Australian Government’s Bureau of Meteorology Can’t Do HTTPS
bom.gov.au
bom.gov.au
Now that it’s December, time to get moving BoM!
[1] https://www.zdnet.com/article/bom-seeks-robust-cloud-and-wan...
Wait, the do have a correct cert on port 443... some fool play is happening!!!
Someone approved a shiny new design but functionality is more inefficient now.
I did have the certificate and reverse proxy ready to go a full 18 months before I could finish the app migration. Someone previous developer was REALLY against relative URLs. "http://".$host.$urlPath everywhere.
This is surprising, can you go into more depth?
[Citation needed]
In my personal case? OpenStreetMap/Google maps.
This may be a real concern in less wealthy parts of the world, but I doubt it applies to Australia.
* based on past reading of discussions here, in some states using encryption may be illegal, not sure if this is really the case, this may eventually come to the West as well, see Australia and U.S. officials attacks on encryption
* old computers/OS/browser that the user can't update
The rain radar map seamlessly combining radars is awesome.
That's a different situation to that of the Italian Health Ministry mentioned in another comment.
"Bureau of Meteorology hacked by foreign spies in massive malware attack, report shows"
Clearly someone has an interest in targeting it - who knows if HTTPS would actually mitigate the risks though. Doubt it would hurt and would not be that difficult. It shows the lack of maintaince in BOM that leads to events like this.
Just an educated guess ;)
https://arstechnica.com/information-technology/2015/04/ddos-...
I'm reminded of the COVID reporting fiasco we had in the UK in October [0] where Public Health England - an agency of the NHS - lost COVID data because they were using .xls files to log data rather than .xlsx - the former was silently truncating critical datasets because of a hard row limit. The .xlsx format first appeared in 2007, so the NHS have only had 13 years to get their act together.
[0] https://www.theregister.com/2020/10/05/excel_england_coronav...
It took them many years to add the redirect.
It's long over due for an overhaul. I'm glad to hear it has already started.
works fine here.
Their current https server at https://www.bom.gov.au returns AkamaiGHost in the Server Header:
HTTP/1.1 307 Temporary Redirect
Server: AkamaiGHost
Content-Length: 0
Location: http://www.bom.gov.au/akamai/https-redirect.html
Date: Wed, 02 Dec 2020 12:23:22 GMT
Connection: keep-alive
Server-Timing: cdn-cache; desc=HIT
Server-Timing: edge; dur=1
Also their IP address (for me 104.108.145.63) belongs to Akamai: NetRange: 104.64.0.0 - 104.127.255.255
CIDR: 104.64.0.0/10
NetName: AKAMAI
NetHandle: NET-104-64-0-0-1
Parent: NET104 (NET-104-0-0-0-0)
NetType: Direct Allocation
OriginAS:
Organization: Akamai Technologies, Inc. (AKAMAI)Edit: looks like most readers don't get it either...
$ curl -v https://www.bom.gov.au/
* Trying 104.78.177.116...
* TCP_NODELAY set
* Connected to www.bom.gov.au (104.78.177.116) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* successfully set certificate verify locations:
* CAfile: /etc/ssl/certs/ca-certificates.crt
CApath: /etc/ssl/certs
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS handshake, Server key exchange (12):
* TLSv1.2 (IN), TLS handshake, Server finished (14):
* TLSv1.2 (OUT), TLS handshake, Client key exchange (16):
* TLSv1.2 (OUT), TLS change cipher, Client hello (1):
* TLSv1.2 (OUT), TLS handshake, Finished (20):
* TLSv1.2 (IN), TLS handshake, Finished (20):
* SSL connection using TLSv1.2 / ECDHE-RSA-AES256-GCM-SHA384
* ALPN, server accepted to use http/1.1
* Server certificate:
* subject: C=AU; ST=VIC; L=Docklands; O=Bureau of Meteorology; CN=*.bom.gov.au
* start date: Jun 10 00:00:00 2020 GMT
* expire date: Sep 9 12:00:00 2021 GMT
* subjectAltName: host "www.bom.gov.au" matched cert's "*.bom.gov.au"
* issuer: C=US; O=DigiCert Inc; OU=www.digicert.com; CN=GeoTrust RSA CA 2018
* SSL certificate verify ok.
> GET / HTTP/1.1
> Host: www.bom.gov.au
> User-Agent: curl/7.58.0
> Accept: */*
>
< HTTP/1.1 307 Temporary Redirect
< Server: AkamaiGHost
< Content-Length: 0
< Location: http://www.bom.gov.au/akamai/https-redirect.html
< Date: Wed, 02 Dec 2020 13:03:03 GMT
< Connection: keep-alive
< Server-Timing: cdn-cache; desc=HIT
< Server-Timing: edge; dur=1
<
* Connection #0 to host www.bom.gov.au left intactThis is verifiable by typing `curl -v https://www.bom.gov.au/` in your terminal.
A "curl --head https://www.bom.gov.au/" answers with "Server: AkamaiGHost", while "curl --head http://www.bom.gov.au/" answers with "Server: Apache".
In large organisations technical issues are often not the blocker. Process, approval chain, etc. often are.