Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https · GitHub
Open Graph Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https
X Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https
Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of Management and Budget (OMB) and for com...
Open Graph Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of...
X Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of...
Opengraph URL: https://github.com/GSA/https/issues/98
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"EFF public comment: HTTPS-Only is necessary and overdue","articleBody":"COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD\n\nThe Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of Management and Budget (OMB) and for comments regarding The HTTPS-Only Standard. EFF is a nonprofit civil liberties organization with more than 22,000 dues-paying members. It has worked for more than 20 years to protect consumer interests, innovation, and free expression in the digital world.\n\nHTTPS deployment in one of EFF's major topic areas. EFF's work in this area includes the SSL Observatory, a research project that catalogues existing deployment of HTTPS; Encrypt the Web, a longstanding project to encourage deployment of encryption, including a report on which major companies support various encryption technology; HTTPS Everywhere, a browser extension to help individuals discover and use the HTTPS version of websites; and Let's Encrypt, a collaboration with Mozilla to launch a free, automated certificate authority to decrease the barriers to entry in deploying HTTPS.\n\nEFF whole-heartedly supports the federal government's adoption of this essential cybersecurity standard. We also urge all state, local, and national governments worldwide to follow suit, as soon as possible.\n\nHTTPS, the secure version of HTTP, protects web browsing activity by encrypting and authenticating everything sent between an individual and a web server. It is rapidly replacing insecure HTTP on the Internet and security experts are [making plans](https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure) to provide warnings when accessing HTTP pages.\n\nWithout HTTPS, a person's browsing activity can be monitored by anyone who controls their network or simply uses the same WiFi network (using a technique called [ARP poisoning](https://en.wikipedia.org/wiki/ARP_spoofing)). For many people, the list of possible snoops could include their employer, school, ISP, national spy agencies, parents, spouse, and/or fellow library patrons. HTTPS is not a silver bullet for all security and privacy problems, but no site can be secure or private without it.\n\nUnfortunately, federal web sites have lagged far behind industry in implementing HTTPS. The most popular commercial web sites, like Google, Facebook, and Twitter, have used HTTPS-only for years. But many federal web sites don't implement HTTPS at all, making it impossible to access them securely. Other sites implement HTTPS, but don't make it the default. And some offer HTTPS but with out-of-date, insecure software and configurations.\n\nGovernment web sites receive a wide array of confidential information. That information absolutely needs to be protected from eavesdropping. But HTTPS doesn't just protect uploaded information like social security numbers. It also protects the confidentiality of what people read. A few examples of how failure to deploy HTTPS puts citizens at risk:\n- A worker downloading [information about her right to organize](http://www.dol.gov/olms/regs/compliance/employeerightsposter11x17_final.pdf) could by spied on by their employer and subjected to reprisals.\n- A veteran's affairs employee seeking to [report fraud anonymously](http://www.washingtonpost.com/politics/at-va-health-facilities-whistleblowers-still-fear-retaliation/2015/03/05/a6774bda-b944-11e4-9423-f3d0a1ec335c_story.html) could be illegally spied on by another arm of the government and unmasked for retaliation.\n- A US citizen abroad, [seeking gender reassignment information](http://travel.state.gov/content/passports/english/passports/information/gender.html) from the State Department, could be outed by local network snoops and imprisoned or killed.\n- An African-American [denied the right to vote](http://thinkprogress.org/election/2012/07/18/542501/study-photo-id-laws-place-substantial-burdens-on-low-income-and-minority-voters/) who seeks to [make a complaint](http://www.justice.gov/crt/complaint/#nine) to the Justice department could be spied on and intimidated by local officials.\n\nThis is just a sample of the many protected groups who need and deserve real confidential access to government services.\n\nFortunately, deployment of HTTPS is easier and cheaper than it has ever been. We call on the federal government to implement the [HTTPS-Only Standard](https://https.cio.gov/) as quickly as possible. State, local, and national governments worldwide should do the same.\n\nA version of this feedback, altered to introduce the HTTPS-Only standard to our readers, is available [on the EFF web site](https://www.eff.org/deeplinks/2015/04/the-federal-https-only-standard).\n","author":{"url":"https://github.com/jsha","@type":"Person","name":"jsha"},"datePublished":"2015-04-09T21:23:10.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/98/https/issues/98"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:5289f566-e4b0-ec58-4161-d274c0d6e195 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 9E4E:E26C3:13E1ED2:1A3BA2E:69718C3A |
| html-safe-nonce | 40ec73af01cdef2ac08eb704a096f5ad1c54d99da7528f75186219e717b52cd1 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5RTRFOkUyNkMzOjEzRTFFRDI6MUEzQkEyRTo2OTcxOEMzQSIsInZpc2l0b3JfaWQiOiIyMTk3MDc4MjU1NjExMjUxNzcwIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 8405e06a410a9ab37758936ea10b388fef10418bea5c903a869f4a431ece1986 |
| hovercard-subject-tag | issue:67453915 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/GSA/https/98/issue_layout |
| twitter:image | https://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/98 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/98 |
| og:image:alt | COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | jsha |
| hostname | github.com |
| expected-hostname | github.com |
| None | 2b0f2f00499ad3dd2c21ad030a3c403edca54df20ea256f6517c6d8c4fa3a1a4 |
| turbo-cache-control | no-preview |
| go-import | github.com/GSA/https git https://github.com/GSA/https.git |
| octolytics-dimension-user_id | 643070 |
| octolytics-dimension-user_login | GSA |
| octolytics-dimension-repository_id | 28724827 |
| octolytics-dimension-repository_nwo | GSA/https |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 28724827 |
| octolytics-dimension-repository_network_root_nwo | GSA/https |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 67235153f3c1514ed5f7dc469f138abc377bd388 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width