Skip to main content

Shutdown makes dozens of .gov websites insecure due to expired TLS certificates

The U.S. government shutdown is causing trouble not only in political circles but also in the world of internet security. As the shutdown enters day 22, making it the longest shutdown in the history of the country, dozens of government websites have been rendered insecure or inaccessible due to expired transport layer security (TLS) certificates.

According to a report by Netcraft, more than 80 TLS certificates that are used by .gov websites have expired and have not been renewed. To make matters worse, some websites are now entirely inaccessible due to security measures brought in long before the shutdown started. Modern browsers are forced to use secure and encrypted protocols when accessing government websites, which is a sensible security measure, but when a certificate is expired the site becomes inaccessible and a warning page is shown instead.

In browsers like Google Chrome and Mozilla Firefox there is a way to bypass the warning and continue on to the site, but this is hidden in an advanced options menu that most non-advanced users wouldn’t know to look for and wouldn’t feel confident using. It is also not advisable for users to enter any sensitive data such as personal information or social security numbers into the websites with this warning as they are currently not secure.

TLS certificates are important because they grant permission to use encrypted communication and authenticate the identity of the certificate holder. The certificates need to be regularly renewed to confirm that the site is still secure and encrypted, and if they are not renewed, the sites automatically show a warning when users try to visit the site.

Some of the affected sites include crucial government services like NASA, the U.S. Department of Justice, and the Court of Appeals. These sites could now be vulnerable to cyber attacks like man-in-the-middle attacks in which an attacker can access and alter information sent between two parties who believe they are communicating directly with each other.

According to CyberScoop, the government shutdown has raised tensions among the government cybersecurity community, with government representatives being notably absent at recent cybersecurity recruiting events held in Washington earlier this month.

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
The 5 best websites like Craigslist in 2024

For years, Craigslist has been the go-to website for scoring a free sofa or finding an apartment. But there are plenty of other alternatives to Craigslist that do an equally fine job, oftentimes with a more attractive interface and fewer spam postings. The 5 best Craigslist alternatives are:

Facebook Marketplace
OfferUp
Locanto
Mercari
Recycler

Read more
How to stop spam emails in Outlook, Gmail, and more
A person sitting on the grass and taking notes at a laptop.

Spam and other unwanted emails are a nuisance, and it can seem like keeping them away from your inbox is a losing battle. But while you won't be able to prevent every piece of spam from landing in your inbox, it is possible to significantly reduce the number of messages that show up.

In this guide, we'll show you how to use filters, blocking, and spam reporting features to help stop spam from invading your inbox. We'll also go over a few more tips on how to reduce unwanted messages overall.
How to stop spam in Gmail
If you use Gmail, the most popular email client, you will eventually start getting spam. Here are our two favorite ways to deal with it.
Block spam in Gmail

Read more
How to add a signature in Gmail on desktop and mobile
how to file for stimulus

Email signatures are a great way to automatically include your contact information to your email correspondence. If you'd like to add a signature to your emails in Gmail, it's easy enough to add one. You'll just need to go through your Gmail settings to do it.

In this guide, we'll show you how to add a signature in Gmail whether you're using the desktop website version of Gmail or its mobile app.
How to add a signature on your desktop
Step 1: Launch your favorite browser and log into your Gmail account as you normally would.

Read more