
Audio By Carbonatix
News and sports websites have some of the lowest levels of security adoption, a study has suggested.
A team of cyber-security experts looked at the security protocols used by the top 500 sites in various industries and online sectors.
They found that fewer than 10% of news and sports websites used basic security protocols such as HTTPS and TLS.
Even those that do are not always using the "latest or strongest protocols", one of the study's authors said.
"As time goes by, all encryption gets weaker because people find ways around it," Prof Alan Woodward, a cyber-security expert at the University of Surrey, told the BBC.
"We tested the University of Surrey's website using a site called Security Headers a couple of weeks ago and it got an A," he explained, "but it's only a C now."
Shopping and gaming
The research, published in the Journal of Cyber Security Technology, shows that some sectors seem much more security-conscious than others.
The websites of computer and technology companies and financial organisations showed a much higher level of adoption than shopping and gaming sites, for example.
"In the financial sector, almost every one of the sites we looked at had encrypted links", Prof Woodward said, "but even in retail the adoption of the very latest standards is low."
A quarter of the shopping sites studied were using Transport Layer Security (TLS), which offers tools including digital certificates, remote passwords, and a choice of ciphers to encrypt traffic between a website and its visitors.
But among news and sport websites fewer than 8% were found to be using the protocol.
Among those that did, many failed to make use of some of the strongest tools available, such as HSTS, which automatically pushes users accessing an unsecured version of a website on to the encrypted version instead.
'Click on the padlock'
"It's like news and sport content providers don't value the security of their content," Prof Woodward said.
"They're leaving themselves vulnerable to attacks like cross-site scripting, where an attacker can pretend something's come from a website when it hasn't."
But Prof Woodward warned against putting too much faith in sites that appear to have the most up-to-date and comprehensive security protocols in place.
"People assume that because they're using TLS they're having a secure conversation, but there's no guarantee about who they're having that secure conversation with," he explained.
"Some of those spoof sites are using more up-to-date security than the genuine sites. You've got to click on that padlock and check who it is you're talking to."
Latest Stories
-
Wontumi chose trial over plea bargain – Deputy AG rejects NPP’s ‘political prisoner’ claim
12 seconds -
2 persons arrested for illegal mining activities close to Agenda 111 Hospital
6 minutes -
Prof. Ladé Wosornu mentors SATOC students at maiden edition of SAMP
9 minutes -
As AI reshapes education, Ghana’s future teachers are being told what technology cannot replace
11 minutes -
BoG warns of regulatory action against Unlicensed Digital Credit Service Providers
14 minutes -
I will eventually switch from reggae and dancehall to highlife – Sugar Ranking
23 minutes -
Wontumi’s lawyers only sought an adjournment, not to move motions – Deputy AG
27 minutes -
No legal basis for Wontumi’s conviction – Atta Akyea fights back
33 minutes -
Miracles Aboagye disputes GH¢55m claim in EOCO probe
48 minutes -
Kenneth Ashigbey denies influencing Wontumi trial, dismisses judge relationship claims as false
49 minutes -
Egyapa Mercer offers free 2026 BECE result checking support for Sekondi constituents
1 hour -
Judges are not obliged to refer every constitutional claim to Supreme Court – Srem-Sai replies Minority
1 hour -
I was shocked to find my name on EOCO’s stop list – Miracles Aboagye
1 hour -
JICA is committed to strengthening laboratory capacity and biomedical research networks across Africa – JICA Ghana Chief Representative
1 hour -
Wontumi’s defence fundamentally misunderstood the law – Deputy AG
2 hours