US government websites get HTTPS security boost

(Image credit: Shutterstock)

The US government's DotGov Program has announced that new .gov sites will only be accessible via HTTPS and that they will automatically be preloaded starting on September 1, 2020.

The program is overseen by the US General Services Administration (GSA) which operates the .gov top-level domain (TLD). The GSA also provides .gov domains to US-based government organizations from federal agencies to local municipalities.

In an announcement on its website, the DotGov Program explained the reason behind its decision to preload the .gov domain, saying:

“We believe the security benefits that come from preloading are meaningful and necessary to continue meeting the public’s expectation of safety on .gov services. We believe that government websites should always be secure.”

Preloading the .gov TLD

Following their move from HTTP to the HTTPS protocol, US government sites will secure visitors' connections using Transport Layer Security (TLS) protocol. This will encrypt any data that is exchanged and also protect users against man-in-the-middle attacks.

Although DotGov will preload the .gov TLD in September of this year, it will not be submitted to the HTTP Strict Transport Security (HSTS) preload list until a later date as doing so would make government sites that currently use HTTPS inaccessible. 

HSTS is a web server directive which tells web browsers to only connect using secure HTTPS connections. Web browsers bundle an HSTS preload list containing the names of all sites known to support secure connections so that browsers don't connect to them using an insecure protocol.

In a blog post, the DotGov Program provided further insight on what preloading the .gov TLD will entail, saying:

“Actually preloading is a simple step, but getting there will require concerted effort among the federal, state, local and tribal government organizations that use a common resource, but don’t often work together in this area. With concerted effort, we could preload .gov within a few years.”

To go about preloading the .gov TLD, the DotGov Program is currently collaborating with the Cybersecurity and Infrastructure Security Agency (CISA) to ensure that .gov domain owners are ready for their domains to be preloaded in the future. Also beginning on September 1, all new .gov domains will be automatically preloaded so that the program can focus on transitioning historical domains and not new ones to HTTPS.

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect