6 ms·
Wow. 1. The non-www version doesn't seem to work. 2. If you try https://www.intelink.gov/ https://www.intelink.gov/, the browser immediately warns you that th
by pdevr 6y ago
Wow.
1. The non-www version doesn't seem to work.
2. If you try https://www.intelink.gov/ https://www.intelink.gov/, the browser immediately warns you that the site is not secure, because of certificate problems.
3. If you still dare to venture ahead, you are greeted with this:
"This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access, are provided only for authorized U.S. Government use. U.S. Government computer systems may be monitored for all lawful purposes, including ensuring that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Monitoring includes authorized attacks by authorized U.S. Government entities to test or verify the security of this system. During monitoring, information may be examined, recorded, copied, and used for authorized purposes. All information including personal information, placed on or sent over this system may be monitored."
I am out of here :-)
- vonmoltke 6y ago> 1. The non-www version doesn't seem to work. Common for "internal" USG sites. I don't know if it's intentional. > 2. If you try https://www.intelink.gov/ https://www.intelink.gov/, the browser immediately warns you that the site is not secure, because of certificate problems. Internal USG sites use USG-generated root certificates and certificate chains. These need to be installed manually from USG sources. > 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access, are provided only for authorized U.S. Government use. U.S. Government computer systems may be monitored for all lawful purposes, including ensuring that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Monitoring includes authorized attacks by authorized U.S. Government entities to test or verify the security of this system. During monitoring, information may be examined, recorded, copied, and used for authorized purposes. All information including personal information, placed on or sent over this system may be monitored." The standard disclaimer on all internal and classified systems. I'm glad I no longer have to click through that daily.
- ianmf 6y ago> 3. These banners are required on all government IT systems. The sole purpose of these banners is to prevent criminals from saying they were not aware of what they were doing, mistakenly accessed the site, etc. It is a legality.
- TecoAndJix 6y agosee this STIG (NIST) requirement for network devices - https://www.stigviewer.com/stig/firewall/2015-09-18/finding/V-3013 https://www.stigviewer.com/stig/firewall/2015-09-18/finding/...
- Pick-A-Hill2019 6y agoThen it's just as well you didn't scroll down to the comments section of tfa that links to a blog page called "Dangerous I.P. addresses that you should never ever scan" (https://dangerousip.blogspot.com/ https://dangerousip.blogspot.com/)
- wrkronmiller 6y ago> 207.60.36.176 - 207.60.36.183 Chris Pet Store Peculiar on many levels...
- Pick-A-Hill2019 6y ago" All the below are FBI controlled Linux servers & IPs/IP-Ranges 207.60.0.0 - 207.60.255.0 " I have no idea how they verified it* (or perhaps inserted as a prank?) but almost certainly it's no longer current (the list is from 2016) but uhmm yeah - It makes all those 80's movies that had the surveilance teams in grey vans marked 'Joes 24 Hour Plumbers' or 'Billy-Bobs Flowers' kinda funny. * IIRC one of the US Three Letter Agencies set up a load of dummy websites but used the same html code snippet in all of them. Once the first one was discovered and exposed as being a front it was game over. (meta comment - I think I might have read it as a post here on HN)
- secfirstmd 6y agoYou might be talking about the way the CIA reused code to communicate with sources in Iran in its China operations? Then got a ton of people killed by being stupid/lazy - despite internal whistleblowers going to Congress to warn them it was dangerous? https://www.telegraph.co.uk/technology/2018/11/03/dozens-us-spies-killed-iran-china-uncovered-cia-messaging-service/ https://www.telegraph.co.uk/technology/2018/11/03/dozens-us-... Something similar happened in Lebanon IIRC. Lazy reuse of tradecraft - a pizzeria and some mobiles I think it was.
- DakharsBuzumCIA 6y agoI was going to comment on 'a dozen killed.' 12 * 80 kg is just 960 kg , so, I guess it's either a baker's dozen, 13, which makes it 1040, or those people were fat as fuck. Learn to weigh 80 kg, or, I mean; don't join the CIA. Either or. Fat bastards! L O L
- ckozlowski 6y agoYou need the DoD Root CAs. You can get them from here, just follow the instructions: https://public.cyber.mil/pki-pke/end-users/getting-started/ https://public.cyber.mil/pki-pke/end-users/getting-started/ They're not bad to have in general. The notice you see there is standard boilerplate.
- nefitty 6y agoThis seems like it should be included in default root stores. I am out of my element here, but it would be cool if anyone can explain why or if I would need to manually add govt CAs.
- lostapathy 6y agoIf you allow the US gov CAs to be bundled with your browser, do you allow any country? How would non-US citizens feel about having US CA's in their browser by default?