Senator requests better https compliance at US Department of Defense [pdf]
21–30 of 56 posts
Re: Senator requests better https compliance at US Department of Defense [pdf]
#22Earlier quoted context omitted.
I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…
I keep seeing people putting Lets Encrypt down. What is so wrong with it?
Re: Senator requests better https compliance at US Department of Defense [pdf]
#23AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#24Re: Senator requests better https compliance at US Department of Defense [pdf]
#25Re: Senator requests better https compliance at US Department of Defense [pdf]
#26Unrelated, but it would be nice if someone OCRed so that the text is accessible. Otherwise it's just a high-quality scan.
I was wondering something similar. It's clearly a typed letter, but it's offset from the letterhead. Was this scanned and placed onto the letterhead? I don't understand how that crookedness happens? I don't think it it wasn't a crooked page placed into a typewriter.. but I also can't explain why it would be printed, scanned at an angle, placed onto letterhead, and then published. All that said - the senator seems rea…
My guess is someone then said "eh, good enough, I can't be bothered going to get more letterhead paper out of the box to feed into the bypass tray, then going to re-print the document from my computer", and took the letter to Senator Wyden for signature. He then signed, and the signed letter was scanned for preservation as a digital record.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#27AFAIK, the point of the DoD Root CA is to avoid trusting an external entity not to intercept military traffic. Most .mil HTTPS sites that are intended to be accessed by the public (like https://www.army.mil/ ) are signed by a regular Root CA, while internal sites use the DoD Root CA.
But only the owner of the private key associated with the certificate can intercept traffic. The keys used to sign the certificate have no impact on the actual encryption whatsoever...
It is worth considering that some DoD systems only have whitelisted CAs installed to limit the ability for an adversary to MitM. For example a DoD laptop used in a foreign country, you don't want the foreign government to be able to issue a certificate for a DoD property using their CA (or pressure/steal a commercial CA's signing certificate).
Re: Senator requests better https compliance at US Department of Defense [pdf]
#28Wyden is a treasure. He's also, to my mind, the one who precipitated the Snowden leaks. Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#29Wyden is a treasure. He's also, to my mind, the one who precipitated the Snowden leaks. Wyden asked Clapper if the NSA collected data on Americans. Clapper lied. According to Snowden's account, that's what set him in motion. Even that account is not true, I want lawmakers to be asking that kind of tough and well thought out question.
According to Clapper he misunderstood the question and thought they were asking about something previously just asked. Heard him interviewed on the BBC just a day or so ago where they asked him about it - and he said he hasnt previously lied in the hundreds of times he's appeared so why would he now. So I guess ppl can make up their own minds.
Also, GP's timeline is backward. Snowden reached out to Greenwald four months before that hearing.
Re: Senator requests better https compliance at US Department of Defense [pdf]
#30Used to work in the Senate and have always admired Senator Wyden and his staff when it comes to being up to date on important technical issues like net neutrality, domain name governance, data breach law, cybersecurity standards, and now this. If you have specialized technical knowledge that can inform policy of importance (your call on how to judge that), I encourage you to engage your senators/reps on such issues,…