{"id":9754,"date":"2017-10-09T07:45:06","date_gmt":"2017-10-09T15:45:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/10\/09\/news-3527\/"},"modified":"2017-10-09T07:45:06","modified_gmt":"2017-10-09T15:45:06","slug":"news-3527","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/10\/09\/news-3527\/","title":{"rendered":"The World\u2019s Biggest Military Contractors Don\u2019t Encrypt Their Websites"},"content":{"rendered":"<p><strong>Credit to Author: Lorenzo Franceschi-Bicchierai| Date: Mon, 09 Oct 2017 15:00:00 +0000<\/strong><\/p>\n<p>The websites of four of the five largest American defense and military contractors, which received a combined $95,278,712,971 <a href=\"https:\/\/www.fpds.gov\/downloads\/top_requests\/Top_100_Contractors_Report_Fiscal_Year_2016.xls\" target=\"_blank\">last year<\/a> from the US government, don&#8217;t use web encryption. <\/p>\n<p>The main sites of <a href=\"http:\/\/lockheedmartin.com\/\" target=\"_blank\">Lockheed Martin<\/a>, <a href=\"http:\/\/boeing.com\/\" target=\"_blank\">Boeing<\/a>, <a href=\"http:\/\/www.raytheon.com\/\" target=\"_blank\">Raytheon<\/a>, and <a href=\"http:\/\/www.northropgrumman.com\/\" target=\"_blank\">Northrop Grumman<\/a>, all don&#8217;t have the standard web encryption HTTPS enabled by default, which leaves visitors of these sites exposed to common cyberattacks that could potentially allow hackers to infect them with malware. When tested on Friday, Generaldynamics.com was also not encrypted. On Monday, however, the site redirected to <a href=\"http:\/\/gd.com\" target=\"_blank\">gd.com<\/a>, which is served over HTTPS. <\/p>\n<p>When websites have enabled HTTPS, the connection between the visitors and the site is encrypted, making it more private and secure. Without HTTPS, a hacker on your wireless network, internet service providers or governments, can track your every move online and also intercept and manipulate the data being exchanged between you and the site.<\/p>\n<div class=\"article__media\">\n<div class=\"article__media\"><picture class=\"article__image\"><source media=\"(max-width: 25em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png?resize=400:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png?resize=600:* 2x\"><source media=\"(max-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png?resize=650:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png?resize=975:* 2x\"><source media=\"(min-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png?resize=668:*\"><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659229-Screen-Shot-2017-10-06-at-42705-PM.png\" alt=\"\"><\/picture>\n<div class=\"article__image-caption\">A screenshot of the Northrop Grumman website. <\/div>\n<\/div>\n<div class=\"article__image-caption\"><\/div>\n<\/div>\n<div class=\"article__media\"><picture class=\"article__image\"><source media=\"(max-width: 25em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png?resize=400:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png?resize=600:* 2x\"><source media=\"(max-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png?resize=650:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png?resize=975:* 2x\"><source media=\"(min-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png?resize=672:*\"><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659241-Screen-Shot-2017-10-06-at-42451-PM.png\" alt=\"\"><\/picture>\n<div class=\"article__image-caption\">A screenshot of the Boeing website. <\/div>\n<\/div>\n<div class=\"article__media\"><picture class=\"article__image\"><source media=\"(max-width: 25em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png?resize=400:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png?resize=600:* 2x\"><source media=\"(max-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png?resize=650:*, https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png?resize=975:* 2x\"><source media=\"(min-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png?resize=668:*\"><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/_uncategorized\/1507557659239-Screen-Shot-2017-10-06-at-42553-PM.png\" alt=\"\"><\/picture>\n<div class=\"article__image-caption\">A screenshot of the Lockheed Martin website. <\/div>\n<\/div>\n<div class=\"article__media\"><picture class=\"article__image\"><source media=\"(max-width: 25em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png?resize=400:*, https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png?resize=600:* 2x\"><source media=\"(max-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png?resize=650:*, https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png?resize=975:* 2x\"><source media=\"(min-width: 40.625em)\" srcset=\"https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png?resize=668:*\"><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/_uncategorized\/1507558733691-Screen-Shot-2017-10-06-at-42729-PM.png\" alt=\"\"><\/picture>\n<div class=\"article__image-caption\">A screenshot of Raytheon&#8217;s website. <\/div>\n<\/div>\n<p>Lockheed Martin, Boeing, Raytheon, and Northrop Grumman did not respond to a request for comment. <\/p>\n<p>For years, most of the web didn&#8217;t use web encryption. HTTPS used to slow down pages, getting a digital certificate to encrypt websites was costly and relatively complicated. And, in general, web developers believed HTTPS was only important on sensitive pages where users introduce passwords or credit card numbers.