Application Security
6/9/2015
03:35 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
100%
0%

White House Calls For Encryption By Default On Federal Websites By Late 2016

Just 31% of federal agencies today host HTTPS websites and the Office of Management and Budget (OMB) has now given the rest of the government a deadline for doing so.

In yet another step toward making Internet encryption the new normal, the White House has instituted a new policy requiring all federal agencies to use HTTPS for their public-facing websites by the end of next year.

To date, only 31% of federal agencies run encrypted, HTTPS websites, including whitehouse.gov, cia.gov, nsa.gov, and omb.gov. Interestingly, dhs.gov and fbi.gov are among the agency websites that are not HTTPS-enabled as yet, according to a federal website that tracks and grades HTTPS adoption among agencies.

The OMB first recommended the HTTPS-only policy in draft form in March, and this week's announcement solidifies the plan with guidance and a December 31, 2016, deadline for adopting encrypted website communications via the standard.

Tony Scott, the administration's federal chief information officer, said in the new policy memorandum that all publicly accessible federal government websites and web services must deploy secure connections between the client and website via HTTPS, the Hypertext Transfer Protocol Secure.

"Private and secure connections are becoming the Internet's baseline, as expressed by the policies of the Internet's standards bodies, popular web browsers, and the Internet community of practice. The Federal government must adapt to this changing landscape, and benefits by beginning the conversion now. Proactive investment at the Federal level will support faster internet-wide adoption and promote better privacy standards for the entire browsing public," Scott said in the announcement.

"Although some Federal websites currently use HTTPS, there has not been a consistent policy in this area. An HTTPS-only mandate will provide the public with a consistent, private browsing experience and position the Federal Government as a leader in Internet security," he said.

The US government's encrypted website policy comes on the heels of a wave of SSL/TLS-related moves in the industry, including major websites including Facebook, Twitter, and LinkedIn, going encrypted in an age of privacy and security concerns. Google is even giving HTTPS sites a ranking boost. The Internet Activities Board (IAB) -- which oversees the Internet's architecture, protocols, and standards efforts, last November officially called for encryption to be instituted throughout the protocol stack as a way to secure information exchange, and provide privacy.

IAB chairman Russ Housley also urged developers to deploy encryption by default, and for network and service providers to add it as well to their offerings.

"Web security is in a dismal state," says Jeremiah Grossman, co-founder of WhiteHat Security. "This is a step in the right direction" for the feds, he says.

The catch, however, is just how such a massive number of agencies with large numbers of web pages and sites will manage their SSL/TLS certificates. It's unclear whether the feds will serve as their own certificate authority or not -- that information was not included in the policy. Efforts to reach the OMB prior to press time about the CA were unsuccessful.

"They're going to have a crypto challenge. How are they going to do key management, agency by agency? They're going to run into logistics issues, having expiring SSL keys," for example, Grossman says.

Grossman says despite the inherent challenges of getting HTTPS everywhere in the government, the new policy is a "win for everybody."

[Internet Architecture Board chairman Russ Housley explains what the IAB's game-changing statement about encryption means for the future of the Net. Read Q&A: Internet Encryption As The New Normal.]

The White House encryption policy also comes amid the backdrop of a bitter battle between the FBI and the White House with members of the technology community over backdoors to encryption for helping law enforcement fight crime and terror. Members of the Information Technology Industry Council and the Software and Information Industry Association today penned a letter to President Obama in protest of any policies that would allow for such backdoors.

No Fix For Hacks

HTTPS does not, of course, prevent website hacks or other security events -- a caveat Scott included in the OMB policy document.

"HTTPS-only guarantees the integrity of the connection between two systems, not the systems themselves. It is not designed to protect a web server from being hacked or compromised, or to prevent the web service from exposing user information during its normal operation," he said. "Similarly, if a user's system is compromised by an attacker, that system can be altered so that its future HTTPS connections are under the attacker's control. The guarantees of HTTPS may also be weakened or eliminated by compromised or malicious certificate authorities."

The administration's guidelines for HTTPS deployment calls for all new federal agency websites and services to be HTTPS from the get-go. It recommends HTTPS for intranets as well, but isn't requiring it.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
6/9/2015 | 6:38:04 PM
Apple...
in its iOS 9 dev documentation calls for HTTPS as the default. Security is improving, if slowly.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Security Technologies to Watch in 2017
Emerging tools and services promise to make a difference this year. Are they on your company's list?
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.