Live data from Hacker News

Trusted End Node Security

spi.dod.mil

11–20 of 31 posts

Re: Trusted End Node Security

#11
post #8

Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).

Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs?

Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.

Re: Trusted End Node Security

#12
post #8

Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).

Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs? Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.

DoD does not follow the public rules of CA key handling, revocation or update. The reason to not add it is the same as for other dodgy CAs.

Re: Trusted End Node Security

#13
post #8

Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).

Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs? Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.

I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not.

I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust

Re: Trusted End Node Security

#14
post #8

Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).

Works fine with Chrome on MacOS.

Re: Trusted End Node Security

#15

Earlier quoted context omitted.

Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs? Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.

I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not. I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust

> I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves

They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .tr: you're trusting them for every TLD in the world, to include .com, .gov & .mil. Yes, if you're using XPKI (the standard PKI basically everything on the Internet uses), you're trusting that the Chinese government will never man-in-the-middle your sessions with the IRS. The DoD (rather wisely) chooses to trust only itself to certify itself.

My own opinion is that what we should have done was adopt a system which leveraged DNS to delegate trust (note that this is what Let's Encrypt does), and that we should have rooted DNS in a multinational board: if the U.S., China, Russia, Iran, the United Kingdom, the Ukraine, France & Mexico all agree on something, it's really very likely to be true.

We should also have leveraged IP assignments. Imagine if when you talked to a system it produced proof that it really is allowed to have its IP address and that it really is allowed to speak for a particular domain. That's really what people want, not some sort of nebulous tie to a real-world identity. What we care about is that facebook.com is facebook.com, not that it's Facebook, Inc., headquartered in Menlo Park.

Re: Trusted End Node Security

#16
post #15

Earlier quoted context omitted.

I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not. I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust

> I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .t…

Until that time we have a multinational board controlled CA, is there a list somewhere of the "sensible subset" of browser certs, for various types of users?

Re: Trusted End Node Security

#17
post #15

Earlier quoted context omitted.

I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not. I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust

> I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .t…

Fair point, I didn't really consider the issue with the other CAs that are currently trusted.

Isn't it a double edge sword though with what they chose to do instead? By the DoD using their own CA people accessing their sites externally or on non-DoD devices cannot reliably know if they're being ease dropped on either. It has it's benefits for DoD employees using DoD devices but anyone outside the DoD needs to roll the dice or first request the CA root cert from a DoD employee?

Re: Trusted End Node Security

#18
I would like to add some constructive conversation instead of banter about the cert...how does this get around malware/rootkit software that is embedded in the mobo or bios. How is this really any different than a LiveCD of Kali Linux or something?

I see that it is read-only media so I suppose that helps, but in the end its still only as secure as the machine that you run it from.

Re: Trusted End Node Security

#19
They have a DoD accreditation for their software (EW) but not their bootable media. Therefore, if you govvies run this on your government systems, you'll get your hand slapped and theres no guarantee it won't flag your system.

Re: Trusted End Node Security

#20
post #8

Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).

Certs for anyone keen:

https://iase.disa.mil/pki-pke/Pages/tools.aspx

*under Trust Store

Post reply on HN