Skip to content

Comment on Automatic HTTPS Enforcement for New Executive Branch .gov Domains

Comments

This is fantastic news.

It wasn't that long ago that I tried to log into a government site via my SSN, and discovered that the page didn't even permit HTTPS. I was displeased, to say the least; logging in wasn't exactly optional, so it seemed much worse than a business offering poor security.

Permitting HTTPS is obviously the first step, but security shouldn't be limited to people with the expertise to seek it out. I'm really glad to see that something as inescapable as the .gov domain will be pursuing security-by-default.

Please name and shame the httpd that's asking for plaintext SSNs... That's newsworthy and I'm sure some tech journalists will pick it up on a slow day.

It was a state jobs site which has since updated to HTTPS. They still suck in a lot of ways - the required login is SSN, plus an 8-digit (numeric only) PIN. That's a laughably bad login scheme, but at least they aren't passing it in the clear.

If I do see it again, is there anything like a clearinghouse for this sort of complaint?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.