Live data from Hacker News

Automatic HTTPS Enforcement for New Executive Branch .gov Domains

cio.gov

1–10 of 82 posts

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#2
Co-author of the post here, happy to answer questions. =)

This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant:

https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#3
As a practical question: what is the expected capacity of the preload stores of browsers? Hundreds of thousands, millions or much more domains? Because at some point it seems like everyone with moderately high security requirements may want to have their certificates pinned / preloaded.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#4
post #2

Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...

Any plans to force IPv6 adoption in the same manner?

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#5
This is fantastic news.

It wasn't that long ago that I tried to log into a government site via my SSN, and discovered that the page didn't even permit HTTPS. I was displeased, to say the least; logging in wasn't exactly optional, so it seemed much worse than a business offering poor security.

Permitting HTTPS is obviously the first step, but security shouldn't be limited to people with the expertise to seek it out. I'm really glad to see that something as inescapable as the .gov domain will be pursuing security-by-default.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#6
post #2

Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...

Any plans to force IPv6 adoption in the same manner?

IPv6 is pretty low priority compared to comprehensive HTTPS support.

Disclaimer: Not USDS/18F, just tech professional.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#8

Earlier quoted context omitted.

Any plans to force IPv6 adoption in the same manner?

IPv6 is pretty low priority compared to comprehensive HTTPS support. Disclaimer: Not USDS/18F, just tech professional.

Oh I agree, but the two things can be done at the same time. Especially for new .gov sites.

It appears a lot of .gov sites already support IPv6 but I was wondering if it's an official policy or just at the discretion of the tech team.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#9
post #3

As a practical question: what is the expected capacity of the preload stores of browsers? Hundreds of thousands, millions or much more domains? Because at some point it seems like everyone with moderately high security requirements may want to have their certificates pinned / preloaded.

I think that's an open question. Right now, it's not the millions, that'd be too much to bundle with browsers. But browsers may well change their delivery mechanism for preload information to allow this to scale higher.

In any case, .gov won't add much to the load -- right now there are all of 5,500 .gov domains, and the rate of adding/removal is on the order of dozens every month at most.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#10
post #2

Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...

Any plans to force IPv6 adoption in the same manner?

IPv6 is a federal mandate for agencies: https://www.whitehouse.gov/sites/default/files/omb/assets/eg...

And NIST has a dashboard of adoption: https://usgv6-deploymon.antd.nist.gov/cgi-bin/generate-gov

Post reply on HN