Earlier quoted context omitted.
> I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves They do it precisely because they cannot trust any other CAs. You cannot trust any CAs — and yet you do. Go into your browser: odds are you have CAs controlled by the Russian, Chinese & Turkish governments. You're not just trusting those CAs to issue certificates for .cn, .ru or .t…
Fair point, I didn't really consider the issue with the other CAs that are currently trusted. Isn't it a double edge sword though with what they chose to do instead? By the DoD using their own CA people accessing their sites externally or on non-DoD devices cannot reliably know if they're being ease dropped on either. It has it's benefits for DoD employees using DoD devices but anyone outside the DoD needs to roll th…
Trusted End Node Security
21–30 of 31 posts
Re: Trusted End Node Security
#22Earlier quoted context omitted.
Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs? Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.
I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not. I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust
Public companies don't typically have "our CA getting hacked by a foreign power in a war affecting all our traffic" as a part of their threat model, which is why public companies can use public CAs without worry.
Re: Trusted End Node Security
#23Folks, the reason you get a certificate error is because this .mil site uses a certificate signed by the DoD CAs and none of the major OS/browsers ship with them pre-installed (for what should be obvious reasons).
Re: Trusted End Node Security
#24This doesn't work for me - I need to have the Department of Defense root certificate installed, but I'm not sure I'm willing to do that...
No you don't. At least not even on old IE 11, and I can't imagine any other browser doing it worse (and I know Firefox). The browser is supposed to allow you to access the site my just confirming that you want. No root certificates.
Re: Trusted End Node Security
#25Re: Trusted End Node Security
#26Re: Trusted End Node Security
#27Uh-oh. They argue that this is not an issue since the drive is read only, preventing any persistence of malware between sessions. However, this still means that there are known and fixable holes in the system which are exposed in using TENS; just because the malware goes away when you reboot, doesn't make it ok to allow malware in in the first place.
Also, what about literally any hardware security threats, like physical keyloggers or any evil low level software (bios, eufi, etc)
Re: Trusted End Node Security
#28Earlier quoted context omitted.
Out of curiosity, what are those obvious reasons? Is it because the US military is less trustworthy than other US government institutions or, say, Chinese and Turkish government CAs? Edit: To make this clear, I'm not interested in a spurious political debate, I'm really just interested in the reasons / who decided this e.g. for my browser Firefox on the basis of what reasons.
I have ranted to co-workers for years now about the DoD with their third party root CA cert. I never know if the link I'm accessing is actually for the DoD or not. I personaly cannot think of a good reason they do this. Maybe they argue that they don't trust any CA Authorities other than themselves due to issues in the past like with symantec https://searchsecurity.techtarget.com/podcast/Risk-Repeat-Ba... or entrust
They are in a kind of unique position.
Re: Trusted End Node Security
#29Earlier quoted context omitted.
Fair point, I didn't really consider the issue with the other CAs that are currently trusted. Isn't it a double edge sword though with what they chose to do instead? By the DoD using their own CA people accessing their sites externally or on non-DoD devices cannot reliably know if they're being ease dropped on either. It has it's benefits for DoD employees using DoD devices but anyone outside the DoD needs to roll th…
99%+ of DoD traffic will be from DoD-managed endpoints, which will be managed and have the DoD CA certificates installed. The DoD use case doesn't typically require them to cater to outside users, with possible exceptions for things like recruiting, which can be handled on separate networks.
/edit. That was a very long time ago though so I'm not sure if they're even using that same screen sharing site anymore or if they've since changed it to use a public CA root cert.
Re: Trusted End Node Security
#30Earlier quoted context omitted.
No you don't. At least not even on old IE 11, and I can't imagine any other browser doing it worse (and I know Firefox). The browser is supposed to allow you to access the site my just confirming that you want. No root certificates.
On Safari the only option to proceed requires installing the DoD certificate.