[ARIN-Suggestions] Response to Suggestion 2015.2: SUPPORT HSTS WHERE TECHNICALLY FEASIBLE

ARIN info at arin.net
Thu Feb 12 17:30:34 EST 2015


ARIN has issued its initial response to ACSP Suggestion 2015.2. The 
suggestion and response text are provided below. This suggestion remains 
open and is available at:

https://www.arin.net/participate/acsp/suggestions/2015-2.html

Regards,

Communications and Member Services
American Registry for Internet Numbers (ARIN)

****
Suggestion: *Description: Support HSTS where technically feasible.

Submitter has noticed that www.arin.net has for some time been 
https-only, with attempts to connect via http issued a 301 redirect to 
the https site.

An improvement upon this practice would be to support HTTP Strict 
Transport Security (RFC 6797). At a high level, HSTS informs capable 
browsers [*] via an additional header in each HTTPS session that for a 
certain period of time (typically months to one year) they should never 
try to connect to the site via unencrypted HTTP. This is an additional 
layer of protection against man in the middle attacks.

[*] At this writing, HSTS is widely supported (Chrome, Firefox, Opera, 
Safari, and upcoming in IE for Windows 10).

Value to Community: Increased protection against spoofing/MITM attacks

*Response:*

Thank you for submitting your suggestion, numbered 2015.2, on the topic 
of HSTS support for the ARIN website.

We will explore HSTS support to our website. Provided there are no 
adverse effects in testing, we will be rolling this improvement out 
within the next 60 days. Thank you again for suggesting this 
improvement. This ACSP item will remain open until the work is completed.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.arin.net/pipermail/arin-suggestions/attachments/20150212/a1da6ef3/attachment.html>


More information about the arin-suggestions mailing list