The Pentagon Says It Will Start Encrypting Soldiers' Emails Next Year (vice.com)
An anonymous reader shares a Motherboard report: Basic decade-old encryption technology is finally coming to Pentagon email servers next year. For years, major online email providers such as Google and Microsoft have used encryption to protect your emails as they travel across the internet. That technology, technically known as STARTTLS, isn't a cutting edge development -- it's been around since 2002. But since that time the Pentagon never implemented it. As a Motherboard investigation revealed in 2015, the lack of encryption potentially left some soldiers' emails open to being intercepted by enemies as they travel across the internet. The US military uses its own internal service, mail.mil, which is hosted on the cloud for 4.5 million users. But now the Defense Information Systems Agency or DISA, the Pentagon's branch that oversees email, says it will finally start using STARTTLS within the year, according to a letter from DISA. DISA's promise comes months after Senator Ron Wyden (D-Oregon) said he was concerned that the agency wasn't taking advantage of "a basic, widely used, easily-enabled cybersecurity technology."
None of this, of course, is to say that encryption of email itself has been un available. Indeed I use the credentials on my CAC (Common Access Card) to encrypt most if not all of my email before sending it.
If you want news from today, you have to come back tomorrow.
It is here:
What could possibly go wrong?
"which is hosted on the cloud "
Ah, yes, "the cloud". Like there is just one. Thanks for the specifics. Does anyone know the details here; is the military really using AWS for email hosting?
...I think people have misconceptions about how exactly emails works. It's not bounced around from server to server until it gets to it's destination.
It's delivered directly to whichever server(s) your specified in your domain's mx record. So emails cannot simply be intercepted by whomever just like that.
However by default it is sent as clear text, which means in theory your Tier 3 (your ISP), tier 2 and tier 1 providers could intercept those emails since the packets have to pass through their networking equipment to get to their destination. But if most confidential emails are internal, then you could setup VPN tunnels between servers and that solves that problem.If you are sharing top secret or confidential military info , you should be encrypting every email you send via your email client, regardless if the servers transmit it in clear text or not.
They're talking about *personal* emails, right? Surely they aren't *that* incompetent that they're sending official communications over unencrypted email? PLEASE tell me they're not that stupid...
Most SMTP servers that implement STARTTLS don't even bother to verify the certificate presented to them by the remote host. Pretty trivial to MITM this traffic. This is basically the equivalent of putting a crapton of post cards in a lock box with a skeleton key. It'll keep honest people from reading your mail..thats about it.
The real solution is to encrypt the CONTENTS of the email using something like S/MIME or GPG.
StartTLS is no panacea, an active MITM peer can simply strip the request.
Actually, no.
- if you set to StartTLS to "required" (or if you use IMAPS), your client will only go further if a successful SSL/TLS encrypted link is established with the server.
The MITM can't just strip the request, the client will refuse to connect.
- SSL/TLS links will fail if they are not signed by a recognized authority.
The attacker needs to have a key that is signed by a trusted authority (and thus either needs to have a certificate issuer in cahoots - has actually hapenned with some cert authorities in the past - or needs to manage to get control of the e-mail server (thus can actually access without MITM. OR can steel the original private key and freely MITM. OR can generate a new key and have it at least non-EV signed and use this new key for MITM)
MITM is the main class of problems that SSL/TLS can succesfully fight (when done right). /certificates) )
(As opposed to "privacy" class of problems, which are better handled with end-to-end encryption, like PGP / GPG (web of trust) or S/MIME (public key
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
Oooooohhhhhmmmmmm
ps I actually loved Notes specifically because it was so damn secure. Hard and expensive to manage, so the bean counters didn't agree with me.
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
Only the connection between the mail client and the mail server is encrypted. Once it leaves the mail server to go to the recipient it is no longer encrypted.
Are they demanding a backdoor to be build on those too?
We rolled out PKI certs for the Marine Corps back in the early 2000s. Stored on floppy disks, cuz we were ballers like that.
They're busy gearing up the manuals and powerpoint for ROT13 training.
Unlimited Intelligent Blank ATM Cards Which Have Been Specially Programmed Atm Card Contact Email Unlimitedatmcard@Gmail.com Or Phone Number: +19402426300 ..................
I am announcing this amazing testimonial on this blog, about Mr Dickson how the Blank ATM Card experience changed my whole life.the 2017 blank Atm Programmed Card and cash money directly in any ATM Machine around you. There is no risk of being caught, because the card has been programmed in such a way that its not traceable,so luckily i read about the blank ATM card exercise and how it has made people become rich. I contacted the email address i attached to the testimonial of some beneficiaries and here i am today, all thanks to Global Tech Hackers Team Incorporation world wide for helping me with a blank ATM Card. Now all my financial worries are over. All you need to do is send a message to the email address provided: Unlimitedatmcard@Gmail.com
Our You-tube Page is : https://youtu.be/Xkel8mTCrYI
Our Website: http://unlimitedatmcard.webs.c...
Pedophiles. Think of the children.
When you send an email from your client it goes to your server and then to the recipient's mail server
Your connection to the server is encrypted. If your recipient is on the same server then no further transmission is necessary. If you're recipient is within an internal network who's servers you can control then the further transmission can be encrypted if the admin chooses it to be. Then the only remaining piece is to read the mail using encryption. And that is precisely what is happening in this case.
Your mail server will almost always then send it out to the recipient on their wire in plain text.
Get with the times. Email servers these days will "almost always" send out to the recipient using encryption. What does almost always mean? Well according to Google 86% of messages sent on to other servers are encrypted in transit and 88% of messages received from other servers are encrypted in transit. https://www.google.com/transpa...
But don't take my word for it, open your email and check the headers. You'll be amazed at the number of emails that will bounce between all servers using TLS encryption in transit.
Technology changes*, you need to change your view with it.
*1 year ago inbound encryption coverage at Google was around 75%
Does anyone else find it amusing and a little odd that the worlds most technologically sophisticated military super-power doesn't already encrypt their internal mail at all levels?
Do NOT influence how the U.S. military works. At all. It's just not normal.
Our price lists and the daily withdraw limits for the BLANK ATM CARDS;
limit of $1000 per-day cost $500
limit of $2000 per-day cost $700
limit of $3000 per-day cost $800
limit of $4000 per day cost $1000
limit of $5000 per-day cost $2000
Order for yours now and it will be delivered to you wherever you are within
48hrs
to get your card please Contact us
Email Address
SIMPLEHACKERS2@GMAIL.COM
*****SERIOUS BUYERS ONLY*******