Site navigation

Is Scotland’s Public Sector Failing on HTTPS Encryption?

Ross Kelly

,

Google Chrome

The Chrome 68 update has been raising concerns among web users that high-profile websites are not adequately secure, including a host of Scottish public sector organisations. 

Following Google’s Chrome 68 update, the web browser has begun flagging numerous popular websites, including the Daily Mail, as “not secure” for failing to adopt HTTPS encryption.

The news outlet is just one of many websites that Chrome will now flag because they still use HTTP. Earlier this year, Google announced an overhaul of the Chrome browser as part of a concerted shift toward greater web encryption. The tech giant has even quietly boosted HTTPS-enabled sites in its search rankings for several years, obliging organisations to adopt more secure data transfer protocols.

In an increasingly volatile online environment, ensuring adequate security is of paramount importance, yet a number of Scottish public sector bodies aren’t using secure encryption methods on their websites.

What is HTTPS?

HTTPS is a form of web encryption that ensures a secure connection between both the user and the websites they visit and is an extension of ‘HyperText Transfer Protocol’ – you’ll usually see this in the far left corner of your browser URL bar. The additional ‘S’ stands for secure and ensures that your data is encrypted before it travels online.

For websites not using HTTPS encryption, the risk of security breaches is a growing issue. Malware now represents one of the most common tactics for cybercriminals worldwide.

Currently, around 20% of the top 500 global websites use HTTP – the encryption method Google intends to phase out – however, there is no evidence to suggest that any of these sites are subject to cybersecurity breaches.

A host of websites familiar to British web users, such as Sky Sports, Argos or Boohoo are still to adopt HTTPS and as of yet, haven’t reported any significant data security issues – so what is the fuss all about?

A Concerted Shift

In 2016, Google announced its goal to pioneer web encryption and begin naming and shaming websites with unencrypted connections. This was a cunning strategy to encourage both web developers to adopt HTTPS encryption and ensure that companies adopt it.

The events currently unfolding suggest that Google is finally ramping up its attempts to push through HTTPS encryption – and the Chrome 68 update has offered them the perfect opportunity to improve online security. In a blog post on the Google website, Chrome Security Product Manager Emily Schechter described the update as a “milestone” for Chrome security.

Firefox and Safari have also adopted similar practices to Chrome, highlighting websites that use credit or debit card information for some time now, and they are expected to push harder toward greater encryption standards.

Google isn’t alone in its championing of HTTPS – governments are also joining in on the efforts. The National Cyber Security Centre (NCSC) issued advice in 2018 recommending that all website should adopt HTTPS to ensure greater encryption standards and highlighted the benefits for both businesses and users.

HTTPS Encryption in Scotland’s Public Sector

Professor Bill Buchanan OBE highlights that one-in-four national bodies of Scotland fail in basic HTTPS tests. Companies including Creative Scotland, Highlands and Islands Airports Ltd, Highlands and Islands Enterprise, Scottish Social Services Council and the Scottish Funding Council are some of the companies that offer absolutely no support for HTTPS.

Some of the sites, Buchanan says, redirect back to an insecure HTTP version. Others, such as Quality Meat Scotland “don’t even exist in a secure form.”

It’s not all doom and gloom for Scotland’s public sector bodies, however. There are a significant number of sites that have received a gold star for security and trust in supporting HTTPS, some of these include:

Professor Buchanan said it is disappointing that such a significant number of public sector bodies haven’t taken up HTTPS encryption given the ease of adoption.

He said: “It is disappointing that around 1-in-4 public bodies of Scotland have not been able to do something as simple as put HTTPs on their site. It doesn’t cost anything for a certificate these days, and it is a relatively easy task to add it to the site.

“In the long-term, the site should redirect from HTTP to HTTPs, but for a start, all public bodies should support HTTPs, as we need trust in our online world.”

Should You Avoid Sites?

There is no current need to avoid websites not using HTTPS encryption, however as with any online activity, remaining vigilant is key.

Under an unencrypted HTTP connection, your data could still potentially be intercepted by bad actors. Web users regularly fall victim to attacks that trick them into handing over sensitive data such as credit card information; these are known as man-in-the-middle attacks and involve cybercriminals creating websites to copy and pose as legitimate destinations.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data