US government websites get HTTPS security boost

(Image credit: Shutterstock)

The US government's DotGov Program has announced that new .gov sites will only be accessible via HTTPS and that they will automatically be preloaded starting on September 1, 2020.

The program is overseen by the US General Services Administration (GSA) which operates the .gov top-level domain (TLD). The GSA also provides .gov domains to US-based government organizations from federal agencies to local municipalities.

In an announcement on its website, the DotGov Program explained the reason behind its decision to preload the .gov domain, saying:

“We believe the security benefits that come from preloading are meaningful and necessary to continue meeting the public’s expectation of safety on .gov services. We believe that government websites should always be secure.”

Preloading the .gov TLD

Following their move from HTTP to the HTTPS protocol, US government sites will secure visitors' connections using Transport Layer Security (TLS) protocol. This will encrypt any data that is exchanged and also protect users against man-in-the-middle attacks.

Although DotGov will preload the .gov TLD in September of this year, it will not be submitted to the HTTP Strict Transport Security (HSTS) preload list until a later date as doing so would make government sites that currently use HTTPS inaccessible. 

HSTS is a web server directive which tells web browsers to only connect using secure HTTPS connections. Web browsers bundle an HSTS preload list containing the names of all sites known to support secure connections so that browsers don't connect to them using an insecure protocol.

In a blog post, the DotGov Program provided further insight on what preloading the .gov TLD will entail, saying:

“Actually preloading is a simple step, but getting there will require concerted effort among the federal, state, local and tribal government organizations that use a common resource, but don’t often work together in this area. With concerted effort, we could preload .gov within a few years.”

To go about preloading the .gov TLD, the DotGov Program is currently collaborating with the Cybersecurity and Infrastructure Security Agency (CISA) to ensure that .gov domain owners are ready for their domains to be preloaded in the future. Also beginning on September 1, all new .gov domains will be automatically preloaded so that the program can focus on transitioning historical domains and not new ones to HTTPS.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over