Page 1 of 1

Is an https:// connection always secure?

Posted: Mon Feb 22, 2010 1:40 am
by phule
Can a website direct you to a webpage that has a https:// connection and still be unsecure? I've noticed that NS will not force such a website to be secure.

An example is Grandtea.com at http://www.grandtea.com/

Re: Is an https:// connection always secure?

Posted: Mon Feb 22, 2010 2:19 am
by Alan Baxter
Once you see https://www.grandtea.com in the url bar, your connection is encrypted and secure from eavesdropping.
Grandtea.com looks safe enough to me. It switches itself to https as soon as I select Checkout. That said, I was also able to successfully force https by adding the following to NoScript Options > Advanced > HTTPS > Behavior > Force the following sites to use secure connections:

Code: Select all

www.grandtea.com
Edit: https as soon as I select Checkout

Re: Is an https:// connection always secure?

Posted: Mon Feb 22, 2010 3:12 am
by Alan Baxter
Alan Baxter wrote:Once you see https://www.grandtea.com in the url bar, your connection is encrypted and secure from eavesdropping.
Followup:
Apparently that's true only if the favicon turns blue or green too.
The Checkout page had an https connection and the blue favicon in the url bar. I think the blue favicon with grandtea.com in it indicates that all the content on the page was encrypted. But if I enter https://www.grandtea.com/ into the url bar, then the favicon doesn't change to blue. I clicked on the favicon and then clicked More Information to bring up the Page Info > Security information. Its technical details say that parts of the page I'm viewing are not encrypted. I think that's OK; they weren't sending me any information that needed to be encrypted.

Re: Is an https:// connection always secure?

Posted: Tue Feb 23, 2010 1:11 am
by phule
Alan Baxter wrote:Apparently that's true only if the favicon turns blue or green too.
The Checkout page had an https connection and the blue favicon in the url bar. I think the blue favicon with grandtea.com in it indicates that all the content on the page was encrypted. But if I enter https://www.grandtea.com/ into the url bar, then the favicon doesn't change to blue. I clicked on the favicon and then clicked More Information to bring up the Page Info > Security information. Its technical details say that parts of the page I'm viewing are not encrypted. I think that's OK; they weren't sending me any information that needed to be encrypted.
The favicon not changing color plus the padlock icon at the bottom of the window not "locking" is what made me suspicious. Thanks for clearing things up!

Re: Is an https:// connection always secure?

Posted: Tue Feb 23, 2010 3:57 am
by Alan Baxter
You're welcome. Happy shopping!

Re: Is an https:// connection always secure?

Posted: Tue Feb 23, 2010 6:54 am
by dhouwn
Alan Baxter wrote:I think that's OK; they weren't sending me any information that needed to be encrypted.
But you should be aware of the fact that these unencrypted information can be manipulated. HTTPS is not only about encryption.