The Pentagon Says It Will Start Encrypting Soldiers' Emails Next Year
motherboard.vice.com
motherboard.vice.com
When I saw the title, I thought they would start to use GnuPG or PEP or maybe switching from SMTP and MIME to something else.
And then it seems that they're still where the rest of the world was a almost decade ago, and starting implementing TLS.
I'm a bit surprised they can even get their email delivered today without having implemented TLS.
But, yeah, I just forgot about S/MIME while I was writing that comment. It's probably a better fit, especially in terms of revocation (OCSP, etc).
They have of course been able to encrypt individual emails for at least a decade with their CAC/PKI by checking a box in their email client.
After re-reading the article they never make any mention of existing crypto practices... Seems like purposely misleading or sloppy journalism.
However in the origin article they link to there is a useful gem:
> "STARTTLS is an extension for the Post Office Protocol 3 and Internet Message Access protocols, which rely on username and password for system access," the spokesperson wrote. "To remain compliant with DOD PKI policy, DEE does not support the use of username and password to grant access, and does not leverage either protocol."
I'm not versed in those protocols, but if that statement was true at the time it makes sense to me that the military wouldn't take a step back to using passwords when they already implemented physical tokens (CAC+pin) DoD-wide.