Non-tech being very important here. The US government is not a technology company. So think of the worst enterprise software you've seen and the US government has it beat somewhere on some system they are still using.
How does this happen? Contracts, they write contracts to the lowest bidder to build them software and then they pick the greenest/cheapest software engineers to do work in a mix of waterfall, agile, what's older than waterfall?
On top of that they've got mission critical software that runs on this stuff. A silly little change like upgrading paper Notices to Airmen (NOTAMs) requires YEARS of planning, safety analysis, and buy in from a representative every airport/airline/airtraffic controller across the US. Multiple unions etc.
At it's worst the us government is slower than the slowest enterprise company you've seen.
On top of all that, there is a review board for EVERY (mostly open source library you want to import, so there aren't bad actors on it. This review process is slow and pushes back on innovation. The worst thing you can do as a contractor is not hit your deadline. So many of them use tried and true technologies to get the job done, but don't innovate.
Is it by decision? Yes the decision to pick the cheapest contractors, yes by the decision to include security in a way that actually slows things down, yes by a myriad of decisions that make innovating government software really hard.
Is it by incompetence? Meh, yes and no. You have people even at these contracts who are railing and screaming against this. There is competence in all these places. But the pressure to slow down and do things a specific way push back so hard it's really difficult to accept new risk.
And this was just my experience on one contract. Another government contract was super innovative and fun.
Also the innovative nature of what we were building at the new contract vs. just redoing a crud app.
I suspect part of it was me too. My first job, vs my ability to discern better contracts etc in for future ones.
The switch from HTTP to HTTPS is almost never as simple as "call LetsEncrypt and switch the port number". If you have an existing HTTP site that includes Images, Script, Styles, Frames from other HTTP resources, switching the top of the page to HTTPS may break functionality on the page if the browser's security settings deny HTTP resources from being loaded on the newly HTTPS page.
That said, there's really no reason any government shouldn't prioritize these fixes... except we are in the middle of a COVID-pocalypse where budgets are likely to get slashed. Sometimes it's "incompetence" of management (not seeing the risk after it's described to them or their underlings not communicating the risk), but mostly
I know its a bit of a nitpick, but its important that they know we understand the laws they want to push through and STILL disagree with them.
I take it you've never worked for the government, have you?
Heads should roll, really.
You can read more about this here: http://n-gate.com/software/2017/ (Discourse on https)
Such a pointless read.
Make a valid argument and I'll listen to you, but parroting "but I don't need it" does nothing to add to the conversation at all.
Is adding HTTPS a 100% required critical sev0 ship-blocking bug on every site in the world? No. Is it a valuable improvement to add HTTPS? I'd argue that it is.