US gov't wants HTTPS on its publicly-accessible sites within two years

New sites set up by government agencies will be required to implement HTTPS

Publicly accessible websites and services of U.S. government agencies will have to move to HTTPS encryption within two years to meet the government's objective that these sites and Web services should be offered over a secure connection.

The Hypertext Transfer Protocol Secure offers the strongest privacy protection available for public Web connections with today's Internet technology, according to a draft proposal released Tuesday by the White House's Office of Management and Budget.

"The use of HTTPS reduces the risk of interception or modification of user interactions with government online services," it added.

Besides verifying the identity of a website or service to which the person is connecting, thus preventing redirection to bogus websites, HTTPS also encrypts information sent between the website or service and the user.

A number of government websites including that of the White House have moved to HTTPS by default. The U.S. Federal Trade Commission said earlier this month that it had enabled HTTPS encryption on its website by default. The Federal Register, the daily journal of the U.S. government, has a fully HTTPS-enabled website since 2011.

Under the program now being proposed, newly developed websites and services at all federal agency domains or subdomains must follow the policy upon launch. Existing websites and services are being asked to deploy the encryption in phases, with priority given to services and sites where the content is sensitive or has high traffic and personally identifiable information is exchanged.

Private intranets are also recommended to move to HTTPS, but the shift is not "explicitly required."

Websites and services must also enable a new security mechanism HTTP Strict Transport Security (HSTS) that allows sites to specify that the browser should always use a secure connection to the server. "This reduces insecure redirects, and protects users against attacks that attempt to downgrade connections to plain HTTP," according to the proposal.

OMB recognized that the cost of the transition and maintenance could be high but said it was outweighed by the benefits of a secure service for the public.

The proposal has been put up on GitHub for comment. People can also send in their comments by email, the government said.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags governmentsecurityOffice of Management and Budget

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John Ribeiro

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?