US gov't wants HTTPS on its publicly-accessible sites within two years

New sites set up by government agencies will be required to implement HTTPS

Publicly accessible websites and services of U.S. government agencies will have to move to HTTPS encryption within two years to meet the government's objective that these sites and Web services should be offered over a secure connection.

The Hypertext Transfer Protocol Secure offers the strongest privacy protection available for public Web connections with today's Internet technology, according to a draft proposal released Tuesday by the White House's Office of Management and Budget.

"The use of HTTPS reduces the risk of interception or modification of user interactions with government online services," it added.

Besides verifying the identity of a website or service to which the person is connecting, thus preventing redirection to bogus websites, HTTPS also encrypts information sent between the website or service and the user.

A number of government websites including that of the White House have moved to HTTPS by default. The U.S. Federal Trade Commission said earlier this month that it had enabled HTTPS encryption on its website by default. The Federal Register, the daily journal of the U.S. government, has a fully HTTPS-enabled website since 2011.

Under the program now being proposed, newly developed websites and services at all federal agency domains or subdomains must follow the policy upon launch. Existing websites and services are being asked to deploy the encryption in phases, with priority given to services and sites where the content is sensitive or has high traffic and personally identifiable information is exchanged.

Private intranets are also recommended to move to HTTPS, but the shift is not "explicitly required."

Websites and services must also enable a new security mechanism HTTP Strict Transport Security (HSTS) that allows sites to specify that the browser should always use a secure connection to the server. "This reduces insecure redirects, and protects users against attacks that attempt to downgrade connections to plain HTTP," according to the proposal.

OMB recognized that the cost of the transition and maintenance could be high but said it was outweighed by the benefits of a secure service for the public.

The proposal has been put up on GitHub for comment. People can also send in their comments by email, the government said.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags governmentOffice of Management and Budget

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John Ribeiro

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?