Reply to topic  [ 2 posts ] 
Forced HTTPS add-on 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
The EFF have released a Firefox add-on to force HTTPS full session connections on server.

The add-on attempts to force a server to accept the complete session in HTTPS mode, which ensures the information passed back and forth between the browser and the server are encrypted.

Not all servers are configured to allow encrypted sessions and some that do won't have a verifiable certificate, but it is a move in the right direction.

NOTE: Many servers don't use encryption, because they need a valid certificate (otherwise the user will get a message from the browser saying that the site can't be trusted), which costs money. Also, the encryption costs extra processing on both the client and server side. The client shouldn't have any problems, but it could mean that, on the server side, the site owner must invest in a more powerful server or add additional servers behind its load balancer, in order to cope with the additional load of encrypting/decrypting the traffic.

This is why many sites restric the encrypted link to the login process (E.g. many web mail services use an encrypted session to log the user in, then revert to an unencrypted link to display the emails). Google Mail started allowing users to use a completely encrypted session back in April, but it was done quietly and the user must either start the inital contact with the server with an https:// request or change their account options to request an always encrypted link.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Last edited by big_D on Mon Jun 21, 2010 6:28 pm, edited 2 times in total.



Mon Jun 21, 2010 7:53 am
Profile ICQ
Site Admin
User avatar

Joined: Fri Apr 24, 2009 6:12 am
Posts: 7011
Location: Wiltshire
Reply with quote
nice post :D

_________________
<input type="pickmeup" name="coffee" value="espresso" />


Mon Jun 21, 2010 5:57 pm
Profile WWW
Display posts from previous:  Sort by  
Reply to topic   [ 2 posts ] 

Who is online

Users browsing this forum: No registered users and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.