US military and intelligence computer networks (2015)
electrospaces.net
electrospaces.net
Given the recent SolarWinds breach I wonder how these networks are impacted. Most of them look like from the early 90s.
Classified military networks are very different than civilian networks. They aren't just air-gapped. Because they are not general purpose networks they can have lots of internal barriers that would not be acceptable outside of the military. Want to use HDMI for your new screen? Nope. VGA because it doesn't require compute power within the screen. Want to use a Bluetooth headset? Nope. You are stuck with a curly wire from 1972 because that wire has passed the emissions security inspections. Such principals extend to the internal barriers too. Important national security websites can look like personal websites from the 1990s not because they are not updated but because they are very restricted in how they can load information from other sources. The fact that these networks look old doesn't mean they are behind the curve on security.
Got too many passwords to remember? Want a "password manager"... lol. Good luck with that in a world where computer A isn't even allowed to be in the same room as computer B.
1. The non-www version doesn't seem to work.
2. If you try https://www.intelink.gov/, the browser immediately warns you that the site is not secure, because of certificate problems.
3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access, are provided only for authorized U.S. Government use. U.S. Government computer systems may be monitored for all lawful purposes, including ensuring that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Monitoring includes authorized attacks by authorized U.S. Government entities to test or verify the security of this system. During monitoring, information may be examined, recorded, copied, and used for authorized purposes. All information including personal information, placed on or sent over this system may be monitored."
I am out of here :-)
Common for "internal" USG sites. I don't know if it's intentional.
> 2. If you try https://www.intelink.gov/, the browser immediately warns you that the site is not secure, because of certificate problems.
Internal USG sites use USG-generated root certificates and certificate chains. These need to be installed manually from USG sources.
> 3. If you still dare to venture ahead, you are greeted with this: "This is a United States Government computer system. This computer system, including all related equipment, networks, and network devices, including Internet access, are provided only for authorized U.S. Government use. U.S. Government computer systems may be monitored for all lawful purposes, including ensuring that their use is authorized, for management of the system, to facilitate protection against unauthorized access, and to verify security procedures, survivability, and operational security. Monitoring includes authorized attacks by authorized U.S. Government entities to test or verify the security of this system. During monitoring, information may be examined, recorded, copied, and used for authorized purposes. All information including personal information, placed on or sent over this system may be monitored."
The standard disclaimer on all internal and classified systems. I'm glad I no longer have to click through that daily.
These banners are required on all government IT systems. The sole purpose of these banners is to prevent criminals from saying they were not aware of what they were doing, mistakenly accessed the site, etc. It is a legality.
Peculiar on many levels...
I have no idea how they verified it* (or perhaps inserted as a prank?) but almost certainly it's no longer current (the list is from 2016) but uhmm yeah - It makes all those 80's movies that had the surveilance teams in grey vans marked 'Joes 24 Hour Plumbers' or 'Billy-Bobs Flowers' kinda funny.
* IIRC one of the US Three Letter Agencies set up a load of dummy websites but used the same html code snippet in all of them. Once the first one was discovered and exposed as being a front it was game over. (meta comment - I think I might have read it as a post here on HN)
https://www.telegraph.co.uk/technology/2018/11/03/dozens-us-...
Something similar happened in Lebanon IIRC. Lazy reuse of tradecraft - a pizzeria and some mobiles I think it was.
One day someone at our company decided that it would be a good idea to scan whitehouse.gov. We got told to never do that again...
You can get them from here, just follow the instructions: https://public.cyber.mil/pki-pke/end-users/getting-started/
They're not bad to have in general.
The notice you see there is standard boilerplate.
How would non-US citizens feel about having US CA's in their browser by default?