Live data from Hacker News

Senator requests better https compliance at US Department of Defense [pdf]

wyden.senate.gov

21–30 of 56 posts

Re: Senator requests better https compliance at US Department of Defense [pdf]

#21
As a veteran can we please get someone to look at the patchwork of expired certificates and questionable CN's that exists as the VA Benefits system? I swear the handshakes are coming live from some old half-retired grunt in the payroll department.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#22
post #19

Earlier quoted context omitted.

I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…

I keep seeing people putting Lets Encrypt down. What is so wrong with it?

For the record, the US DoD /is/ using Let's Encrypt.

https://crt.sh/?Identity=%25.mil&iCAID=16418

Re: Senator requests better https compliance at US Department of Defense [pdf]

#23

AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.

But only the owner of the private key associated with the certificate can intercept traffic. The keys used to sign the certificate have no impact on the actual encryption whatsoever...

Re: Senator requests better https compliance at US Department of Defense [pdf]

#26

Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.

I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…

Looks to me like the body of the letter was printed onto paper pre-printed with the letterhead, but that the paper was fed through the printer at an angle.

My guess is someone then said "eh, good enough, I can't be bothered going to get more letterhead paper out of the box to feed into the bypass tray, then going to re-print the document from my computer", and took the letter to Senator Wyden for signature. He then signed, and the signed letter was scanned for preservation as a digital record.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#27
post #23

AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.

But only the owner of the private key associated with the certificate can intercept traffic. The keys used to sign the certificate have no impact on the actual encryption whatsoever...

All true/correct.

It is worth considering that some DoD systems only have whitelisted CAs installed to limit the ability for an adversary to MitM. For example a DoD laptop used in a foreign country, you don't want the foreign government to be able to issue a certificate for a DoD property using their CA (or pressure/steal a commercial CA's signing certificate).

Re: Senator requests better https compliance at US Department of Defense [pdf]

#28
post #20

Wyden is a treasure. He's also, to my mind, the one who precipitated the Snowden leaks. Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.

According to Clapper he misunderstood the question and thought they were asking about something previously just asked. Heard him interviewed on the BBC just a day or so ago where they asked him about it - and he said he hasnt previously lied in the hundreds of times he's appeared so why would he now. So I guess ppl can make up their own minds.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#29
post #28
post #20

Wyden is a treasure. He's also, to my mind, the one who precipitated the Snowden leaks. Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.

According to Clapper he misunderstood the question and thought they were asking about something previously just asked. Heard him interviewed on the BBC just a day or so ago where they asked him about it - and he said he hasnt previously lied in the hundreds of times he's appeared so why would he now. So I guess ppl can make up their own minds.

The previous question was about whether the NSA builds dossiers on all Americans, which is a far cry from having a database of phone call metadata not linked to PII used to find phone numbers of associates of malicious foreign agents.

Also, GP's timeline is backward. Snowden reached out to Greenwald four months before that hearing.

Re: Senator requests better https compliance at US Department of Defense [pdf]

#30
post #6

Used to work in the Senate and have always admired Senator Wyden and his staff when it comes to being up to date on important technical issues like net neutrality, domain name governance, data breach law, cybersecurity standards, and now this. If you have specialized technical knowledge that can inform policy of importance (your call on how to judge that), I encourage you to engage your senators/reps on such issues,…

I would definitely be interested in being a helpful source for a senate office on some matters. How would I go about gaining the credibility and connections required for them?
Post reply on HN