{"id":12495,"date":"2020-06-26T10:15:19","date_gmt":"2020-06-26T14:15:19","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=12495"},"modified":"2020-09-16T11:04:01","modified_gmt":"2020-09-16T15:04:01","slug":"gov-domains-to-force-https-hsts-preloading-will-be-enabled-starting-sept-1","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/gov-domains-to-force-https-hsts-preloading-will-be-enabled-starting-sept-1\/","title":{"rendered":"New .Gov Domains to Force HTTPS: HSTS Preloading Will Be Enabled Starting Sept. 1"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">In a move that aims to make all U.S. federal, state and county websites more secure, the General Services Administration\u2019s DotGov Program announces that new government domains will be added to the HSTS preload list starting this fall as part of a larger move toward the eventual full .gov migration to HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">What\u2019s massive, bloated, and slow to change?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your answer is \u201cthe U.S. government,\u201d then you\u2019d be correct. I say this because it\u2019s 2020, and we\u2019re <em>still<\/em> watching the government (slowly) add SSL\/TLS certificates to their websites to ensure secure connections. This is even after the <a href=\"https:\/\/www.thesslstore.com\/blog\/encryption-watch-almost-half-us-federal-websites-still-not-secure\/\">Obama administration issued an executive order<\/a> in 2015 (<a href=\"https:\/\/obamawhitehouse.archives.gov\/sites\/default\/files\/omb\/memoranda\/2015\/m-15-13.pdf\">M-15-13<\/a>) that compelled them to do so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Heck, my predecessor, Patrick Nohe, even started a White House petition to compel the General Services Administration (GSA) to <a href=\"https:\/\/www.thesslstore.com\/blog\/compel-gsa-add-gov-tld-hsts-preload-list\/\">add the .gov TLD to the global browser HSTS preload list<\/a> (although that didn\u2019t get enough votes \u2014 most likely because not enough people understood the importance of what he was trying to accomplish).<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<p class=\"wp-block-paragraph\">Needless to say, this migration to HTTPS is happening a lot more slowly than we\u2019d like. But there is some good news that we\u2019re happy to share: The DotGov Program has <a rel=\"noreferrer noopener\" href=\"https:\/\/home.dotgov.gov\/management\/preloading\/dotgovhttps\/\" target=\"_blank\">announced their intention to add new .gov domains to the HSTS preload list<\/a> starting Sept. 1, 2020. &nbsp;This means that they\u2019re showing their commitment to serving all of their websites via the secure HTTPS protocol (eventually).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, what does HSTS preloading mean for government website users and website security as a whole? And what does it mean for the future of HTTP?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is HSTS Preloading and Why Does It Mean Greater Security for End Users?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Simply put, HSTS \u2014 or what\u2019s also known as <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-hypertext-strict-transport-security-hsts\/\">HTTP Strict Transport Security<\/a> \u2014 is a web security policy that forces a browser to only make secure HTTPS (Hypertext Transfer Protocol Secure) connections with the relevant website. Even if the user types in \u201chttp:\/\/,\u201d the browser will ignore that and use \u201chttps:\/\/\u201d anyway.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is great, right? It means that it\u2019s going to force browsers to use a more secure connection no matter what.<em> <\/em>However, there\u2019s one small caveat with HSTS: it uses a header to communicate the strict transport security parameter. This means that you\u2019d need to download the header <em>before<\/em> your browser knows to always connect to the website via HTTPS in the future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because the policy communicates this way, it means that there\u2019s a small window of opportunity (before the browser downloads the header) in which hackers could swoop in during that first connection. Although it\u2019s a very narrow attack vector and, with the right tools, a bad guy could eliminate the SSL encryption connection and, ultimately, steal data or phish your users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, this is where HSTS preloading saves the day. <strong>The HSTS preload list is a set of websites that are hardcoded into browsers to employ strict transport security.<\/strong> What this means is that when someone connects to a website on the HSTS preload list for the first time, the browser already knows that it must connect only using an HTTPS connection, thereby eliminating that small window of opportunity for hackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, by adding government websites to the HSTS preload list, it means that all of the browsers using the list will already know that they can only connect using HTTPS. (Hence why it\u2019s call \u201cHSTS preloading, because you\u2019re preloading the list with those specific domains.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An additional added benefit of HSTS preloading is that users will experience faster page load speeds because the browsers will no longer require server redirects from HTTP to HTTPS. Sounds like a real win-win, if you ask me.