Live data from Hacker News

US military and intelligence computer networks (2015)

electrospaces.net

21–28 of 28 posts

Re: US military and intelligence computer networks (2015)

#21

Earlier quoted context omitted.

" All the below are FBI controlled Linux servers & IPs/IP-Ranges 207.60.0.0 - 207.60.255.0 " I have no idea how they verified it* (or perhaps inserted as a prank?) but almost certainly it's no longer current (the list is from 2016) but uhmm yeah - It makes all those 80's movies that had the surveilance teams in grey vans marked 'Joes 24 Hour Plumbers' or 'Billy-Bobs Flowers' kinda funny. * IIRC one of the US Three Le…

You might be talking about the way the CIA reused code to communicate with sources in Iran in its China operations? Then got a ton of people killed by being stupid/lazy - despite internal whistleblowers going to Congress to warn them it was dangerous? https://www.telegraph.co.uk/technology/2018/11/03/dozens-us-... Something similar happened in Lebanon IIRC. Lazy reuse of tradecraft - a pizzeria and some mobiles I thi…

I was going to comment on 'a dozen killed.' 12 * 80 kg is just 960 kg , so, I guess it's either a baker's dozen, 13, which makes it 1040, or those people were fat as fuck.

Learn to weigh 80 kg, or, I mean; don't join the CIA. Either or. Fat bastards! L O L

Re: US military and intelligence computer networks (2015)

#22
post #19

Earlier quoted context omitted.

You need the DoD Root CAs. You can get them from here, just follow the instructions: https://public.cyber.mil/pki-pke/end-users/getting-started/ They're not bad to have in general. The notice you see there is standard boilerplate.

This seems like it should be included in default root stores. I am out of my element here, but it would be cool if anyone can explain why or if I would need to manually add govt CAs.

If you allow the US gov CAs to be bundled with your browser, do you allow any country?

How would non-US citizens feel about having US CA's in their browser by default?

Re: US military and intelligence computer networks (2015)

#23
post #19

Earlier quoted context omitted.

This seems like it should be included in default root stores. I am out of my element here, but it would be cool if anyone can explain why or if I would need to manually add govt CAs.

If you allow the US gov CAs to be bundled with your browser, do you allow any country? How would non-US citizens feel about having US CA's in their browser by default?

Seems like most people, US or not, should not trust DoD-signed stuff by default.

Re: US military and intelligence computer networks (2015)

#24
post #4

What a great rabbit hole! It's pretty interesting to see how some of these sites are "protected" (big HTML warning stating "DO NOT ACCESS THIS") and some oldschool-IT named domains such as https://itdashboard.gov/ . Given the recent SolarWinds breach I wonder how these networks are impacted. Most of them look like from the early 90s.

>> Given the recent SolarWinds breach I wonder how these networks are impacted. Classified military networks are very different than civilian networks. They aren't just air-gapped. Because they are not general purpose networks they can have lots of internal barriers that would not be acceptable outside of the military. Want to use HDMI for your new screen? Nope. VGA because it doesn't require compute power within the…

We aren't allowed to use VGA because it's vulnerable to being sniffed. Everything has to be hdmi or display port/mini display port

Re: US military and intelligence computer networks (2015)

#25

Earlier quoted context omitted.

>> Given the recent SolarWinds breach I wonder how these networks are impacted. Classified military networks are very different than civilian networks. They aren't just air-gapped. Because they are not general purpose networks they can have lots of internal barriers that would not be acceptable outside of the military. Want to use HDMI for your new screen? Nope. VGA because it doesn't require compute power within the…

We aren't allowed to use VGA because it's vulnerable to being sniffed. Everything has to be hdmi or display port/mini display port

It depends on the threat profile. In an emissions secure zone, inside a big metal box like say a ship, the chance of a bug in the monitor's hdmi circuitry can be higher than the risk of the vga being sniffed.

Re: US military and intelligence computer networks (2015)

#26
post #19

Earlier quoted context omitted.

This seems like it should be included in default root stores. I am out of my element here, but it would be cool if anyone can explain why or if I would need to manually add govt CAs.

If you allow the US gov CAs to be bundled with your browser, do you allow any country? How would non-US citizens feel about having US CA's in their browser by default?

A lot of people have CAs controlled by various countries in their browsers by default. It was big news when CNNIC was dropped from Firefox and Chrome in 2015.

Re: US military and intelligence computer networks (2015)

#27

Earlier quoted context omitted.

We aren't allowed to use VGA because it's vulnerable to being sniffed. Everything has to be hdmi or display port/mini display port

It depends on the threat profile. In an emissions secure zone, inside a big metal box like say a ship, the chance of a bug in the monitor's hdmi circuitry can be higher than the risk of the vga being sniffed.

Funnily enough a static configuration HDMI display needs no special circuitry, as it's essentially VGA that didn't pass a DAC and you can spam it directly to LCD matrix.

Re: US military and intelligence computer networks (2015)

#28

Earlier quoted context omitted.

We aren't allowed to use VGA because it's vulnerable to being sniffed. Everything has to be hdmi or display port/mini display port

It depends on the threat profile. In an emissions secure zone, inside a big metal box like say a ship, the chance of a bug in the monitor's hdmi circuitry can be higher than the risk of the vga being sniffed.

If theres a chance of there being a bug in the HDMI circuitry isn't there just as much chance of there being a bug in VGA?.
Post reply on HN