Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Submit w3id org to HSTS preload list (configuration changes needed) #1942

Open
athalhammer opened this issue Dec 10, 2020 · 0 comments
Open

Comments

@athalhammer
Copy link
Contributor

athalhammer commented Dec 10, 2020

Dear all,

HSTS preload lists enable to avoid sending the first request as plain HTTP and directly encrypt the first request. This has a lot of security benefits, in particular avoiding man-in-the-middle attacks that target interception of the first request.

It seems that w3id.org is not fit for being submitted to the list that is used by a couple of browsers:

https://hstspreload.org/?domain=w3id.org

So, in my opinion, basically everyone that uses http://w3id.org to refer to their resources could potentially be targeted and users of these URIs could be easy victims on malicious public WIFI etc.

Edit - here a screenshot:
fail

Edit:
So when someone requests http://w3id.org/fraunhofer/lighthouse-projects/evolopro/cirp.ttl, and has never visited https://w3id.org before, this first request will be plain HTTP (tried and tested with wireshark).

Kind regards,
Andreas

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant