I don't think that's correct. Cryptographic authentication of messages should be allowed (ARRL agrees with me[0]), the language specifies you cannot "obscure the meaning" of the communication.
That's correct. There's one exception to the encryption rule, which is when sending commands to a space station. (That does not allow you to encrypt the responses, though.) See 47 CFR 97.211, https://www.law.cornell.edu/cfr/text/47/97.211