Visible to the public An Evaluation of the HTTPS Adoption in Websites in Greece: Estimating the Users Awareness

TitleAn Evaluation of the HTTPS Adoption in Websites in Greece: Estimating the Users Awareness
Publication TypeConference Paper
Year of Publication2018
AuthorsKontogeorgis, Dimitrios, Limniotis, Konstantinos, Kantzavelou, Ioanna
Conference NameProceedings of the 22Nd Pan-Hellenic Conference on Informatics
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6610-6
KeywordsHTTPs, Human Behavior, human factors, Metrics, pubcrawl, resilience, Resiliency, Scalability, Security Risk Estimation, TLS, web security
Abstract

The adoption of the HTTPS - i.e. HTTP over TLS - protocol by the Hellenic websites is studied in this work. Since this protocol constitutes a de-facto standard for secure communications in the web, our aim is to identify whether the underlying TLS protocol in popular websites in Greece is properly configured, so as to avoid known vulnerabilities. To this end, a systematic approach utilizing two well-known TLS scanner tools is adopted to evaluate 241 sites of high popularity. The results illustrate that only about half of the sites seem to be at a satisfactory level and, thus, there is still much room for improvement, mainly due to the fact that obsolete ciphers and/or protocol versions are still supported; there is also a small portion - i.e. about 3% of the sites - that do not implement the HTTPS at all, thus posing very high security risks for their users who provide their credentials via a totally insecure channel. We also examined, using an appropriate online questionnaire, whether the users are actually aware of what the HTTPS means and how they check the security of the websites. The outcome of this research shows that much work needs to be done to increase the knowledge and the security awareness of an average Internet user.

URLhttps://dl.acm.org/citation.cfm?doid=3291533.3291556
DOI10.1145/3291533.3291556
Citation Keykontogeorgis_evaluation_2018