René's URL Explorer Experiment


Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https · GitHub

Open Graph Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https

X Title: EFF public comment: HTTPS-Only is necessary and overdue · Issue #98 · GSA/https

Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of Management and Budget (OMB) and for com...

Open Graph Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of...

X Description: COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of...

Opengraph URL: https://github.com/GSA/https/issues/98

X: @github

direct link

Domain: github.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"EFF public comment: HTTPS-Only is necessary and overdue","articleBody":"COMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD\n\nThe Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of Management and Budget (OMB) and for comments regarding The HTTPS-Only Standard. EFF is a nonprofit civil liberties organization with more than 22,000 dues-paying members. It has worked for more than 20 years to protect consumer interests, innovation, and free expression in the digital world.\n\nHTTPS deployment in one of EFF's major topic areas. EFF's work in this area includes the SSL Observatory, a research project that catalogues existing deployment of HTTPS; Encrypt the Web, a longstanding project to encourage deployment of encryption, including a report on which major companies support various encryption technology; HTTPS Everywhere, a browser extension to help individuals discover and use the HTTPS version of websites; and Let's Encrypt, a collaboration with Mozilla to launch a free, automated certificate authority to decrease the barriers to entry in deploying HTTPS.\n\nEFF whole-heartedly supports the federal government's adoption of this essential cybersecurity standard. We also urge all state, local, and national governments worldwide to follow suit, as soon as possible.\n\nHTTPS, the secure version of HTTP, protects web browsing activity by encrypting and authenticating everything sent between an individual and a web server. It is rapidly replacing insecure HTTP on the Internet and security experts are [making plans](https://www.chromium.org/Home/chromium-security/marking-http-as-non-secure) to provide warnings when accessing HTTP pages.\n\nWithout HTTPS, a person's browsing activity can be monitored by anyone who controls their network or simply uses the same WiFi network (using a technique called [ARP poisoning](https://en.wikipedia.org/wiki/ARP_spoofing)). For many people, the list of possible snoops could include their employer, school, ISP, national spy agencies, parents, spouse, and/or fellow library patrons. HTTPS is not a silver bullet for all security and privacy problems, but no site can be secure or private without it.\n\nUnfortunately, federal web sites have lagged far behind industry in implementing HTTPS. The most popular commercial web sites, like Google, Facebook, and Twitter, have used HTTPS-only for years. But many federal web sites don't implement HTTPS at all, making it impossible to access them securely. Other sites implement HTTPS, but don't make it the default. And some offer HTTPS but with out-of-date, insecure software and configurations.\n\nGovernment web sites receive a wide array of confidential information. That information absolutely needs to be protected from eavesdropping. But HTTPS doesn't just protect uploaded information like social security numbers. It also protects the confidentiality of what people read. A few examples of how failure to deploy HTTPS puts citizens at risk:\n-  A worker downloading [information about her right to organize](http://www.dol.gov/olms/regs/compliance/employeerightsposter11x17_final.pdf) could by spied on by their employer and subjected to reprisals.\n- A veteran's affairs employee seeking to [report fraud anonymously](http://www.washingtonpost.com/politics/at-va-health-facilities-whistleblowers-still-fear-retaliation/2015/03/05/a6774bda-b944-11e4-9423-f3d0a1ec335c_story.html) could be illegally spied on by another arm of the government and unmasked for retaliation.\n- A US citizen abroad, [seeking gender reassignment information](http://travel.state.gov/content/passports/english/passports/information/gender.html) from the State Department, could be outed by local network snoops and imprisoned or killed.\n- An African-American [denied the right to vote](http://thinkprogress.org/election/2012/07/18/542501/study-photo-id-laws-place-substantial-burdens-on-low-income-and-minority-voters/) who seeks to [make a complaint](http://www.justice.gov/crt/complaint/#nine) to the Justice department could be spied on and intimidated by local officials.\n\nThis is just a sample of the many protected groups who need and deserve real confidential access to government services.\n\nFortunately, deployment of HTTPS is easier and cheaper than it has ever been. We call on the federal government to implement the [HTTPS-Only Standard](https://https.cio.gov/) as quickly as possible. State, local, and national governments worldwide should do the same.\n\nA version of this feedback, altered to introduce the HTTPS-Only standard to our readers, is available [on the EFF web site](https://www.eff.org/deeplinks/2015/04/the-federal-https-only-standard).\n","author":{"url":"https://github.com/jsha","@type":"Person","name":"jsha"},"datePublished":"2015-04-09T21:23:10.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/98/https/issues/98"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:5289f566-e4b0-ec58-4161-d274c0d6e195
