Brit borough council apologizes for telling website users to disable HTTPS
(2023/11/29)
- Reference: 1701250207
- News link: https://www.theregister.co.uk/2023/11/29/reading_borough_council_https/
- Source link:
Reading Borough Council has securely restored its planning portal after facing criticism for recommending questionable tech security practices to users.
Before the fixed version went live this morning, the English local authority's online planning application portal had been offline due to "technical issues," an outage that had persisted for nearly a month.
Responding to a discussion related to the issue via a now-deleted post on X, the council's official account recommended users disable HTTPS in their browser as a way around the technical issues disrupting access to the planning portal.
Reading Borough Council's X post that instructed users to disable HTTPS
Until November 26, the same advice appeared in a yellow banner sprawled across the planning portal's homepage.
The council advised users to access the service using Chrome rather than [1]Safari , since Safari does not allow users to turn off HTTPS, before listing the instructions on how to switch off the security feature.
[2]
Chrome has used HTTPS for its default navigation protocol [3]since 2021 , offering better load speeds for websites and protections from data interception or manipulation.
[4]
[5]
HTTPS builds on HTTP by using TLS encryption for requests and responses, meaning any sensitive data submitted to a website is encrypted rather than being sent in plaintext. An intercepted HTTP request, which lacks encryption, could provide cybercriminals with sensitive information like passwords, potentially leading to more severe attacks.
While the likelihood of users submitting sensitive information on a council's website for planning applications is low, if they forget to re-enable HTTPS afterward, they could remain vulnerable to online attacks.
[6]OpenCart owner turns air blue after researcher discloses serious vuln
[7]How to give Windows Hello the finger and login as someone on their stolen laptop
[8]Britain proposes 'super-complaints' to help keep the internet safe
[9]Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain
More than anything else, Reading council was promoting embarrassingly bad security hygiene.
The council has since [10]apologized for publishing this information, calling it "incorrect."
[11]
In the latest update on November 24, the council tweeted posted: "Apologies for the incorrect information that was tweeted."
The council sent a statement to The Register today: "The Council's Planning Portal is back online with a secure connection restored at 10:08 am on 27 November following the successful completion of remedial work.
"A planning portal website update was required as access from some internet browsers was being blocked.
[12]
"We apologize for the obvious inconvenience and confusion caused and the portal should now be fully operational with no special action on the part of users being necessary."
The local authority declined to provide an answer on how the original advice to disable HTTPS was approved internally.
The Register approached the National Cyber Security Centre (NCSC) but it did not respond.
The official advice from GCHQ's cybersecurity arm to website operators is to always use HTTPS, even if the website is basic enough to not include private content, sign-in pages, or other sensitive information like credit card details.
UK public sector organizations, like Reading Borough Council, have access to the NCSC's [13]Web Check service, which can audit a website and identify misconfigurations as well as whether HTTPS is in use or not. ®
Get our [14]Tech Resources
[1] https://www.theregister.com/2023/11/02/apple_safari_browser/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/03/24/chrome_firefox_privacy/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/11/24/opencart_vulnerability_dispute/
[7] https://www.theregister.com/2023/11/22/windows_hello_fingerprint_bypass/
[8] https://www.theregister.com/2023/11/17/supercomplaints_proposed/
[9] https://www.theregister.com/2023/11/14/tetra_encryption_algorithms_open_sourced/
[10] https://twitter.com/ReadingCouncil/status/1728821050887331916
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2018/03/27/ncsc_web_check_sitrep/
[14] https://whitepapers.theregister.com/
Before the fixed version went live this morning, the English local authority's online planning application portal had been offline due to "technical issues," an outage that had persisted for nearly a month.
Responding to a discussion related to the issue via a now-deleted post on X, the council's official account recommended users disable HTTPS in their browser as a way around the technical issues disrupting access to the planning portal.
Reading Borough Council's X post that instructed users to disable HTTPS
Until November 26, the same advice appeared in a yellow banner sprawled across the planning portal's homepage.
The council advised users to access the service using Chrome rather than [1]Safari , since Safari does not allow users to turn off HTTPS, before listing the instructions on how to switch off the security feature.
[2]
Chrome has used HTTPS for its default navigation protocol [3]since 2021 , offering better load speeds for websites and protections from data interception or manipulation.
[4]
[5]
HTTPS builds on HTTP by using TLS encryption for requests and responses, meaning any sensitive data submitted to a website is encrypted rather than being sent in plaintext. An intercepted HTTP request, which lacks encryption, could provide cybercriminals with sensitive information like passwords, potentially leading to more severe attacks.
While the likelihood of users submitting sensitive information on a council's website for planning applications is low, if they forget to re-enable HTTPS afterward, they could remain vulnerable to online attacks.
[6]OpenCart owner turns air blue after researcher discloses serious vuln
[7]How to give Windows Hello the finger and login as someone on their stolen laptop
[8]Britain proposes 'super-complaints' to help keep the internet safe
[9]Bug hunters on your marks: TETRA radio encryption algorithms to enter public domain
More than anything else, Reading council was promoting embarrassingly bad security hygiene.
The council has since [10]apologized for publishing this information, calling it "incorrect."
[11]
In the latest update on November 24, the council tweeted posted: "Apologies for the incorrect information that was tweeted."
The council sent a statement to The Register today: "The Council's Planning Portal is back online with a secure connection restored at 10:08 am on 27 November following the successful completion of remedial work.
"A planning portal website update was required as access from some internet browsers was being blocked.
[12]
"We apologize for the obvious inconvenience and confusion caused and the portal should now be fully operational with no special action on the part of users being necessary."
The local authority declined to provide an answer on how the original advice to disable HTTPS was approved internally.
The Register approached the National Cyber Security Centre (NCSC) but it did not respond.
The official advice from GCHQ's cybersecurity arm to website operators is to always use HTTPS, even if the website is basic enough to not include private content, sign-in pages, or other sensitive information like credit card details.
UK public sector organizations, like Reading Borough Council, have access to the NCSC's [13]Web Check service, which can audit a website and identify misconfigurations as well as whether HTTPS is in use or not. ®
Get our [14]Tech Resources
[1] https://www.theregister.com/2023/11/02/apple_safari_browser/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/03/24/chrome_firefox_privacy/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/11/24/opencart_vulnerability_dispute/
[7] https://www.theregister.com/2023/11/22/windows_hello_fingerprint_bypass/
[8] https://www.theregister.com/2023/11/17/supercomplaints_proposed/
[9] https://www.theregister.com/2023/11/14/tetra_encryption_algorithms_open_sourced/
[10] https://twitter.com/ReadingCouncil/status/1728821050887331916
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZWcZ07QvEtNZ7GcdZQSQeQAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2018/03/27/ncsc_web_check_sitrep/
[14] https://whitepapers.theregister.com/
Re: So what's new?
Anonymous Coward
"I've drawn this to their attention several times over the last few years, and just like El Reg, had no response."
Oh, you've had a "response" Mike, just not one they are going to tell you about. ;-)
Nothing new
elsergiovolador
The tax man already tells people to bend over and he seized the lube.
gnasher729
So the told their users that they should switch from a browser that insists on secure connections to one that allows to turn security off. Excellent.
So what's new?
" The Register approached the National Cyber Security Centre (NCSC) but it did not respond "
It never does. And despite javascript being a primary vector for malware, the NCSC web site is entirely a javascript "app". You can't even see the emergency contact number with scripting disabled. I've drawn this to their attention several times over the last few years, and just like El Reg, had no response.
I suppose that as an offshoot of government it thinks it's too superior to mere mortals (even the qualified ones) to be bothered to respond.