In Nod To Privacy, Feds Say Every Agency Website Will Be Encrypted

Whitehouse.gov/AP

While the "HTTPS-Only Standard" makeover likely won’t happen overnight, privacy proponents cheered the effort.

The White House is planning to mandate that all agency websites use HTTPS encryption to protect citizens from online eavesdroppers. While the "HTTPS-Only Standard" makeover likely won’t happen overnight, privacy proponents cheered the effort.

Today, hundreds of the federal government's roughly 1,200 websites, including IRS.gov, still use the insecure protocol, HTTP. It was only last week WhiteHouse.gov, yielding to criticism, switched to HTTPS or Hypertext Transfer Protocol.

It is unclear when the proposed policy will be finalized. The deadline for feedback on the proposal is March 31, according to a new HTTPS-secure website promoting the initiative.

Agencies would have two years to comply, once a final policy is issued. Layering the technology over existing communications lines typically carries some costs.

Many e-commerce sites have long embraced HTTPS by default. And increasingly, law firms are moving to insulate their clients from snooping. That is partly the work of Christopher Soghoian, an American Civil Liberties Union principal technologist, who for many, many months has been enticing attorneys (and media outlets) with free bottles of whiskey, in jest, to turn on HTTPS. [Full disclosure: Nextgov.com does not use HTTPS.]

"I won't be buying whiskey for all federal agencies," he said Tuesday in an interview. "There are ethical reasons behind it. And my NGO salary doesn't stretch that far. We think this is a really, really good move in terms of protecting the privacy of Americans."

That said, the policy would be exclusive to the executive branch. The courts and Congress have no set rule on website encryption. And in a world where there is no such thing as nonsensitive data, the absence of HTTPS could infringe on citizens’ privacy and compromise trust in government websites. 

"If you're a constituent and you are looking up your member's position on a sensitive issue like gun control or abortion or religion in schools, anyone watching the network -- which could mean your employer, your university, your Internet provider -- they could learn what political issues you are interested in,” Soghoian said. "And that is obviously extremely sensitive information that no one else has any business knowing."

Communications interceptions can violate more than just privacy. They can betray trust in online documents, videos and other content.

"You should be confident when you read a judicial opinion on the Web that you are getting the real one," Soghoian said. 

CIA.gov -- a Bastion of Online Trust Since 2006

Already, some key government sites, including HealthCare.gov and the Federal Trade Commission's FTC.gov, use the secure connection. The General Services Administration's digital invention shop, 18F, recently pledged to install HTTPS on all sites it creates for agencies. CIA.gov has used HTTPS since 2006. 

"There are these pockets of excellence within the federal government, but up until now the norm has been insecurity and it's really nice to see things moving in the right direction," Soghoian said. 

Agencies might have to invest considerable time and money to obtain the protections. 

Many major organizations, including the IRS and Apple, use “content distribution networks” to serve up their pages to users faster. Some of these networks charge agencies several thousand dollars per month to institute HTTPS, Soghoian said. Amazon's CloudFront and CloudFlare offer the technology free, but Akamai, a big federal vendor, does not, he said. 

On the new site launched Tuesday, federal officials said the "tangible benefits to the American public outweigh the cost to the taxpayer.”

HTTPS hides form submissions, webpage visits, cookies and other data when it is in transit -- whether the data originates from the user or the site. 

However, it cannot completely cover one's footsteps online. Interlopers can learn a user is visiting certain website extensions, if not the exact webpages. Other visible metadata can allow intruders to extrapolate what an Internet user is up to, such as the time spent on a site or the size of a requested transfer. 

And HTTPS isn’t impervious to fraud. Hackers can forge digital "certificates," which are used to tell Web browsers a connection is secure. By inserting a stolen or phony certificate, an attacker can drop into the middle of the virtual conversation and toy with communications, an experience suffered by Google and Yahoo, among others. 

On Tuesday, Ars Technica reported that Microsoft right now is rushing to suppress fallout from a certificate forgery. A fake HTTPS certificate was issued for one of the firm’s Windows Live websites, live.fi or www.live.fi, so attackers might be able to launch man-in-the-middle attacks, according to Ars.

Unlike other areas of cybersecurity, this is not a case of the federal government leading by example -- yet. The HTTP format "leaves Americans vulnerable to known threats, and reduces their confidence in their government," federal officials said. "The proposed HTTPS-only standard will provide the public with a consistent, private browsing experience and position the federal government as a leader in Internet security."

As of Tuesday afternoon, Soghoian was still taking to Twitter to urge organizations to “encrypt all the things” in the Internet of Things.

"We're getting close to tax time, and it's not good the IRS still does not use HTTPS," Soghoian said. "It's an embarrassment."

IRS officials were not immediately able to comment. White House officials did not respond to requests for comment. 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.