a gig compressed (65G when extracted). Is this the insurance file? I would think that, if a compressed 0.5G file extracts to 65G then a compressed and encrypted 1.4G file would extract to something much bigger than 65G. Is this release from some other encrypted file that I was unaware of?

From what I’ve seen, it consists only of a few things that were already public plus the diplomatic cables. I was under the impression that the insurance file contained much more than that.

Weirdly, Leigh seems to be denying his responsibility. If he did publish a password in his book then we’ll no for sure soon enough.

---

<div class="post-metadata">

**Author:** ![waterj2](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@waterj2](https://boards.straightdope.com/u/waterj2)\
**Post date:** [September 3, 2011, 5:32pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/4 "2011-09-03T17:32:36Z")

</div>

[This article](http://www.spiegel.de/international/world/0,1518,783778,00.html) in _Der Spiegel_ lays out the whole story. Long story short, as I understand it: Wikileaks put the encrypted data on the web, and gave the _Guardian_ the URL and the password to unencrypt it. After the _Guardian_ got the data, Wikileaks took it offline, but left it hidden in a secret folder on their servers. This was included in the set of data that was mirrored on several Bit Torrent sites. David Leigh of the _Guardian_ later published the story of his meeting with Julian Assange, complete with the password that Assange gave him, in his book. Eventually, people figured out that both the encrypted file and the password that decrypts it were out in the open.

---

<div class="post-metadata">

**Author:** ![JoelUpchurch](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@JoelUpchurch](https://boards.straightdope.com/u/JoelUpchurch)\
**Post date:** [September 3, 2011, 5:35pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/5 "2011-09-03T17:35:49Z")

</div>

Does this mean that Julian Assange is now “uninsured”?

---

<div class="post-metadata">

**Author:** ![waterj2](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@waterj2](https://boards.straightdope.com/u/waterj2)\
**Post date:** [September 3, 2011, 5:38pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/6 "2011-09-03T17:38:57Z")

</div>

The insurance file is not the one decrypted by the password supplied by Leigh. There’s a whole bunch of details and speculation if you follow through all the comments on [Bruce Schneier’s blog post](http://www.schneier.com/blog/archives/2011/09/unredacted_us_d.html) about it.

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [September 3, 2011, 5:52pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/7 "2011-09-03T17:52:41Z")

</div>

> [@waterj2](#):
>
> The insurance file is not the one decrypted by the password supplied by Leigh. There’s a whole bunch of details and speculation if you follow through all the comments on [Bruce Schneier’s blog post](http://www.schneier.com/blog/archives/2011/09/unredacted_us_d.html) about it.

That link seems to explain it quite well. Thanks.

It seems then that two rather dumb mistakes were made:  
[ol]  
[li]Using a hidden URL pointing to an apparently unprotected directory. This led to an unauthorized party accessing the file. Didn’t they realize that people would be all over their servers looking for hidden files?[/li][li]Publishing a password that was assumed to be obsolete but wasn’t because the file had been accessed by an unauthorized party.[/li][/ol]  
There certainly are some security lessons to be learned from this incident.

---

<div class="post-metadata">

**Author:** ![Grumman](https://avatars.discourse-cdn.com/v4/letter/g/43a26b/32.png) [@Grumman](https://boards.straightdope.com/u/Grumman)\
**Post date:** [September 3, 2011, 5:55pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/8 "2011-09-03T17:55:23Z")

</div>

[quote=“davidm, post:7, topic:595070”]

[li]Using a hidden URL pointing to an apparently unprotected directory. This led to an unauthorized party accessing the file. Didn’t they realize that people would be all over their server looking for hidden files?[/li][/QUOTE]

“Apparently unprotected” apart from the encryption, you mean? Sure, Wikileaks could have had two layers of protection (one to prevent downloads, one to prevent decryption) - but the same dumbass move that defeated one layer could still have defeated both layers.

Like one commenter said: “Turns out key management is hard when one side publishes the key you gave them in a book.”

