Āé¶¹“«Ć½

Assange: Why WikiLeaks was right to release raw cables

WikiLeaks founder says activists and vulnerable informants needed an accessible and trustworthy version of the cables once others had published them
ā€œFor harm minimisation, there are people who need to knowā€
(Image: Kirsty Wigglesworth/PA)

WikiLeaks founder Julian Assange has defended the organisation’s release of all 251,000 secret US diplomatic cables that it held without the redaction of the names of informants mentioned in them.

In an interview with Āé¶¹“«Ć½, Assange said the leak publishing outfit’s usual editorial ā€œharm minimisationā€ procedures had become irrelevant after other websites published the full text of the unredacted cables.

That full-text publication became possible when WikiLeaks: Inside Julian Assange’s war on secrecy was published in February. Written by two journalists at the newspaper The Guardian, based in London, the book revealed the decryption key for a computer file containing all the US state department cables leaked to WikiLeaks.

The Guardian team say they believed the key – but it had not.

ā€œThat is not how file decryption works,ā€ Assange says. ā€œThe only thing that was temporary was the website location the file was stored in. But the password is not used for the website – it is used for decrypting the file.

ā€œWe entrusted all 251,000 cables to The Guardian so they could read them and do their journalism on them,ā€ he says. ā€œOur security arrangement was perfect, assuming the password was not disclosed.ā€ The Guardianā€ČŁ was given a written copy of a lengthy encryption key – a passphrase – plus an additional word that he had to commit to memory for insertion at a set point within the phrase, adding security if the paper copy was lost.

Trickle of leaks

He later included these details in the book WikiLeaks, which he co-authored. So when the AES256-encrypted file was tracked down to BitTorrent sites – where WikiLeaks had supposedly placed it as a defence against denial-of-service attacks – the cables could be decrypted and began trickling onto rival leak sites like .

The publication of the passphrase and additional secret word in The Guardianā€ČŁ book has horrified not only WikiLeaks but security engineers in general. Their view is perhaps best summed up by the influential BT infosecurity expert Bruce Schneier : ā€œMemo to The Guardian: publishing encryption keys is almost always a bad idea.ā€

The reason? Even if the passphrase had expired – it hadn’t in this case – the way it is put together, alongside knowledge of the use of an additional word, gives an attacker very strong clues as to how an organisation habitually structures its keys, passwords or passphrases. ā€œIt describes our internal security mechanisms,ā€ says Assange.

Three weeks ago, other leak sites realised that The Guardianā€ČŁ passphrase decrypted the BitTorrent file – and the unredacted US cables began appearing on non-WikiLeaks sites. ā€œSo we contacted the US state department, Amnesty International and Human Rights Watch and told them what was occurring,ā€ says Assange – presumably so they could prepare any informants for possible trouble.

Race for knowledge

Then late last week WikiLeaks published the whole tranche of unredacted cables. ā€œThe reason being that a race commenced between the governments who need to be reformed and the people who can reform them using the material,ā€ says Assange.

ā€œAdditionally, for harm minimisation, there are people who need to know that they are mentioned in the material before intelligence agencies know they are mentioned – or at least as soon after as possible.

ā€œBy the time we published the cables, the material was already on dozens of websites, including Cryptome, and were being tweeted everywhere. And even a searchable public interface had been put up on one of them.ā€

Another motive for publishing the tranche, Assange claims, was the provision of a reliable source for the leaks. In the field of leak publishing, he says, WikiLeaks has become a trusted brand. Although versions of the cable tranche were appearing online, ā€œthere was not an authorised version of the cables that the public could rely onā€.

Authorised version

What does he mean by an ā€œauthorisedā€ version of cables, when they were US government property?

ā€œBy ā€˜authorised’ I mean a version that is known to be true – it doesn’t have another agenda. The unauthorised versions that were being tweeted everywhere – although as far as we can determine they were accurate, the public and journalists couldn’t know they were accurate.ā€

He points to stories published in Tajikistan and Pakistan that have been based on fake cables. ā€œWikiLeaks is a way for journalists and the public to check whether a claimed story based on a cable is actually true. They can come to our site to check. We have a 100 per cent accuracy record.ā€