<\/p>\n<p>But none of these arguments are valid today. Pages actually <a href=\"https:\/\/www.troyhunt.com\/i-wanna-go-fast-https-massive-speed-advantage\/\" target=\"_blank\">load faster<\/a> with HTTPS, digital certificates <a href=\"https:\/\/letsencrypt.org\/\" target=\"_blank\">are free<\/a>, and security experts and web developers themselves understand that HTTPS\u2014even on pages without sensitive, user-submitted content\u2014is a good practice to protect visitors. <\/p>\n<p><b> Read more: <\/b><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/bmv5a4\/the-motherboard-guide-to-not-getting-hacked\"><b> The Motherboard Guide To Not Getting Hacked<\/b><\/a><\/p>\n<p>In fact, if a website doesn&#8217;t use HTTPS, hackers can hijack it with attacks known as <a href=\"https:\/\/www.owasp.org\/index.php\/Man-in-the-middle_attack\" target=\"_blank\">Man-in-the-Middle<\/a> or MiTM. In these kind of attacks, a hacker on the same Wi-Fi network or a government that has control over the country&#8217;s internet infrastructure can replace a legitimate, non-HTTPS website, or manipulate it to serve malware. Over the years, there have been countless, real-world, documented attacks where hackers impersonated non-HTTPS websites to infect victims with malware, or trick them into giving out their data. Even surveillance contractors, such as Hacking Team, <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/gvye9m\/hacking-teams-spyware-targeted-porn-sites-visitors\">took advantage of unencrypted sites<\/a>, to <a href=\"https:\/\/www.welivesecurity.com\/2017\/09\/21\/new-finfisher-surveillance-campaigns\/\" target=\"_blank\">hack users<\/a>. <\/p>\n<p>For all these reasons, the web is mostly encrypted now. As of this week, more than 60 percent of pages on the web are loaded over HTTPS, <a href=\"https:\/\/letsencrypt.org\/stats\/\" target=\"_blank\">according to Firefox<\/a>. This is the result of <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/wnjyay\/the-web-is-deprecating-http-and-its-going-to-be-okay\">a concerted push<\/a> by internet freedom and security activists, as well as companies such as Mozilla and Google, to promote the use of HTTPS across the whole internet. <\/p>\n<p class=\"article__pull-quote\">&#8220;You are better protected from man in the middle attacks when visiting Pornhub than Raytheon or Lockheed.&#8221;<\/p>\n<p>&#8220;For companies bidding on major cybersecurity contracts, lack of HTTPS-by-default in 2017 is a bad look,&#8221; John Scott-Railton, a senior researcher at the Citizen Lab, an academic group at the the University of Toronto&#8217;s Munk School of Global Affairs that studies internet security and digital rights, told Motherboard. &#8220;You are better protected from man in the middle attacks when visiting Pornhub than Raytheon or Lockheed.&#8221;<\/p>\n<p>In fact, adult sites, such as Pornhub and YouPorn, as well as most major news <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/3dky4b\/the-white-house-wants-to-encrypt-every-us-government-site\">and government<\/a> websites, <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/yp9eqj\/pornhub-youporn-privacy-https-encryption\">have switched<\/a> to HTTPS by default in the last couple of years. <\/p>\n<p>Google <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/xyg55z\/google-chrome-shaming-http-unencrypted-websites-january\">announced<\/a> last year that it was planning to flag all non-HTTPS sites in Chrome with a &#8220;Not secure&#8221; warning in the next to the URL. Starting last January, sites that ask users for passwords or credit cards <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/xyg55z\/google-chrome-shaming-http-unencrypted-websites-january\">got flagged as insecure<\/a> by Chrome. This month, the latest version of Chrome started giving sites where users enter any kind of data the same treatment in Incognito mode. <\/p>\n<p>Soon, all sites\u2014including those of multi-billion dollar companies\u2014 we&#8217;ll get the same treatment if they don&#8217;t make the switch.<\/p>\n<p>&#8220;Eventually,&#8221; <a href=\"https:\/\/blog.chromium.org\/2017\/04\/next-steps-toward-more-connection.html\" target=\"_blank\">wrote<\/a> Emily Schechter, from the Chrome security team, &#8220;we plan to show the &#8216;Not secure&#8217; warning for all HTTP pages.&#8221;<\/p>\n<p><b> <i> Get six of our favorite Motherboard stories every day <\/i><\/b><a href=\"http:\/\/motherboard.club\/\" target=\"_blank\"><b> <i> by signing up for our newsletter.<\/i><\/b><\/a><\/p>\n<p><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/yw39mg\/us-military-contractors-lockheed-raytheon-boeing-dont-use-https\" target=\"bwo\" >https:\/\/motherboard.vice.com\/en_us\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/59db8160bbf2735d12c78df5\/lede\/1507558637630-shutterstock_95229493.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Lorenzo Franceschi-Bicchierai| Date: Mon, 09 Oct 2017 15:00:00 +0000<\/strong><\/p>\n<p>America\u2019s largest defense contractors still don\u2019t use HTTPS on their main websites. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,13328,10378],"tags":[15586,4500,10439,15584,3919,11124,13408,10573,8175,15570,5897,15585],"class_list":["post-9754","post","type-post","status-publish","format-standard","hentry","category-independent","category-motherboard","category-security","tag-boeing","tag-cybersecurity","tag-encryption","tag-general-dynamics","tag-hacking","tag-https","tag-information-security","tag-infosec","tag-lockheed-martin","tag-northrop-grumman","tag-privacy","tag-raytheon"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9754"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9754\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9754"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}