Does “www.” Mean better transport layer security?
File version
Accepted Manuscript (AM)
Author(s)
Szalachowski, P
Martin, A
Griffith University Author(s)
Primary Supervisor
Other Supervisors
Editor(s)
Date
Size
File type(s)
Location
Canterbury, UK
License
Abstract
Experience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with “www” sub-domains, e.g. “example.com”) as synonyms for their equivalent www-domains (those that are prefixed with “www” sub-domains, e.g. “www.example.com”). In this paper, we analyse datasets of nearly two million plain-domains against their equivalent www-domains to answer the following question: Do plain-domains and their equivalent www-domains differ in TLS security configurations and certificates? If so, to what extent? Our results provide evidence of an interesting phenomenon: plain-domains and their equivalent www-domains differ in TLS security configurations and certificates in a non-trivial number of cases. Furthermore, www-domains tend to have stronger security configurations than their equivalent plain-domains. Interestingly, this phenomenon is more prevalent in the most-visited domains than in randomly-chosen domains. Further analysis of the top domains dataset shows that 53.35% of the plain-domains that show one or more weakness indicators (e.g. expired certificate) that are not shown in their equivalent www-domains perform HTTPS redirection from HTTPS plain-domains to their equivalent HTTPS www-domains. Additionally, 24.71% of these redirections contains plain-text HTTP intermediate URLs. In these cases, users see the final www-domains with strong TLS configurations and certificates, but in fact, the HTTPS request has passed through plain-domains that have less secure TLS configurations and certificates. Clearly, such a set-up introduces a weak link in the security of the overall interaction.
Journal Title
Conference Title
ARES '19: Proceedings of the 14th International Conference on Availability, Reliability and Security
Book Title
Edition
Volume
Issue
Thesis Type
Degree Program
School
Publisher link
Patent number
Funder(s)
Grant identifier(s)
Rights Statement
Rights Statement
© ACM, 2019. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in ARES '19: Proceedings of the 14th International Conference on Availability, Reliability and Security, ISBN: 978-1-4503-7164-3, https://doi.org/10.1145/3339252.3339277
Item Access Status
Note
Access the data
Related item(s)
Subject
Cybersecurity and privacy not elsewhere classified
Persistent link to this record
Citation
Alashwali, ES; Szalachowski, P; Martin, A, Does “www.” Mean better transport layer security?, ARES '19: Proceedings of the 14th International Conference on Availability, Reliability and Security, 2019