An Introduction to HTTPS, by 18F and DigitalGov University
18f.gsa.gov
18f.gsa.gov
I worked as a government contractor for quite a while (SAIC) and I applaud this effort. I imagine the hurdles will be immense, so I wish you the best. We need more of this.
Is 18F sufficiently independent, or this project sufficiently below the radar that it just isn't an issue?
People think "The Federal Government" is a monolith, and they could not be more mistaken. It is a collection of individual entities, operating largely independently and often at odds with one another. 18F is a different entity with a different set of goals from the law enforcement (FBI/DEA/etc.) and intelligence (NSA/CIA/GeoInt) agencies.
In any case, it's also different parts of the tech stack - encrypting everything over the wire with HTTPS is fine so long as the underlying encryption is weak and/or the NSA have a set of keys. The FBI can always just issue a national security letter to the party with whom you are communicating.
That's definitely an accurate description of the US federal government.
Nothing below the radar about it:
https://www.whitehouse.gov/blog/2015/06/08/https-everywhere-...
I have been on a personal crusade of sorts insisting on encryption everywhere. When I come across large sites that don't support any encryption (I am looking at you, Squarespace), I struggle with content to send them to prove my point but this will do nicely.
No one respected in cryptography that I've met, or read papers from, would stand behind it as a seal that'd mean anything in actual security (please, someone, prove me wrong: I want to see SOME light in this tunnel). There are private entities with much more sensitive information than the U.S. Government, and the ones that take it seriously easily surpass FIPS (in purpose, not paper) with good engineering, because they can't hide behind a rubber stamp.
Not too long ago, I was on a team that was required to keep a FIPS-certified (FIPS 140-2) binary blob in production for months while there were known exploits against it. If you actually care about keeping amateur algorithms and implementations out of sensitive situations (vs. "Proving You Care via Paperwork"), you'd do better to follow Google or Facebook's security blogs than FIPS, because they react faster.
https://wiki.openssl.org/index.php/FIPS_mode_and_TLS#TLS_1.2 isn't exactly a restrictive sets.