Live data from Hacker News

Automatic HTTPS Enforcement for New Executive Branch .gov Domains

cio.gov

81–82 of 82 posts

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#81
post #75

Earlier quoted context omitted.

What you're trusting the browser for there is the extra protection that preloading provides, but that's not the whole benefit here. The larger benefit is that it makes it infeasible for services to neglect to support HTTPS. So, even if your browser's preload list is busted, the site will be guaranteed to support HTTPS because of this effort, which you'll still benefit from.

Ah ok. I think I see what you are saying now. As long as a sizeable portion of browsers support a fresh version of the preloaded list, there is sufficient customer feedback to push the servers to only support https. Right?

Exactly.

Re: Automatic HTTPS Enforcement for New Executive Branch .gov Domains

#82

It should really be .gov.us rather than a top level domain.

.gov, .mil, and .edu predate the existence of country-code TLDs. They're a legacy of when the Internet was a US government funded research project. You could argue that since the Internet has become a global commercial network, the US should no longer have these special, exclusive TLDs. But switching over would be a ton of work, and there really aren't enough downsides to the US having these domains to justify a chan…

In fact, there are now way more state/local .gov domains (~4,000) than federal .gov domains (~1,300).
Post reply on HN