Live data from Hacker News

US military and intelligence computer networks (2015)

electrospaces.net

11–20 of 28 posts

Re: US military and intelligence computer networks (2015)

#11
post #7
post #3

Earlier quoted context omitted.

Wow. 1. The non-www version doesn't seem to work. 2. If you try https://www.intelink.gov/ , the browser immediately warns you that the site is not secure, because of certificate problems. 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access,…

> 3. These banners are required on all government IT systems. The sole purpose of these banners is to prevent criminals from saying they were not aware of what they were doing, mistakenly accessed the site, etc. It is a legality.

see this STIG (NIST) requirement for network devices - https://www.stigviewer.com/stig/firewall/2015-09-18/finding/...

Re: US military and intelligence computer networks (2015)

#12
post #3

Earlier quoted context omitted.

Wow. 1. The non-www version doesn't seem to work. 2. If you try https://www.intelink.gov/ , the browser immediately warns you that the site is not secure, because of certificate problems. 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access,…

Then it's just as well you didn't scroll down to the comments section of tfa that links to a blog page called "Dangerous I.P. addresses that you should never ever scan" ( https://dangerousip.blogspot.com/ )

I'm curious what services like Shodan deal with the legal aspects of things. For example they obviously scan the Irish governments sites but I would be afraid to do that even though I do legitimate research. Is there any actual guidance out there about how to balance these things?

Re: US military and intelligence computer networks (2015)

#13

Earlier quoted context omitted.

Then it's just as well you didn't scroll down to the comments section of tfa that links to a blog page called "Dangerous I.P. addresses that you should never ever scan" ( https://dangerousip.blogspot.com/ )

> 207.60.36.176 - 207.60.36.183 Chris Pet Store Peculiar on many levels...

" All the below are FBI controlled Linux servers & IPs/IP-Ranges 207.60.0.0 - 207.60.255.0 "

I have no idea how they verified it* (or perhaps inserted as a prank?) but almost certainly it's no longer current (the list is from 2016) but uhmm yeah - It makes all those 80's movies that had the surveilance teams in grey vans marked 'Joes 24 Hour Plumbers' or 'Billy-Bobs Flowers' kinda funny.

* IIRC one of the US Three Letter Agencies set up a load of dummy websites but used the same html code snippet in all of them. Once the first one was discovered and exposed as being a front it was game over. (meta comment - I think I might have read it as a post here on HN)

Re: US military and intelligence computer networks (2015)

#14
post #3
post #2

https://intelink.gov is a gateway to some of these.

Wow. 1. The non-www version doesn't seem to work. 2. If you try https://www.intelink.gov/ , the browser immediately warns you that the site is not secure, because of certificate problems. 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access,…

You need the DoD Root CAs.

You can get them from here, just follow the instructions: https://public.cyber.mil/pki-pke/end-users/getting-started/

They're not bad to have in general.

The notice you see there is standard boilerplate.

Re: US military and intelligence computer networks (2015)

#15
post #4

What a great rabbit hole! It's pretty interesting to see how some of these sites are "protected" (big HTML warning stating "DO NOT ACCESS THIS") and some oldschool-IT named domains such as https://itdashboard.gov/ . Given the recent SolarWinds breach I wonder how these networks are impacted. Most of them look like from the early 90s.

>> Given the recent SolarWinds breach I wonder how these networks are impacted.

Classified military networks are very different than civilian networks. They aren't just air-gapped. Because they are not general purpose networks they can have lots of internal barriers that would not be acceptable outside of the military. Want to use HDMI for your new screen? Nope. VGA because it doesn't require compute power within the screen. Want to use a Bluetooth headset? Nope. You are stuck with a curly wire from 1972 because that wire has passed the emissions security inspections. Such principals extend to the internal barriers too. Important national security websites can look like personal websites from the 1990s not because they are not updated but because they are very restricted in how they can load information from other sources. The fact that these networks look old doesn't mean they are behind the curve on security.

Got too many passwords to remember? Want a "password manager"... lol. Good luck with that in a world where computer A isn't even allowed to be in the same room as computer B.

Re: US military and intelligence computer networks (2015)

#16

Earlier quoted context omitted.

> 207.60.36.176 - 207.60.36.183 Chris Pet Store Peculiar on many levels...

" All the below are FBI controlled Linux servers & IPs/IP-Ranges 207.60.0.0 - 207.60.255.0 " I have no idea how they verified it* (or perhaps inserted as a prank?) but almost certainly it's no longer current (the list is from 2016) but uhmm yeah - It makes all those 80's movies that had the surveilance teams in grey vans marked 'Joes 24 Hour Plumbers' or 'Billy-Bobs Flowers' kinda funny. * IIRC one of the US Three Le…

You might be talking about the way the CIA reused code to communicate with sources in Iran in its China operations? Then got a ton of people killed by being stupid/lazy - despite internal whistleblowers going to Congress to warn them it was dangerous?

https://www.telegraph.co.uk/technology/2018/11/03/dozens-us-...

Something similar happened in Lebanon IIRC. Lazy reuse of tradecraft - a pizzeria and some mobiles I think it was.

Re: US military and intelligence computer networks (2015)

#17
post #4

What a great rabbit hole! It's pretty interesting to see how some of these sites are "protected" (big HTML warning stating "DO NOT ACCESS THIS") and some oldschool-IT named domains such as https://itdashboard.gov/ . Given the recent SolarWinds breach I wonder how these networks are impacted. Most of them look like from the early 90s.

Those HTML banners aren't intended to "protect" anything, they just indicate what classification level the content is.

Re: US military and intelligence computer networks (2015)

#18
post #4

What a great rabbit hole! It's pretty interesting to see how some of these sites are "protected" (big HTML warning stating "DO NOT ACCESS THIS") and some oldschool-IT named domains such as https://itdashboard.gov/ . Given the recent SolarWinds breach I wonder how these networks are impacted. Most of them look like from the early 90s.

Sensitive networks are airgapped because vulns like solarwinds are not unforeseeable.

Re: US military and intelligence computer networks (2015)

#19
post #3

Earlier quoted context omitted.

Wow. 1. The non-www version doesn't seem to work. 2. If you try https://www.intelink.gov/ , the browser immediately warns you that the site is not secure, because of certificate problems. 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access,…

You need the DoD Root CAs. You can get them from here, just follow the instructions: https://public.cyber.mil/pki-pke/end-users/getting-started/ They're not bad to have in general. The notice you see there is standard boilerplate.

This seems like it should be included in default root stores. I am out of my element here, but it would be cool if anyone can explain why or if I would need to manually add govt CAs.
Post reply on HN