24 ms·
My team and I are the folks that have been fighting to make exactly this happen in DoD for years. We provide web hosting for the DoD Public Affairs community; w
by PW_Ops_Guy 8y ago
My team and I are the folks that have been fighting to make exactly this happen in DoD for years. We provide web hosting for the DoD Public Affairs community; we host 785 of DoD's top websites including defense.gov, af.mil, marines.mil, navy.mil, etc. For a deeper understanding of the issue, I have written a few blog posts about this to inform my stakeholders (links below).
Delivering public DoD websites using commercially-signed certificates was nearly impossible until January of this year when DoD CIO signed a memo titled, "Commercial Public Key Infrastructure (PKI) Certificates on Public-Facing Unclassified Web Servers." That memo enabled us to use commercial DV certificates to deliver public-facing .mil websites and will save the taxpayer millions of dollars. The day we got that memo was a very good day; we've been trying to get this change made for literally more than 10 years.
My team and I are passionate about our work, and we refuse to be another typical DoD information system that's down all the time, impossible to use, and only works on some archaic version of IE. The truly frustrating part of this is that we're already doing exactly what the Senator is asking, but I have no way to let him know. Yay bureaucracy.
Here are the links to the blog posts discussing this:
1 - http://publicweb.dodlive.mil/2016/10/06/why-doesnt-my-public-website-use-https/ http://publicweb.dodlive.mil/2016/10/06/why-doesnt-my-public...
2 - http://publicweb.dodlive.mil/2017/09/19/still-no-https-for-dma-hosted-websites/ http://publicweb.dodlive.mil/2017/09/19/still-no-https-for-d...
3 - http://publicweb.dodlive.mil/2018/04/02/https-breakthrough/ http://publicweb.dodlive.mil/2018/04/02/https-breakthrough/
- kstrauser 8y agoThank you for your hard work on this! As someone who had to automate a lot of .gov interactions, these million little roadbumps you describe made my work very difficult (if lucrative).
- 3pt14159 8y agoI've been fighting to get your friendly northern neighbour, GC, secure. One thing I can't quite square though: Why on earth are so many supposedly important systems _so_ insecure. For example, TLS on email servers for our military think tanks or the unclassified email servers of our intelligence agencies or militaries. Not having S/MIME or PGP I kinda understand, but full-blown TLS? I know protocol downgrade attacks / DNS attacks / etc are a thing, but passive surveillance of email traffic is _well documented_ and a thousand times easier than something noisy involving forged DNS responses. Even if there are networks with reliable blackers for actual classified stuff, surely communicating with professors or researchers that lack clearance is also worth protecting, no? Why is it taking decades to get simple email / server configurations fixed? Also, why is everything so broken and why does nobody seem to care? Take QNX for example, the supposedly secure microkernel OS that we put in ever switch, router, car, truck, nuclear power plants, military radios, etc. It had almost all the same vulnerabilities that Linux and Windows had. Broken SRNG, hardcoded backdoor⇧⌥←^h^h "maintenance password", easy privilege escalation. Hell, even the crypt function wasn't a hash! It was just a bit mixer! What is in the way of someone at the NSA just saying: "No, don't allow this to happen. Don't let them put the operating system into a bunch of stuff that we sell on the market."
- 616c 8y agoWhat group? USDS Defense Digital Service? Would be interested to know of such initiatives.
- PW_Ops_Guy 8y agoWe are the Defense Media Activity. You can check us out here: https://www.dma.mil/Services/DOD-Public-Web/ https://www.dma.mil/Services/DOD-Public-Web/. We have worked with the DDS, the DoD incarnation of USDS, on several initiatives.