Automatic HTTPS Enforcement for New Executive Branch .gov Domains
1–10 of 82 posts
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#2This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant:
https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#3Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#4Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#5It wasn't that long ago that I tried to log into a government site via my SSN, and discovered that the page didn't even permit HTTPS. I was displeased, to say the least; logging in wasn't exactly optional, so it seemed much worse than a business offering poor security.
Permitting HTTPS is obviously the first step, but security shouldn't be limited to people with the expertise to seek it out. I'm really glad to see that something as inescapable as the .gov domain will be pursuing security-by-default.
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#6Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...
Any plans to force IPv6 adoption in the same manner?
Disclaimer: Not USDS/18F, just tech professional.
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#7Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#8Earlier quoted context omitted.
Any plans to force IPv6 adoption in the same manner?
IPv6 is pretty low priority compared to comprehensive HTTPS support. Disclaimer: Not USDS/18F, just tech professional.
It appears a lot of .gov sites already support IPv6 but I was wondering if it's an official policy or just at the discretion of the tech team.
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#9As a practical question: what is the expected capacity of the preload stores of browsers? Hundreds of thousands, millions or much more domains? Because at some point it seems like everyone with moderately high security requirements may want to have their certificates pinned / preloaded.
In any case, .gov won't add much to the load -- right now there are all of 5,500 .gov domains, and the rate of adding/removal is on the order of dozens every month at most.
Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains
#10Co-author of the post here, happy to answer questions. =) This is a GSA initiative, not an 18F initiative. But 18F has a recent post detailing executive branch progress on HTTPS that may also be relevant: https://18f.gsa.gov/2017/01/04/tracking-the-us-governments-p...
Any plans to force IPv6 adoption in the same manner?
And NIST has a dashboard of adoption: https://usgv6-deploymon.antd.nist.gov/cgi-bin/generate-gov