The Wikileaks blame game — who released what, exactly?

The story of how the unredacted version of the US diplomatic cables ended up in the wild really is a disgraceful farce — a tragedy of errors, with plenty of blame to go round. Nigel Parry has a great round-up and Micah Sifry also weighs in.

There’s one thing I am not inclined to blame Assange for, however: It’s been misreported just about everywhere that Assange and Wikileaks released the fully unredacted cables themselves, as per their tweet:

WIKILEAKS RELEASE: Full Cablegate2 database file (torrent)

The above downloads a SQL file. They also made a 60GB HTML version available, in addition to the SQL database version above. I downloaded both files, and searched them for previously redacted cables which I had read when they were released. In these BitTorrent files, however, those cables are still redacted. It’s only the remaining, previously unreleased files which are left unredacted.

The online resources showing this partially redacted version of the cables are and (Both these links go to the same cable from 2006 where a Chinese official asks the US to censor Google Earth imagery in China (without success). In both cases, the name of the official is redacted.)

The completely unredacted version of the cables is the file hosted by Cryptome, and it is this version which the online search tool queries. (Here is the same cable about Google Earth as before. It reveals the name of the official.)

So it appears that Wikileaks is not directly responsible for “unredacting” the previously redacted material that is now floating around. The source of that lies elsewhere. Is this a distinction without a difference? I’m not sure; Wikileaks did after all tweet a link to the search tool. Perhaps in the current chaos Wikileaks is not even sure what it is releasing.

So who bears the preponderance of the blame, then? Right now I’m leaning towards The Guardian’s David Leigh for his apparent technological ineptitude in not knowing that encrypted files don’t come with temporary passwords — perhaps he watched too many James Bond films, where messages self-destruct on camera. By Parry’s account, Leigh couldn’t even unzip a file on his own. It’s not surprising then that he’d put the password to the unredacted original trove of cables in his book, published in February 2011. It’s colossal cluelessness, and I hope he’s sleeping badly for all the vulnerable people he’s put at risk.

Julian Assange is also to blame, primarily for being so cavalier with the information, entrusting it to people who are not capable of keeping it safe (or perhaps not being clear enough to Leigh about the nature of the file in question). As a result, intelligence agencies have likely had access to the unredacted cables for some time now.

The damage this has done is real. I would not want to be the Chinese person in this 2010 cable, a nephew of a Politburo Standing Committee member, who told US diplomats that cyber attacks against Google in China were being coordinated by his government. That cable was previously redacted, but now shows his name.

Nor would I want to be the Chinese person in this 2008 cable, published by Wikileaks a few days ago in its unredacted form, where he tells US diplomats:

Xxx himself is a leader of an underground church in Shanghai. He recently returned from a secret meeting of leaders of underground churches from Beijing, Shanghai, Tianjin, Wuhan, and Nanjing. Participants in the meeting reported that there has been an increase of governmental scrutiny and pressure because of the Olympics.

Getting his real name is now as easy as clicking on the link above. If these people, and others like them, find themselves harassed or arrested as a result of this débâcle, then I’m afraid that on balance, the Wikileaks experiment in radical transparency has made the world a worse place — and all through the sheer ineptitude of all parties concerned.

Wikileaks own leak ushers in the era of radical transparency

As the story emerges about how Wikileaks’ US diplomatic cables came to be available in an unredacted, unencrypted form this week, potentially harming the safety of many informants and other vulnerable people, one obvious lesson is again in evidence:

People are the weakest link in any encryption system.

The potential for human error is constant and unswerving, and so the odds were always that eventually, somehow, somebody would screw up — even somebody as security obsessed as Julian Assange was not exempt. It’s a common cliché to posit that “information wants to be free”; perhaps it is more accurate to say that for information, being encrypted is an unstable state — either the password is soon forgotten or taken to the grave and the information disappears from the universe, or else some blunder eventually allows it to escape to the world at large. For information, in the long run, it’s more “Live free or die”; there is no stable intermediate state. Conspiracies are short-lived at best because humans are fallible; those Knights Templar successfully defending the Holy Grail across the millennia exist only in bad fantasy fiction.

The 500MB BitTorrent file that contains all the cables unzips to around 60GB of HTML files — my computer’s been at it for over 8 hours and counting. I can’t not rifle through this trove now that it is in the wild, of course. Previously, I was frustrated that I couldn’t just do text searches on all the content for my own ad hoc investigative reporting, although I understood and approved of the reason why. Now that this information is in the open, we can’t just let those with nefarious motives read them — we all need to read up, so that there is some hope for a silver lining. (If I find anything relevant to Dliberation’s remit, I’ll blog it of course.)

It looks like we will after all have to adjust to living in a global society where radical transparency is an expected outcome, whether from customer database leaks or whistleblower actions. For a while, as The Guardian and others released redacted versions of the cables, we thought Pandora’s box could be opened just a sliver. We were wrong.