Showing posts with label http. Show all posts
Showing posts with label http. Show all posts

Thursday, April 19, 2012

Certified and Validated

In this post, I will elaborate more on HTTPS. We previously discussed the term phishing in this blog. To summarize, phishing is an attempt to manipulate or trick a person into providing confidential information to an individual that is not authorized to receive such information. To protect yourself from phishing, recent web browsers have developed a way for checking if a website is valid or not.

Web browsers trust HTTPS websites based on certificate authorities which come pre-installed in their software. Examples of certificate authorities are “Microsoft” and “VeriSign”. In the example below, the bank's web site is verified by "VeriSign, Inc."

Always look for the green address bar. Recent web browsers show a green address bar in order to tell the user that this web site is legit and trustworthy. Its purpose is to give more confidence to the user and ensure them that they are visiting a trusted web site.

This issue plays an important role in Information Security. Next time you visit a web site make sure you look for the green address, especially web sites that ask for important and private information and web sites for payment transactions. To reassure yourself, check the certificate to know if this site is validated.

Tuesday, April 10, 2012

Look for the S in The HTTP

We are all familiar with the word HTTP, Hyper Text Transfer Protocol. It is an application protocol that functions as a request/response protocol in the client/server computing model. Basically, most of what you see in your browser is transferred to your computer over HTTP. Our topic is not about HTTP and its functions, it is about HTTP and security.

Some of us are familiar with HTTPS, Hyper Text Transfer Protocol Secure. As you can see, the letter ‘S’ stands for secure. The ‘S’ comes from SSL/TLS protocol, which provides communication security over the Internet. A combination of HTTP and SSL/TLS produces HTTPS. The main objective of HTTPS is to provide a secure connection over an insecure network. Not all pages have HTTPS since it is very expensive. Pages that communicate personal data like passwords and credit cards use the HTTPS.

A page who’s URL begins with “https://” means that this page is secured and the current connection between you and the server is secured, since it provides an encrypted communication and secure identification. Payment transactions on the Internet often use HTTPS communication in order to prevent any third part interception.
You can now easily differentiate between HTTP and HTTPS. HTTP starts with “http://” :

It is an unsecured connection that is subject to third party interception, which can allow attackers to gain access to sensitive information. On the other hand, HTTPS starts with “https://”  
It is a secured connection that is designed to resist attacks or interception or even eavesdropping.

To conclude, always look for the ‘S’ in HTTP when providing secure and confidential data, this will ensure that this page is secure and nothing is suspicious about it. In my next post I will address more about HTTPS.