News: 1639079171

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

A third of you slackers out there still aren't using HTTPS by default

(2021/12/09)


Almost a third of the world wide web's top million sites are still not using HTTPS by default, according to infosec researcher Scott Helme's analysis.

In his Top 1 Million Analysis, in which he runs crawlers over a guessable number of websites, Helme published his findings on a variety of common internet security technologies. Broadly, he found that most security measures were on the top – except for extended verification (EV) certificates.

On HTTPS, Helme found that 71.7 per cent of sites he scanned actively redirected his crawler to use HTTPS-encrypted connections, a figure he said had improved markedly from 57.6 per cent in September 2019.

[1]

Similarly, TLS v1.1 – which browser-maker Mozilla said it would [2]actively block from March 2020 onwards – has completely disappeared from Helme's analysis, while v1.3 has spread from around 16 per cent of websites to 37 per cent of the million sites analysed, itself an increase of 129 per cent over the last 18 months.

[3]

[4]

"It seems like industry-wide efforts to focus on deploying more and better encryption are really paying off and I hope that focus and drive can start to spread to other areas of security as we approach the saturation point for HTTPS," Helme told The Register .

To EV or not to EV? Sod it, ditch 'em

Not all is good news, depending on your point of view. [5]EV certificates are dying out at a rate of knots with just 10,174 sites using them – a sharp drop since August 2018's high point of 25,000 sites, according to Helme's figures.

EV certificates used to be displayed fairly prominently in browsers and included the certified organisation's physical address. A couple of years ago Google all but hid the EV details in its dominant Chrome browser, [6]on the grounds that ordinary users didn't care about the details. Shortly afterwards Mozilla followed suit in Firefox.

"The rise of Let's Encrypt marks a sharp drop in the perceived value of EV certificates," said Kevin Bocek, veep of security strategy and threat intelligence at Venafi (which sponsored Helme's report). "Browsers no longer give EV certificates any special treatment, and the speed of development today simply does not accommodate the slow, manual approval processes connected with them... Given that EV certificates are not automation friendly, their usage and value is going to continue to drop."

Keys to victory

Authentication key usage to secure the initial stages of negotiating an HTTPS connection was something that surprised Helme, as he told us. His figures showed that RSA keys are generally more prevalent than ECDSA among website operators.

Helme told El Reg : "RSA3072 is notably slower than RSA2048 and the performance hit for jumping up to RSA4096 is really quite something. If sites are taking the performance hit in the pursuit of stronger keys for better security, they should be switching to ECDSA which will give them better security and better performance at the same time, which is a rare thing as usually when you try to increase performance or security, one will cost you the other."

[7]OpenSSL alpha adds TLS 1.3 support

[8]Google to bury indicator for Extended Validation certs in Chrome because users barely took notice

[9]It's not easy being green: EV HTTPS cert seller Sectigo questions Chrome's logic in burying EV HTTPS cert info

[10]These truly are the end times for TLS 1.0, 1.1: Firefox hopes to 'eradicate' weak HTTPS standard by blocking it

Back in 2014 as public outrage over US dragnet internet surveillance was at its peak, the IETF briefly mulled [11]deprecating RSA altogether from TLS v1.3 .

This eventually [12]happened in 2018 , but the widespread use of TLS v1.2 means RSA is still a feature of the wider internet for now.

[13]

Helme added that his gut feeling was that most operators are content with what they've got and haven't figured out that ECDSA might come with performance benefits.

The full report can be read [14]on Helme's website , free from paywalls or payment-by-handing-over-email-address mechanisms. You can even view the raw data. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YbKKmjbdZ5X1cPlVKHbg7wAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2020/02/10/tls_10_11_firefox_complete_eradication/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbKKmjbdZ5X1cPlVKHbg7wAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YbKKmjbdZ5X1cPlVKHbg7wAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2019/08/12/google_chrome_extended_validation_certificates/

[6] https://www.theregister.com/2019/08/12/google_chrome_extended_validation_certificates/

[7] https://www.theregister.com/2018/02/14/openssl_1_1_1_alpha_adds_tls_1_3_support/

[8] https://www.theregister.com/2019/08/12/google_chrome_extended_validation_certificates/

[9] https://www.theregister.com/2021/03/03/sectigo_google_certificates/

[10] https://www.theregister.com/2020/02/10/tls_10_11_firefox_complete_eradication/

[11] https://www.theregister.com/2014/05/08/rsa_depreciated_from_tls/

[12] https://www.theregister.com/2018/02/14/openssl_1_1_1_alpha_adds_tls_1_3_support/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YbKKmjbdZ5X1cPlVKHbg7wAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://scotthelme.co.uk/top-1-million-analysis-november-2021/

[15] https://whitepapers.theregister.com/



karlkarl

If that third suddenly started using encryption, I wonder how much more energy it would take (possibly needlessly if all those sites are doing is displaying pointless adverts anyway).

exactly

captain veg

If a site is not exchanging any private and/or sensitive information, what's the point?

-A.

Browser fascism

adam 40

What annoys me more is when the browser insists on it, this cutting you off from legacy websites (such as web pages on equipment) that will never change.

Re: exactly

Ken Hagan

The point is that "encryption" also includes proof that what you have received is what the site sent you, so man-in-the-middle attacks are harder. Of course, if (like most people?) you are blindly accepting anything that is signed then you'll accept the man-in-the-middle's signed malware so this point isn't actually useful.

Re: exactly

Vadheterdu

There's web site authentication as well as encrypted communication when using https. The authentication part could be useful even for Joe Blogz's random Wordpress site.

But my cat wants his privacy

The Man Who Fell To Earth

That's why there's photos of him only his 10,000,000+ closest friends can see via https.

HTTPS is secure but ...

Version 1.0

So you get an email with a link to your new purchase order on an HTTPS site and it downloads new_purchase_order.pdf.exe for you?

Certainly HTTPS is a major security function but don't misinterpret "security" as secure.

Reading between the lines.

Anonymous Coward

It's not that these sites are not using https, it's that they don't have a redirect in place. I. E. if you default to https (which most browsers do), then you will get the https.

I:
The best way to make a silk purse from a sow's ear is to begin
with a silk sow. The same is true of money.
II:
If today were half as good as tomorrow is supposed to be, it would
probably be twice as good as yesterday was.
III:
There are no lazy veteran lion hunters.
IV:
If you can afford to advertise, you don't need to.
V:
One-tenth of the participants produce over one-third of the output.
Increasing the number of participants merely reduces the average
output.
-- Norman Augustine