White House Calls For Encryption By Default On Federal Websites By Late 2016

  /     /     /  
Publicated : 22/11/2024   Category : security


White House Calls For Encryption By Default On Federal Websites By Late 2016


Just 31% of federal agencies today host HTTPS websites and the Office of Management and Budget (OMB) has now given the rest of the government a deadline for doing so.



In yet another step toward making Internet encryption the new normal, the White House has instituted a new policy requiring all federal agencies to use HTTPS for their public-facing websites by the end of next year.
To date, only 31% of federal agencies run encrypted, HTTPS websites, including whitehouse.gov, cia.gov, nsa.gov, and omb.gov. Interestingly, dhs.gov and fbi.gov are among the agency websites that are not HTTPS-enabled as yet, according to
a federal website that tracks and grades HTTPS adoption
 among agencies.
The OMB first recommended the HTTPS-only policy in draft form in March, and this weeks announcement solidifies the plan with guidance and a December 31, 2016, deadline for adopting encrypted website communications via the standard.
Tony Scott, the administrations federal chief information officer, said
in the new policy memorandum
that all publicly accessible federal government websites and web services must deploy secure connections between the client and website via HTTPS, the Hypertext Transfer Protocol Secure.
Private and secure connections are becoming the Internets baseline, as expressed by the policies of the Internets standards bodies, popular web browsers, and the Internet community of practice. The Federal government must adapt to this changing landscape, and benefits by beginning the conversion now. Proactive investment at the Federal level will support faster internet-wide adoption and promote better privacy standards for the entire browsing public, Scott said in the announcement.
Although some Federal websites currently use HTTPS, there has not been a consistent policy in this area. An HTTPS-only mandate will provide the public with a consistent, private browsing experience and position the Federal Government as a leader in Internet security, he said.
The US governments encrypted website policy comes on the heels of a wave of SSL/TLS-related moves in the industry, including major websites including Facebook, Twitter, and LinkedIn, going encrypted in an age of privacy and security concerns. Google is even giving HTTPS sites a ranking boost. The Internet Activities Board (IAB) -- which oversees the Internets architecture, protocols, and standards efforts,
last November officially called for encryption to be instituted throughout the protocol stack
as a way to secure information exchange, and provide privacy.
IAB chairman Russ Housley also urged developers to deploy encryption by default, and for network and service providers to add it as well to their offerings.
Web security is in a dismal state, says Jeremiah Grossman, co-founder of WhiteHat Security. This is a step in the right direction for the feds, he says.
The catch, however, is just how such a massive number of agencies with large numbers of web pages and sites will manage their SSL/TLS certificates. Its unclear whether the feds will serve as their own certificate authority or not -- that information was not included in the policy. Efforts to reach the OMB prior to press time about the CA were unsuccessful.
Theyre going to have a crypto challenge. How are they going to do key management, agency by agency? Theyre going to run into logistics issues, having expiring SSL keys, for example, Grossman says.
Grossman says despite the inherent challenges of getting HTTPS everywhere in the government, the new policy is a win for everybody.
[Internet Architecture Board chairman Russ Housley explains what the IABs game-changing statement about encryption means for the future of the Net. Read
Q&A: Internet Encryption As The New Normal
.]
The White House encryption policy also comes amid the backdrop of a bitter battle between the FBI and the White House with members of the technology community over backdoors to encryption for helping law enforcement fight crime and terror. Members of the Information Technology Industry Council and the Software and Information Industry Association today
penned a letter to President Obama
 in protest of any policies that would allow for such backdoors.
No Fix For Hacks
HTTPS does not, of course, prevent website hacks or other security events -- a caveat Scott included in the OMB policy document.
HTTPS-only guarantees the integrity of the connection between two systems, not the systems themselves. It is not designed to protect a web server from being hacked or compromised, or to prevent the web service from exposing user information during its normal operation, he said. Similarly, if a users system is compromised by an attacker, that system can be altered so that its future HTTPS connections are under the attackers control. The guarantees of HTTPS may also be weakened or eliminated by compromised or malicious certificate authorities.
The administrations guidelines for HTTPS deployment calls for all new federal agency websites and services to be HTTPS from the get-go. It recommends HTTPS for intranets as well, but isnt requiring it.

Last News

▸ 27 Million South Koreans Hit by Online Gaming Theft. ◂
Discovered: 23/12/2024
Category: security

▸ Homeland Security Background Checks Breach Raises Concerns. ◂
Discovered: 23/12/2024
Category: security

▸ Fully committed to the future world of technology. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
White House Calls For Encryption By Default On Federal Websites By Late 2016