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Data Transfers Across the Internet Without the Use of HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">But why is HSTS preloading \u2014 and using HTTPS in general \u2014 really necessary? Let\u2019s take a moment for a quick refresher on how data transmits across the internet for sites that don\u2019t use HTTPS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Any info that\u2019s sent between two parties (for example, your end users\u2019 web browser and the website they\u2019re connected to) via the internet is sent in plaintext format. This means that <strong>any data sent using HTTP can be intercepted and read by anyone<\/strong> \u2014 your nosy neighbor Tim, your employer, government entities, or a random (and potentially malicious) hacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not only is this a big privacy issue, but it\u2019s also a security issue that can result in identity theft and a litany of other types of cybercrimes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HTTPS Secures Data in Transit<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In a nutshell, HTTPS is a connection made via the transport layer security, which is a combination of encryption and <a href=\"https:\/\/www.thesslstore.com\/blog\/digital-signatures-why-you-should-sign-everything\/\">digital signatures<\/a>. This type of connection enables the communication channel between the two parties to be encrypted to ensure data transmissions are secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the DotGov website:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cHTTPS is a key protection for websites and web users. It offers security and privacy when connecting to the web, and provides governments the assurance that what they publish is what is delivered to users. In the last few years, HTTPS has become the default connection type on the web.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Google\u2019s latest <a href=\"https:\/\/transparencyreport.google.com\/https\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Transparency Report data<\/a> (as of June 13, 2020) shows that 95% of users connect via HTTPS:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"627\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/google-transparency-https-traffic-1024x627.png\" alt=\"A chart from Google's Transparency Report relating to the use of HTTPS\" class=\"wp-image-12496 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/google-transparency-https-traffic-1024x627.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/google-transparency-https-traffic-300x184.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/google-transparency-https-traffic-768x470.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/google-transparency-https-traffic.png 1160w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Image source: <a href=\"https:\/\/transparencyreport.google.com\/https\/overview\" target=\"_blank\" rel=\"noreferrer noopener\">Google Transparency Report<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">And this is great \u2014 95% of users is the overwhelming majority. But it\u2019s still not at the level that website users need it to be. For a truly secure internet, this number should be at the full 100%. But, hey, we understand that Rome wasn\u2019t built in a day. And considering that the internet was originally built for government use (for scientists and researchers to share data) and not for the personal or commercial use it\u2019s evolved to today, it\u2019s <em>a little<\/em> understandable why these changes take time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s important to note, however, that while <strong>HTTPS only guarantees the integrity of the connection between two parties or systems \u2014 it doesn\u2019t guarantee that the system or website that an individual connects to is legitimate.<\/strong> So, you could be securely connected to a website, but HTTPS doesn\u2019t ensure that it\u2019s the <em>real<\/em> site. This is the difference between being \u201csafe\u201d and being \u201csecure\u201d \u2014 it\u2019s also where <a href=\"https:\/\/www.thesslstore.com\/blog\/10-types-of-phishing-attacks-and-phishing-scams\/\">fake\/phishing websites<\/a> can <em>really<\/em> ruin your day.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Where SSL\/TLS Certificates Come Into Play for Website Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Using encryption on a website isn\u2019t going to do you any good if you\u2019re connecting to a hacker\u2019s device instead of the legitimate server. However, there is a solution: install a minimum of organization validated (OV) SSL\/TLS certificates on your web server. By using an OV (or extended validation) SSL\/TLS certificate on your website, you\u2019re ensuring that any data transmitted between users and your website is secure by:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Authenticating the web server to the client. <\/strong>This enables clients to verify that they\u2019re actually connecting to a legitimate party because the site and organization that owns it has been validated by a trusted third party (certificate authority [CA]).<\/li><li><strong>Using an encryption key to secure the channel.<\/strong> What this does it transmit data via a secure connection so it appears as gibberish to any non-intended parties \u2014 this way, anyone outside the channel can\u2019t decrypt and read the data transmitting within it because they don\u2019t have a key. &nbsp;<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Using an SSL\/TLS certificate to facilitate an HTTPS connection helps to protect users against eavesdropping and man-in-the-middle (MitM) attacks. But OV\/EV SSL takes security a step further by adding identity assurance that validates the identity of the organization, government, or business to whom a website belongs.<\/p>\n\n\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n\n\n\n<h2 class=\"wp-block-heading\">30,000 Foot Perspective: What This Shift to HTTPS (via HSTS Preloading) Means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For starters, this mass move to HTTPS via HSTS preloading is obviously a great security measure. However, it\u2019s not perfect and still means we have a long way to go. <strong>Despite the fact that Google pretty much made HTTPS mandatory for websites to rank several years ago, <a href=\"https:\/\/www.thesslstore.com\/blog\/one-quarter-federal-websites-no-https\/\">not all government websites have migrated to HTTPS<\/a>.<\/strong> For example, the <a href=\"http:\/\/www.floridahealth.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Florida Department of Health<\/a> website loads via the insecure HTTP connection:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"306\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/florida-dept-of-health-insecure-website-1024x306.png\" alt=\"Screenshot of the Florida Department of Health website using an insecure HTTP connection\" class=\"wp-image-12497 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/florida-dept-of-health-insecure-website-1024x306.