Security problem at Whitehouse website [telecom]

If anyone of my readers knows anyone at the White House Communications Agency, please tell them that either the white house web site has a configuration problem, or someone is diverting SSL requests to a man-in-the-middle attacker. I assume the former, but it's a PR problem at the very least, especially after the "Obamacare" sign-up fiasco.

I've confirmed this with several different machines, different Operating Systems, and multiple locations. It's a real problem, and has been going on for at least fourteen hours.

The site is at

formatting link
.

Reply to
Telecom Digest Moderator
Loading thread data ...

The wrong cert is from Akamai, a provider that many (most?) busy web sites use to spead out the load so they respond faster. The SSL cert problem is a longstanding issue and they're painfully aware of it.

R's, John

***** Moderator's Note *****

I don't care if they're *aware* of it. I care that they're allowing the site to remain online without *fixing* it.

Good grief - it's the damned White House website! Are the people in charge of the President's public image so inured to imcompetence in the civil service that they think it's OK to expect taxpayers to ignore warnings about possible man-in-the-middle attacks?

Twenty-six hours, and counting.

Bill Horne Moderator

Reply to
John Levine

If there were a straightforward fix, they'd fix it. If you click through the browser warnings, you end up at the non-SSL whitehouse.gov which is also hosted at Akamai but your browser doesn't complain.

R's, John

***** Moderator's Note *****

They don't need to fix it: the White House can simply order Akamai to turn off https access. It is a *public* website, intended to distribute (I hope) *public* information. I wouldn't be offended by a message saying "Whitehouse.gov is optimized for quick response, so https is not supported": I only came across it by accident, after I typed the domain name while already on a secure site. However, if the website responds, I think I'm entitled to have it work properly.

This is not a technical problem: it's a political one. Someone is sending a message that they don't care if the President's statements get through to the electorate.

Bill Horne Moderator

Reply to
John Levine

Most likely they are using the same incompetent website engineers that tried writing the Obamacare web site.

I can see it now, a large board room filled with political hacks, and the decision is... Move them over to the White House project so we can use the "national security" blanket to keep them away from the media.

Reply to
GlowingBlueMist

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.