http://personalliberty.com/eff-websites-must-use-hsts-order-secure/


EFF: Websites Must Use HSTS In Order To Be Secure

April 4, 2014 by Electronic Frontier
Foundation<http://personalliberty.com/author/electronicfrontierpl/>


*This article, written by Electronic Frontier Foundation technologist
Jeremy Gillula, was originally published on the organization's website on
April 4.*

You would think that by now the Internet would have grown up enough that
things like online banking, email, or government websites would rely on
thoroughly engineered security to make sure your data isn't intercepted by
attackers. Unfortunately when it comes to the vast majority of websites on
the Internet, that assumption would be dead wrong. That's because most
websites (with <https://accounts.google.com/> a <https://www.twitter.com/>
few <https://paypal.com/> notable <https://skydrive.live.com/>
exceptions<https://www.gov.uk/>)
don't yet support a standard called
HSTS<http://blog.veracode.com/2014/03/security-headers-on-the-top-1000000-websites-march-2014-report/>--HTTPS
Strict Transport Security.

Why is lack of HSTS even an issue? To see what could go wrong, imagine the
following common scenario. You're in a coffee shop and you want to check
your bank account. You pop open your laptop, connect to the free wifi, load
up your web browser, and type in your bank's URL. No security alerts pop up
when you load the page, and there's even a padlock icon next to the
address, so you go ahead and login. Unfortunately, you could very well have
just sent your login information to a potential attacker.

The way the attack worked is as follows. When your browser first tried to
contact the bank's server and load its homepage via HTTP, the attacker
intercepted the request to connect and prevented it from getting there
(perhaps by having his laptop pretend to be that free wifi hot-spot). He
then sent your request to the bank's server himself. When he got the
response back (i.e. the webpage to load, the images to display, etc.)
he stripped
out <http://www.thoughtcrime.org/software/sslstrip/> any links that would
initiate a secure HTTPS connection, modified the page so that it would show
the padlock icon next to the address (by setting a padlock as the favicon),
and sent it back to your laptop. Of course these kinds of attacks have
been<http://www.wired.com/2010/03/packet-forensics/>
automated <https://hakshop.myshopify.com/products/wifi-pineapple>. The
result is a page that looks identical in your web browser--the only
difference is that it's not secured, and the attacker can read everything
you send to the server and everything that gets sent back.

But why couldn't your browser detect the attack? The problem is that modern
browsers display prominent security alerts only when a website's security
credentials appear suspicious--if a website connects over a secure channel
and everything appears OK nothing much happens, and the same is true if the
website connects over a normal, insecure channel. Without HSTS, browsers
have no way of knowing that a website *should* be delivered securely, and
so cannot alert you when a website that ought to be loaded securely (e.g.
your bank's website) is instead loaded via a normal connection (i.e. the
unencrypted version the attacker sends to you instead). HSTS fixes that by
allowing servers to send a message to the browser saying "Hey! Connections
to me should be encrypted!" and allowing browsers to understand and act on
that message.

So why haven't more websites enabled HSTS? The biggest reason, we fear, is
that web developers just don't know about
it.1<https://www.eff.org/deeplinks/2014/02/websites-hsts#footnote1_dr4o6ue>Another
problem is that support for HSTS in browsers has been incomplete:
only Chrome, Firefox, and Opera have had HSTS support for a significant
period <http://caniuse.com/stricttransportsecurity>. This is changing
though: we noticed that Apple quietly added HSTS support to Safari in OS X
10.9. For now, Internet Explorer doesn't support HSTS--which means that
there's basically no such thing as a secure website in IE.

In response to questions from EFF about this situation, a Microsoft
spokesperson told EFF that the company would now commit to supporting HSTS
in the next major release of Internet Explorer (we aren't sure whether we
have 
persuaded<https://www.eff.org/deeplinks/2013/11/encrypt-web-report-whos-doing-what>Microsoft
to implement HSTS sooner, though that seems quite likely, and is
great news). This means that with the next major release of IE, every major
browser will support properly secured websites.

In the mean time, what can users do to make sure their connections are
secure? One option would be to use EFF's HTTPS Everywhere browser
extension<https://www.eff.org/https-everywhere>.
HTTPS Everywhere automatically tells your browser to use secured
connections on many (but not all) websites that support them; on many
domains it functions like a client-initiated equivalent of the serverside
HSTS mechanism.

But what if you're stuck using a browser that doesn't support HSTS or HTTPS
Everywhere, or a website that doesn't support HSTS? For now all a savvy
user can do is to always carefully examine the address of the site you've
loaded, and verify that it's secure by checking to make sure it has "https"
in the front and is the precise address you want to
visit.2<https://www.eff.org/deeplinks/2014/02/websites-hsts#footnote2_gz84t03>Unfortunately
this assumes that you know ahead of time (and remember)
whether or not a site should be secure, and are meticulous with every
website you visit. This is obviously a huge burden to place on users--it
makes a lot more sense to automate the process via HSTS, and it's about
time website operators the world over picked up the slack and did so.




__._,_.___


 Visit Your 
Group<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmcXJsYzgzBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzEzOTY2NTM3MzA->

   - New 
Members<https://groups.yahoo.com/neo/groups/grendelreport/members/all;_ylc=X3oDMTJnNXFldWFwBF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2bWJycwRzdGltZQMxMzk2NjUzNzMw>
   1

 [image: Yahoo!
Groups]<https://groups.yahoo.com/neo;_ylc=X3oDMTJlOXNwanZmBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTM5NjY1MzczMA-->
* Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> *
Unsubscribe <[email protected]?subject=Unsubscribe>*
Terms
of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to