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/florida-dept-of-health-insecure-website-300x90.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/florida-dept-of-health-insecure-website-768x229.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/florida-dept-of-health-insecure-website.png 1376w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Graphic: A screenshot of the insecure HTTP connection made on the Florida Department of Health website on June 24, 2020.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The same can be said about the New York State Library website:<img loading=\"lazy\" decoding=\"async\" width=\"662\" height=\"237\" src=\"\"><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"480\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/ny-state-library-1024x480.png\" alt=\"A screenshot of the New York Library's official website using an insecure HTTP connection\" class=\"wp-image-12498 addshadow\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/ny-state-library-1024x480.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/ny-state-library-300x141.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/ny-state-library-768x360.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/ny-state-library.png 1257w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>Graphic: A screenshot of the insecure HTTP connection made on the New York State Library website on June 24, 2020. (It&#8217;s using an insecure connection, much like the rest of the New York State Department of Education website.)<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, there are still plenty of other government sites that don\u2019t use HTTPS. The silver lining here, though, is that since May 2017, any new federal executive branch .gov domains have been&nbsp;<a href=\"https:\/\/www.cio.gov\/2017\/01\/19\/automatic-https.html\" target=\"_blank\" rel=\"noreferrer noopener\">automatically added<\/a>&nbsp;to the HSTS preload list. Furthermore, since August 2018, they\u2019ve also allowed other newly registered .gov domains to opt-in to this protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now, why they didn\u2019t just make it mandatory for <em>all<\/em> .gov domains instead of leaving it as an opt in? You\u2019d have to ask them. But at least this move is still a step in the right direction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Of course, this HSTS preloading initiative isn\u2019t going to be without its struggles. In the DotGov Program\u2019s report \u201cMaking .gov More Secure by Default,\u201d they admit that while the HSTS preloading process itself is easy, getting everyone to the table that the change would affect is going to be quite the undertaking:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p><em>\u201cNote that we\u2019re announcing&nbsp;an intent to preload the TLD, but&nbsp;<strong>not actually preloading it today<\/strong>. If we did that, some government websites that don\u2019t offer HTTPS would become inaccessible to users, and we don\u2019t want to negatively impact services on our way to enhancing them!&nbsp;Actually preloading&nbsp;is a simple step, but getting there will require concerted effort among the federal, state, local and tribal government organizations that use a common resource, but don\u2019t often work together in this area.<\/em><\/p><p><em>With concerted effort, we could preload .gov within a few years.\u201d<\/em><\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts on Adding All Government Domains to HSTS Preload List<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The concern here would be that even though 95% of traffic is connecting to websites using HTTPS, it means that there\u2019s still 5% that\u2019s not. Even if you just narrow this down to traffic connecting to government domains, that\u2019s still a lot of people and potentially missed connections if the process isn\u2019t handled properly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Okay, that\u2019s the bad news \u2014 but there is good news. For one, this means that if they take their time, they\u2019ll (hopefully) do it right. (Okay, I know there\u2019s an obvious punchline about government efficiency here, but let\u2019s keep things civil.) Basically, they\u2019ve announced their intention to add all future .gov sites to the HSTS preload list. So, any future sites after that date need to be set up as HTTPS only.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Secondly, this shift to HTTPS via HSTS preloading means that the insecure HTTP protocol is now one step closer to its (inevitable) demise. This move by the DotGov Program to ensure government website users will only be able to connect via secure connections in the future essentially pounding a massive nail into the coffin of HTTP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All in all, we\u2019re glad to see that DotGov Program has made the public commitment to greater website safety through HSTS preloading. Frankly, it\u2019s been long overdue. However, Uncle Sam is quick to hedge his bet about the progress of the initiative by stating up front that this isn\u2019t going to be a quick move. So, we should prepare ourselves for some bumps along the road ahead.<\/p>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>\n","protected":false},"excerpt":{"rendered":"<p>In a move that aims to make all U.S. government websites more secure, the General Services Administration\u2019s DotGov Program announces the migration of government domains to the HSTS preload list starting this fall<\/p>\n","protected":false},"author":17,"featured_media":12503,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[160,12430],"class_list":["post-12495","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-hsts","tag-hsts-preloading","post-with-tags"],"views":20888,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2020\/06\/hsts-preloading-make-gov-sites-secure2.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=12495"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/12495\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/12503"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=12495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=12495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=12495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}