Exclusive: Snowden Swiped Password From NSA Coworker
A civilian NSA employee recently resigned after being stripped of his security clearance for allowing former agency contractor Edward Snowden to use his pers...
Context & Ripple Effects
The mechanics of Edward Snowden's access have been filling in piece by piece since Reuters reported in August 2013 that he downloaded NSA secrets while working for Dell, and a December Forbes profile built a picture of him from colleagues who called him 'a genius among geniuses.' What NBC adds today is the specific key: he did not hack his way in, he borrowed a civilian coworker's password.
The human cost lands immediately — the coworker has been stripped of his security clearance and resigned. That detail matters because the NSA was already mid-restructuring: the Wall Street Journal reported in November 2013 on an agency-wide overhaul prompted by the leaks, and this disclosure gives that overhaul a concrete failure mode to fix — credential sharing between staff and contractors going undetected. The pickup breadth (New York Times, Slate, Ars Technica, Mashable and others running it same-day) signals how much appetite there still is for any new fact about how the leak happened.
First-order effects
- The coworker whose password Snowden used has lost his clearance and resigned, making individual credential discipline a career-ending liability inside the agency.
- NSA officials now have a confirmed, low-tech explanation for part of the access trail, which feeds directly into the investigation of how Snowden assembled his document trove with ordinary tooling.
Second-order effects
- The overhaul the Wall Street Journal documented in November 2013 now has to extend beyond network architecture to personnel-level controls — shared passwords, contractor accounts, and audit trails flagging one identity used from multiple desks.
- Other cleared contractors and support staff at the agency come under sharper scrutiny as managers re-examine who else has ever lent or borrowed login credentials.
Third-order effects
- If the pattern holds, the Snowden episode converts insider incidents into permanent policy: intelligence agencies move toward strict single-user credential enforcement and continuous monitoring of account behavior, a textbook case of incident-led permissioning where each breach tightens the boundary for everyone else.
The trend: Intelligence agencies are rewriting their security posture around identity and credential control, turning each Snowden-era disclosure into a new layer of access restriction.