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-id9E4E:E26C3:13E1ED2:1A3BA2E:69718C3A
html-safe-nonce40ec73af01cdef2ac08eb704a096f5ad1c54d99da7528f75186219e717b52cd1
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5RTRFOkUyNkMzOjEzRTFFRDI6MUEzQkEyRTo2OTcxOEMzQSIsInZpc2l0b3JfaWQiOiIyMTk3MDc4MjU1NjExMjUxNzcwIiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0=
visitor-hmac8405e06a410a9ab37758936ea10b388fef10418bea5c903a869f4a431ece1986
hovercard-subject-tagissue:67453915
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/GSA/https/98/issue_layout
twitter:imagehttps://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/98
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/cd2fe9378301f6d3ebcf2a1ba34019b4122a19915671ab7d2d994232b18e45e9/GSA/https/issues/98
og:image:altCOMMENTS OF THE ELECTRONIC FRONTIER FOUNDATION REGARDING THE HTTPS-ONLY STANDARD The Electronic Frontier Foundation (EFF) is grateful for this opportunity to respond to the request by the Office of...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernamejsha
hostnamegithub.com
expected-hostnamegithub.com
None2b0f2f00499ad3dd2c21ad030a3c403edca54df20ea256f6517c6d8c4fa3a1a4
turbo-cache-controlno-preview
go-importgithub.com/GSA/https git https://github.com/GSA/https.git
octolytics-dimension-user_id643070
octolytics-dimension-user_loginGSA
octolytics-dimension-repository_id28724827
octolytics-dimension-repository_nwoGSA/https
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id28724827
octolytics-dimension-repository_network_root_nwoGSA/https
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release67235153f3c1514ed5f7dc469f138abc377bd388
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/GSA/https/issues/98#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FGSA%2Fhttps%2Fissues%2F98
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FGSA%2Fhttps%2Fissues%2F98
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=GSA%2Fhttps
Reloadhttps://github.com/GSA/https/issues/98
Reloadhttps://github.com/GSA/https/issues/98
Reloadhttps://github.com/GSA/https/issues/98
GSA https://github.com/GSA
httpshttps://github.com/GSA/https
Notifications https://github.com/login?return_to=%2FGSA%2Fhttps
Fork 95 https://github.com/login?return_to=%2FGSA%2Fhttps
Star 280 https://github.com/login?return_to=%2FGSA%2Fhttps
Code https://github.com/GSA/https
Issues 16 https://github.com/GSA/https/issues
Pull requests 11 https://github.com/GSA/https/pulls
Actions https://github.com/GSA/https/actions
Projects 0 https://github.com/GSA/https/projects
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/GSA/https/security
Please reload this pagehttps://github.com/GSA/https/issues/98
Insights https://github.com/GSA/https/pulse
Code https://github.com/GSA/https
Issues https://github.com/GSA/https/issues
Pull requests https://github.com/GSA/https/pulls
Actions https://github.com/GSA/https/actions
Projects https://github.com/GSA/https/projects
Security https://github.com/GSA/https/security
Insights https://github.com/GSA/https/pulse
New issuehttps://github.com/login?return_to=https://github.com/GSA/https/issues/98
New issuehttps://github.com/login?return_to=https://github.com/GSA/https/issues/98
#108https://github.com/GSA/https/pull/108
EFF public comment: HTTPS-Only is necessary and overduehttps://github.com/GSA/https/issues/98#top
#108https://github.com/GSA/https/pull/108
Public Commenthttps://github.com/GSA/https/issues?q=state%3Aopen%20label%3A%22Public%20Comment%22
https://github.com/jsha
https://github.com/jsha
jshahttps://github.com/jsha
on Apr 9, 2015https://github.com/GSA/https/issues/98#issue-67453915
making planshttps://www.chromium.org/Home/chromium-security/marking-http-as-non-secure
ARP poisoninghttps://en.wikipedia.org/wiki/ARP_spoofing
information about her right to organizehttp://www.dol.gov/olms/regs/compliance/employeerightsposter11x17_final.pdf
report fraud anonymouslyhttp://www.washingtonpost.com/politics/at-va-health-facilities-whistleblowers-still-fear-retaliation/2015/03/05/a6774bda-b944-11e4-9423-f3d0a1ec335c_story.html
seeking gender reassignment informationhttp://travel.state.gov/content/passports/english/passports/information/gender.html
denied the right to votehttp://thinkprogress.org/election/2012/07/18/542501/study-photo-id-laws-place-substantial-burdens-on-low-income-and-minority-voters/
make a complainthttp://www.justice.gov/crt/complaint/#nine
HTTPS-Only Standardhttps://https.cio.gov/
on the EFF web sitehttps://www.eff.org/deeplinks/2015/04/the-federal-https-only-standard
Public Commenthttps://github.com/GSA/https/issues?q=state%3Aopen%20label%3A%22Public%20Comment%22
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.