That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…
Senator requests better https compliance at US Department of Defense [pdf]
11–20 of 56 posts
Re: Senator requests better https compliance at US Department of Defense [pdf]
#12What an excellent letter. It appears that this Senator knows what he is talking about, or is at least very well informed by those around him. I wish more people--not just those in government--were this informed about these very serious issues.
That would be Chris Soghoian: https://en.wikipedia.org/wiki/Christopher_Soghoian
https://news.ycombinator.com/threads?id=csoghoian
and very disciplined about not using social media while working in the Senate!
Re: Senator requests better https compliance at US Department of Defense [pdf]
#13Re: Senator requests better https compliance at US Department of Defense [pdf]
#14AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#15That is a letter from a US Senator requiring the CIO of the US DOD to provide him with progress on the deployment of TLS and enforcing with HSTS. In the UK, the Home Secretary (who really ought to know better) once memorably wittered on about "hashtags" (1). I suggest that Ron Wyden off of Oregon is either or both of well informed and knowledgeable in IT matters. (1) https://www.theregister.co.uk/2017/04/03/uk_home_s…
Here are his words about the death of Aaron: https://en.wikisource.org/wiki/Senator_Wyden_Remarks_at_Aaro...
Re: Senator requests better https compliance at US Department of Defense [pdf]
#16AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.
But any CA can issue certificates for any domain in our current system. Sure, you can always manually inspect the certificate and see if the root CA is expected. But does anyone do that at all?
Re: Senator requests better https compliance at US Department of Defense [pdf]
#17Just this month alone I have been 'mandated' to sign multiple documents and complete on-line courses that I can not access due to the Army's making everything only Microsoft compatible. So many sites are years old still making ancient calls to Internet Explorer functions.
The simple act of fixing the certificate issues would eliminate half the frustration right now. The second thing they need to do is mandate that any site has to operate with all the major browsers, and not just ancient versions of IE.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#18Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.
I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published.
All that said - the senator seems reasonably well informed and asking some good questions - even if his final suggestion for the US military to use Let's Encrypt made me cringe a little :)
Re: Senator requests better https compliance at US Department of Defense [pdf]
#19Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.
I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…
Re: Senator requests better https compliance at US Department of Defense [pdf]
#20Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.