New US Executive Branch Websites to Force HTTPS

new-us-executive-branch-websites-to-force-https photo 1

The government missed the Obama administration's Dec. 31 deadline to enable HTTPS encryption on all federal websites using the .gov domain. But all new websites issued under the Trump administration will be served to Web browsers with HTTPS automatically enabled, the General Services Administration announced on Thursday.

It's a consolation prize that doesn't require any extra work: the GSA can flip the equivalent of a digital switch for all new websites, telling modern Web browsers like Google Chrome to only load the HTTPS version of the page. The process, known as HTTP Strict Transport Security (HSTS), is already widely used. You've probably seen it in action if you type in a website URL like "http://www.newegg.com," and your browser automatically translates the request into https://www.newegg.com.

The GSA will only enable HSTS by default for new executive branch websites starting this spring, although many existing websites in all three federal government branches already support it. In order for it to work, the site must ensure that all of its subdomains and associated Web services support HTTPS encryption, a task that's much easier for brand new sites than those that are decades old.

Related

  • Feds Must Encrypt Government Websites by Dec. 2016Feds Must Encrypt Government Websites by Dec. 2016

"Once preloading is in effect, browsers will strictly enforce HTTPS for these domains and their subdomains," the GSA explained in a blog post. "Users will not be able to click through certificate warnings. Any Web services on these domains will need to be accessible over HTTPS in order to be used by modern Web browsers."

The Obama administration announced in June 2015 that all federal websites must enforce HTTPS connections by Dec. 31, 2016. Out of approximately 1,000 .gov domains, only 61 percent enforced HTTPS by the deadline, TechCrunch reported.

Google last fall said it would display a conspicuous "not secure" label in its Chrome Web browser next to the URL of any website that doesn't support HTTPS. The label will roll out with Chrome 56, which is scheduled for release this month.

Recommended stories

How to Stop Websites From Asking to Show Notifications

Web browsers now allow websites to show you notifications. Visit many news and shopping websites, and you’ll see a popup telling you the website wants to show notifications on your desktop. You can disable these notification prompts in your web browser if they annoy you.

11 Things You Can Do with the MacBook’s Force Touch Trackpad

The new Force Touch trackpad on Apple’s MacBooks is similar to the 3D Touch display on the iPhone 6s and 7, allowing you to press down harder to perform a different task or bring up secondary options. Here are some cool things you can do with the MacBook’s Force Touch trackpad.

More stories

Can I Use Task Scheduler to Monitor My Computer’s Battery?

If you like to keep a close eye on your laptop’s battery charge level, then you may be looking for a built-in way to help monitor it while you are busy working. Is there one or do you need a custom solution? Today’s SuperUser Q&A post has the answer to a battery monitoring reader’s question.