The US Army, Navy, DARPA, others do not implement STARTTLS, a basic email encryption protocol
How the US Military Fails to Protect Its Soldiers' Emails — Many government agencies, including the US military, are leaving the emails of soldiers and government employees potentially … Tweets: @ncweaver , @csoghoian and @trevortimm Tweets: Nicholas Weaver / @ncweaver : I'm sure every foreign intelligence service on the planet loves that almost all .mil doesn't use StartTLS: http://motherboard.vice.com/ ... Christopher Soghoian / @csoghoian : If you tweet about something enough - such as the gov not using email crypto - eventually someone will write about it http://motherboard.vice.com/ ... Trevor Timm / @trevortimm : How the US military fails to take the most basic steps to protect its soldiers' emails: http://motherboard.vice.com/ ...
Context & Ripple Effects
Researchers Nicholas Weaver and Christopher Soghoian spent weeks publicly pressing the point before Motherboard wrote it up: the Army, Navy, DARPA and other .mil domains were not implementing STARTTLS, the free opportunistic encryption layer that has existed for years. The finding landed because it was trivially fixable — this is configuration hygiene, not a research problem.
The story became a template for a longer arc. Two years later DHS issued a directive ordering federal agencies to adopt DMARC and STARTTLS, yet 2018 research found the CIA, NSA and DOD still had not rolled out DMARC across all their domains. The Pentagon's encryption gaps kept surfacing at higher stakes, from GAO findings on weak passwords to unencrypted data in ballistic missile systems.
First-order effects
- Soldiers' and government employees' email transits networks unencrypted, readable by any foreign intelligence service positioned to passively capture traffic — Weaver's exact concern in the tweets accompanying the piece.
- Army, Navy, and DARPA IT shops face immediate pressure to enable STARTTLS on their mail servers, a fix measured in configuration changes rather than procurement.
Second-order effects
- Public naming by security researchers forces a policy answer: DHS's 2017 directive converting voluntary best practices into mandated ones for every federal agency is the direct institutional response.
- Auditors adopt email crypto as a recurring test case — the same 2018 reporting window produced GAO findings on Pentagon password hygiene and a DoD report flagging missing encryption in ballistic missile systems, turning 'basic protocol not deployed' into a standing audit category.
Third-order effects
- A structural gap emerges between issuing directives and verifying deployment: agencies can be formally ordered (2017) and still found non-compliant (2018), suggesting mandates without enforcement mechanisms leave the exposure intact.
- If the pattern holds, military communications drift toward consumer-grade encrypted messaging apps as workarounds — a dynamic visible again when an internal NSA memo warned staff about Signal use in 2025, pushing sensitive traffic onto tools outside government control.
The trend: Federal cybersecurity keeps repeating the same cycle — researcher disclosure, directive, slow agency adoption — with each audit showing basic-protocol gaps persisting years after they were first flagged.