Live data from Hacker News

Senator requests better https compliance at US Department of Defense [pdf]

wyden.senate.gov

1–10 of 56 posts

Re: Senator requests better https compliance at US Department of Defense [pdf]

#2
That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS.

In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters.

(1) https://www.theregister.co.uk/2017/04/03/uk_home_secretary_a...

Re: Senator requests better https compliance at US Department of Defense [pdf]

#3
post #2

That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…

Wyden is the most knowledgeable legislator we have when it comes to technology. Here's him explaining Net Neutrality [1] and urging a 'no' vote [2] on Ajit Pai's FCC nomination.

Here's a letter [3] from him a year ago urging the importance of two-factor authentication.

[1] https://www.c-span.org/video/?c4698027/senator-ron-wyden-net...

[2] https://www.c-span.org/video/?434822-2/senator-wyden-ajit-pa...

[3] https://www.wyden.senate.gov/imo/media/doc/Two-Factor%20Auth...

Re: Senator requests better https compliance at US Department of Defense [pdf]

#4
What an excellent letter. It appears that this Senator knows what he is talking about, or is at least very well informed by those around him. I wish more people--not just those in government--were this informed about these very serious issues.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#5
post #3
post #2

That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…

Wyden is the most knowledgeable legislator we have when it comes to technology. Here's him explaining Net Neutrality [1] and urging a 'no' vote [2] on Ajit Pai's FCC nomination. Here's a letter [3] from him a year ago urging the importance of two-factor authentication. [1] https://www.c-span.org/video/?c4698027/senator-ron-wyden-net... [2] https://www.c-span.org/video/?434822-2/senator-wyden-ajit-pa... [3] https://ww…

Wyden is a treasure, plus he's a fan of oshpark[1]!

[1] https://twitter.com/RonWyden/status/896012835448381441

Re: Senator requests better https compliance at US Department of Defense [pdf]

#6
Used to work in the Senate and have always admired Senator Wyden and his staff when it comes to being up to date on important technical issues like net neutrality, domain name governance, data breach law, cybersecurity standards, and now this.

If you have specialized technical knowledge that can inform policy of importance (your call on how to judge that), I encourage you to engage your senators/reps on such issues, or at least connect with the legislative assistants in the offices who cover these issues. Give your senators/rep's DC office a call and ask for the LA (aka legislative assistant) and to brief him/her on the issue at hand. Or at least offer yourself as a resource if needed.

The best part about working in the Senate was being able to call up someone and ask for a briefing on an issue, and most would help out. Those that reached out proactively made life much easier, and, seriously, the squeaky wheel gets the grease in the policy world. Groups like I Am The Cavalry have done great work bringing together cybersecurity experts to raise awareness of, and push action, toward addressing vulnerabilities in systems that, if compromised, could cause major harm (think cars, medical devices, etc.). If you can form a group like that in your area of expertise, you can be more effective. Okay, off my soapbox for now.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#7
AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/) are signed by a regular Root CA, while internal sites use the DoD Root CA.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#8

What an excellent letter. It appears that this Senator knows what he is talking about, or is at least very well informed by those around him. I wish more people--not just those in government--were this informed about these very serious issues.

That would be Chris Soghoian: https://en.wikipedia.org/wiki/Christopher_Soghoian

Re: Senator requests better https compliance at US Department of Defense [pdf]

#9
This would be great...but it seems more likely that what happens if a forcing function is applied is that anything in the current gray area (gray area is putting it nicely) of using the DoD Root CA will likely just become not publicly accessible whether it makes sense or not to do that for the resource (e.g. webmail)

Again, this would be awesome but as a DoD civilian employee...I don't see it happening in a good way

Re: Senator requests better https compliance at US Department of Defense [pdf]

#10

AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.

That is pretty much how it is.
Post reply on HN