A web site that believes in crypto

Steven M. Bellovin smb at cs.columbia.edu
Wed Jan 10 18:31:21 EST 2007


I just stumbled on a web site that strongly believes in crypto --
*everything* on the site is protected by https.  If you go there via
http, you receive a Redirect.  The site?  www.cia.gov:

$ telnet www.cia.gov 80
Trying 198.81.129.100...
Connected to www.odci.gov.
Escape character is '^]'.
GET / HTTP/1.0

HTTP/1.0 301 Found 
Location: https://www.cia.gov/

Connection closed by foreign host.

This has apparently been going on for a while -- see
https://www.cia.gov/cia/public_affairs/press_release/2006/pr04252006.htm
-- but I hadn't noticed it before.

Oh yes -- who vouches for the CIA's identity?  Verisign....


		--Steve Bellovin, http://www.cs.columbia.edu/~smb

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list