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [September 3, 2011, 6:03pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/9 "2011-09-03T18:03:38Z")

</div>

> [@Grumman](#):
>
> “Apparently unprotected” apart from the encryption, you mean? Sure, Wikileaks could have had two layers of protection (one to prevent downloads, one to prevent decryption) - but the same dumbass move that defeated one layer could still have defeated both layers.
> 
> Like one commenter said: “Turns out key management is hard when one side publishes the key you gave them in a book.”

True, but they still should have exercised more care over the actual file. Something like this should have multiple layers of security.

Here’s an article that gives a more complete account of what apparently happened.

> **[Leak at WikiLeaks: A Dispatch Disaster in Six Acts](https://www.spiegel.de/international/world/leak-at-wikileaks-a-dispatch-disaster-in-six-acts-a-783778.html)**
>
> Some 250,000 diplomatic dispatches from the US State Department have accidentally been made completely public. The files include the names of informants who now must fear for their lives. It is the result of a series of blunders by...

---

<div class="post-metadata">

**Author:** ![Ravenman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ravenman/32/2929_2.png) [@Ravenman](https://boards.straightdope.com/u/Ravenman)\
**Post date:** [September 3, 2011, 6:54pm UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/10 "2011-09-03T18:54:24Z")

</div>

Oh my God! A British journalist didn’t exercise discretion! Why… why… why, if you can’t trust a British journalist, who CAN you trust? If there’s one thing I counted on in this world, it is that if I had a secret, I could count on British newspapers to keep it under wraps.

Plus, I’m shocked that something stored on the Internet for safe keeping has been compromised. If my time in government has taught me anything about cyber security, it is these four things: 1) don’t worry about plugging in your thumb drive into any ol’ computer you want – it’s just a thumbdrive; 2) cell phones, Blackberries, and iPhones are totally secure ways to communicate; 3) never change your password, because someone might forget it! 4) nobody has ever hacked the Internet, so don’t worry about leaving sensitive files up there.

It seems that the whiz kids at Wikileaks have also learned the last two lessons. Leading me to conclude that Assange isn’t just a jerk, he’s incompetent.

---

<div class="post-metadata">

**Author:** ![JoelUpchurch](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@JoelUpchurch](https://boards.straightdope.com/u/JoelUpchurch)\
**Post date:** [September 4, 2011, 2:35am UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/11 "2011-09-04T02:35:12Z")

</div>

> [@waterj2](#):
>
> The insurance file is not the one decrypted by the password supplied by Leigh. There’s a whole bunch of details and speculation if you follow through all the comments on [Bruce Schneier’s blog post](http://www.schneier.com/blog/archives/2011/09/unredacted_us_d.html) about it.

I read the link. Is there any indication that the insurance file contains any data that hasn’t been published? Is the insurance file larger than the data already in public?

---

<div class="post-metadata">

**Author:** ![JoelUpchurch](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@JoelUpchurch](https://boards.straightdope.com/u/JoelUpchurch)\
**Post date:** [September 4, 2011, 2:44am UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/12 "2011-09-04T02:44:04Z")

</div>

> [@JoelUpchurch](#):
>
> I read the link. Is there any indication that the insurance file contains any data that hasn’t been published? Is the insurance file larger than the data already in public?

Nevermind. I just read the Spiegel article. BTW, did you notice this statement:

> [@](#):
>
> It is possible that intelligence agencies in a number of countries have already gained access to the data. “Any autocratic security service worth its salt” would have already done so, former US Assistant Secretary of State for Public Affairs P.J. Crowley told news agency AP on Wednesday. Intelligence agencies that haven’t already gotten their hands on the data “will have it in short order,” he added.

---

<div class="post-metadata">

**Author:** ![Really\_Not\_All\_That\_Bright](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@Really\_Not\_All\_That\_Bright](https://boards.straightdope.com/u/Really_Not_All_That_Bright)\
**Post date:** [September 4, 2011, 4:35am UTC](https://boards.straightdope.com/t/wikileaks-leaks-leaked/595070/13 "2011-09-04T04:35:17Z")

</div>

> [@JoelUpchurch](#):
>
> Does this mean that Julian Assange is now “uninsured”?

Presumably he’ll have some other form of “insurance” floating around the web shortly, if so.
