Experience shows that most researchers and developers tend to treat plain-domains (those that are not prefixed with "www" sub-domains, e.g. "example.com") as synonyms for their equivalent www-domains (those that are prefixed with "www" sub-domains, e.g. "www.example.com"). In this paper, we analyse datasets of nearly two million plain-domains against their equivalent www-domains to answer the following question: Do plain-domains and their equivalent www-domains differ in TLS security configurations and certificates? If so, to what extent? Our results provide evidence of an interesting phenomenon: plain-domains and their equivalent www-domains differ in TLS security configurations and certificates in a non-trivial number of cases. Furthermore, www-domains tend to have stronger security configurations than their equivalent plain-domains. Interestingly, this phenomenon is more prevalent in the most-visited domains than in randomly-chosen domains. Further analysis of the top domains dataset shows that 53.35% of the plain-domains that show one or more weakness indicators (e.g. expired certificate) that are not shown in their equivalent www-domains perform HTTPS redirection from HTTPS plain-domains to their equivalent HTTPS www-domains. Additionally, 24.71% of these redirections contains plain-text HTTP intermediate URLs. In these cases, users see the final www-domains with strong TLS configurations and certificates, but in fact, the HTTPS request has passed through plain-domains that have less secure TLS configurations and certificates. Clearly, such a set-up introduces a weak link in the security of the overall interaction.
翻译:经验显示,大多数研究人员和开发者倾向于将平面域( 并非以“ www” 子 Domain 预设为“ www” 子 Domain, 例如“ example. com ” ) 处理为等同的 www- domains 的同义词( 以“ www” 子domain 预设为前缀的) 。 在本文中, 我们分析近200万平面域的数据集, 与其对应的 www- domains 对应的 www- domains 问题: 在 TLS 安全配置和证书中, Do pain-domains 及其等同的 www- domains 安全配置和证书不同? 如果如此, 我们的结果提供了有趣的证据: 平面 Domain- mains 及其等同的www- Domain 安全配置和证书在非三边端端端端端端端端端端的 Hdmaisal- developments 。 这些安全配置比平面平面平面平面平面的更普遍, 在平面的 Hdodogo- dreadtradings 中显示一个高级的Htal- drealdaldex lax 。