Live data from Hacker News

Senator requests better https compliance at US Department of Defense [pdf]

wyden.senate.gov

11–20 of 56 posts

Re: Senator requests better https compliance at US Department of Defense [pdf]

#11
post #2

That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…

Wyden just generally seems to be a reasonable guy that wants to do the right thing and spends time to understand issues. His tech initiatives usually make sense and years ago he also introduced something about health care which also made sense. He is the kind of legislator we should want in Congress.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#12
post #8

What an excellent letter. It appears that this Senator knows what he is talking about, or is at least very well informed by those around him. I wish more people--not just those in government--were this informed about these very serious issues.

That would be Chris Soghoian: https://en.wikipedia.org/wiki/Christopher_Soghoian

... who is HN user csoghoian:

https://news.ycombinator.com/threads?id=csoghoian

and very disciplined about not using social media while working in the Senate!

Re: Senator requests better https compliance at US Department of Defense [pdf]

#14

AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.

But any CA can issue certificates for any domain in our current system. Sure, you can always manually inspect the certificate and see if the root CA is expected. But does anyone do that at all?

Re: Senator requests better https compliance at US Department of Defense [pdf]

#15
post #2

That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…

Senator Wyden is extremely well regarded within the US with regards to technology. If you haven't seen it, he's in the documentary for Aaron Swartz.

Here are his words about the death of Aaron: https://en.wikisource.org/wiki/Senator_Wyden_Remarks_at_Aaro...

Re: Senator requests better https compliance at US Department of Defense [pdf]

#16

AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.

But any CA can issue certificates for any domain in our current system. Sure, you can always manually inspect the certificate and see if the root CA is expected. But does anyone do that at all?

I guess you could have an "internal network" browser config with _only_ the DoD CA root.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#17
Oh you have no idea how welcome this is. As a member of the National Guard, we are expected to use our own personal equipment to access DoD websites. It is a constant battle of certificates that are not recognized, expired, many other things. The Army maintains a gold image for all active duty computers, but us silly part time soldiers who try to use our own equipment are completely screwed.

Just this month alone I have been 'mandated' to sign multiple documents and complete on-line courses that I can not access due to the Army's making everything only Microsoft compatible. So many sites are years old still making ancient calls to Internet Explorer functions.

The simple act of fixing the certificate issues would eliminate half the frustration right now. The second thing they need to do is mandate that any site has to operate with all the major browsers, and not just ancient versions of IE.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#18

Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.

I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead?

I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published.

All that said - the senator seems reasonably well informed and asking some good questions - even if his final suggestion for the US military to use Let's Encrypt made me cringe a little :)

Re: Senator requests better https compliance at US Department of Defense [pdf]

#19

Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.

I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…

I keep seeing people putting Lets Encrypt down. What is so wrong with it?

Re: Senator requests better https compliance at US Department of Defense [pdf]

#20
Wyden is a treasure. He's also, to my mind, the one who precipitated the Snowden leaks.

Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.

Post reply on HN