Experience shows that most researchers and developers tend to treat plain-domains (those that are \textit{not} prefixed with \quotes{www} sub-domains, e.g. \quotes{example.com}) as synonyms for their equivalent www-domains (those that are prefixed with \quotes{www} sub-domains, e.g. \quotes{\justify www.example.com}). In this paper, we analyse datasets of nearly two million plain-domains against their equivalent www-domains to answer the following question: \textit{Do plain-domains and their equivalent www-domains differ in TLS security configurations and certificates? If so, to what extent?} Our results provide evidence of an interesting phenomenon: plain-domains and their equivalent www-domains differ in TLS security configurations and certificates in a non-trivial number of cases. Furthermore, www-domains tend to have stronger security configurations than their equivalent plain-domains. Interestingly, this phenomenon is more prevalent in the most-visited domains than in randomly-chosen domains. Further analysis of the top domains dataset shows that 53.35\% of the plain-domains that show one or more weakness indicators (e.g. expired certificate) that are not shown in their equivalent www-domains perform HTTPS redirection from HTTPS plain-domains to their equivalent HTTPS www-domains. Additionally, 24.71\% of these redirections contains plain-text HTTP intermediate URLs. In these cases, users see the final www-domains with strong TLS configurations and certificates, but in fact, the HTTPS request has passed through plain-domains that have less secure TLS configurations and certificates. Clearly, such a set-up introduces a weak link in the security of the overall interaction.
翻译:经验显示, 大多数研究人员和开发者倾向于将平面数据( 那些是\ textit{ not} 预设为\ quotes{ www} 的子domain, 例如\ quotes{ example.com}) 当作等效 www- domains (那些预设为\ quotes{www} www- domains 的) 的同义词处理。 在本文中, 我们分析近两百万平面域的数据集, 相对等效 www- domains 的相同 www- domains, 解答以下问题:\ textits{domains 以及等同的 www- domains 的等同性? 如果是这样的话, 到什么程度? 我们的结果提供了一种有趣的现象的证据: 平面域和等效的 www-domains 安全配置和证书在非平面 textial- teval 中是不同的 。 此外, www- dealdealdomains 等值的等值的和等值的等值的等值的对等值的对等值的对等值的对等值的对等值的对等值的对等值的对等值, ral- der- der35 表示的对等值的对等值的对等值对等值对等值的对等值对等值的对等值对等值对等值对等值的对等值对等值对等值对等的对等的对等值的对等值的对等值的对等值的对等值的对等值的对等域的对等值的对等值对等值对等值对等值对等值对等值对等值对等值的对等的对等值对等的对等的对等的对等值的对等的对等值的对等值的对等值的对等值的对等值的对等值的对等值的对等值的对等值对等值的对等的对等值对等值对等值对等值对等值对等值对等值对等值对等值对等值对等值对等的对等值的