Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | http - how secure is it?

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion
Register FAQ Community Calendar

http - how secure is it?
Reply
 
Thread Tools
Old 27-09-2021, 09:49   #16
heero_yuy
Perfect Soldier
 
heero_yuy's Avatar
 
Join Date: Mar 2009
Location: Worthing West Sussex
Age: 66
Services: VM 500M SH3 thingy in modem mode XL TV V6 Sony Bravia smart TV and M phone
Posts: 10,994
heero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered stars
heero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered starsheero_yuy is seeing silvered stars
Re: http - how secure is it?

Quote:
Originally Posted by Rillington View Post
Thank you for your reply.

So when you say communication with the site do you mean passwords/emails addresses or do you mean all forms of communication, such as simply going to the site and streaming/downloading data from that website?
All the communication to and from the site is encrypted. The older standard was SSL (Secure Sockets Layer). Now TLS (Transport Layer Security) is in use.

Some background reading
__________________
History is much like an endless waltz: The three beats of war, peace and revolution continue on forever.
However history will change with my coronation - Mariemaia Khushrenada
heero_yuy is offline   Reply With Quote
Advertisement
Old 27-09-2021, 10:20   #17
tweetiepooh
Virgin Media Employee
 
tweetiepooh's Avatar
 
Join Date: Sep 2005
Location: Winchester
Services: Staff MyRates BB: VM XXL TV: VM XL Phone : VM XL
Posts: 3,114
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
Re: http - how secure is it?

HTTPS doesn't just encrypt the data securing it, it also uses certificates to prove that the site is who it says it is. That's probably more important even if just reading data and that no-one is impersonating the site.



If you use a proxy, especially at work, they will install certificates in the browser so the proxy can intercept, decrypt, inspect and rerecrypt on without warnings but generally if the certificate doesn't match or isn't issued properly you browser should warn you. What is causing pain now are the alternate DNS names being enforced on the main name where previously only needing for additional names. This is where you may use variations in name to provide different services but only want one certificate, e.g. www.bbc.co.uk, news.bbc.co.uk (yes I know they do it different now) can all have one certificate, used to be www.bbc and then new.bbc etc in the alternate names, now also have to have www.bbc in the alternate names.
__________________
I work for VMO2 but reply here in my own right. Any help or advice is made on a best-effort basis. No comments construe any obligation on VMO2 or its employees.
tweetiepooh is offline   Reply With Quote
Old 27-09-2021, 12:13   #18
Jaymoss
Just a Geek
 
Join Date: Jul 2015
Posts: 3,594
Jaymoss has a bronzed appealJaymoss has a bronzed appeal
Jaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appealJaymoss has a bronzed appeal
Re: http - how secure is it?

Quote:
Originally Posted by Itshim View Post
Is that why Kaspersky and now, in my case bit defender react to me using cable forum ?
I think you need to run a few scans

Run one from bitdefender, run one from an online scan such as eset

download and install RKill https://www.bleepingcomputer.com/download/rkill/ and run this program. This will stop any processes that might be malware and block deletion if required. Then download and install malwarebytes and run a scan with that

I have a feeling something else is causing your flags

---------- Post added at 12:13 ---------- Previous post was at 12:12 ----------

Quote:
Originally Posted by Carth View Post
*nods in agreement* . . .

They keep flashing warnings up because they have to be 'seen' to be doing the job . . otherwise you'd think they were crap and not buy it again
I personally think they are flagging warnings where other users are not because the system could be compromised
Jaymoss is online now   Reply With Quote
Old 27-09-2021, 12:47   #19
Hom3r
Mum 15/08/46 - 30/09/20
 
Hom3r's Avatar
 
Join Date: Mar 2004
Location: Galactic Sector ZZ9 Plural Z Alpha, www.daves-world.co.uk. A secret Moonbase (shh don't tell anybody)
Age: 55
Services: 1 V6, 2x1TB TiVo, SH3. Samsung Galaxy Note 10+ 5G, Ton's of Smart Home stuff, & Cuddy Toy
Posts: 16,873
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Hom3r has a pair of shiny stars
Re: http - how secure is it?

I use Windows Defender.


I don't download dodgy stuff, and I scan the relevent files.
__________________
STAY AT HOME: I found out that mum will never walk again as the coronavirus attacked her nervous system. She died on September 30th, wearing a mask and she still might be alive today.
Hom3r is offline   Reply With Quote
Old 27-09-2021, 13:09   #20
mrmistoffelees
067
 
mrmistoffelees's Avatar
 
Join Date: Jul 2007
Location: Middlesbrough
Age: 48
Services: Many
Posts: 4,605
mrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronze
mrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronze
Re: http - how secure is it?

Quote:
Originally Posted by heero_yuy View Post
All the communication to and from the site is encrypted. The older standard was SSL (Secure Sockets Layer). Now TLS (Transport Layer Security) is in use.

Some background reading
Correction TLS has been in use for many years and in fact TLS 1.0 & 1.1 are considered not safe and havent been since the back end of 2019. Only TLS 1.2 and above are considered secure.
__________________
Nerves of steel, heart of gold, knob of butter......
mrmistoffelees is offline   Reply With Quote
Old 27-09-2021, 13:35   #21
MikeyB
cf.geek
 
MikeyB's Avatar
 
Join Date: Jun 2003
Location: Swindon
Age: 52
Services: BT FTTP, Humax Foxsat HDR Freesat+
Posts: 810
MikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud of
Re: http - how secure is it?

Quote:
Originally Posted by Dude111 View Post
Http is as secure as its ever been.......
Which is NOT secure!

ANY site running on http can be intercepted and the contents of the site changed before it gets to your browser, https prevents this happening.
Of course, https encrypts all traffic between your browser & the server, so for example your password & any form you fill in, cannot be snooped upon.

Here's a very good article about why every website needs https
https://www.troyhunt.com/heres-why-y...e-needs-https/

There's a video with a demo of changing the contents of a site, without actually changing the site, just what is delivered to your browser.

But as others have said, https does not mean that the site itself is safe or secure, it's the connection to/from the server


Quote:
Originally Posted by Dude111 View Post
I have a question..... If these sites can do it w/o issues,why cant all sites??

I have been trying to get my friend who runs sitcomsonline.com/boards?styleid=1077 to enable http but he doesnt think it will work..... I have told him of city-data but he doesnt understand
All sites could allow http, but the vast majority of sites today choose to only allow https as it's more secure for all involved, simple as that.
If your friend does allow http then he may as well disable https altogether, no point in having it then.

Quote:
Originally Posted by Paul View Post
Many sites simply do not need to be secure.
A news site for example, or indeed, any informational site.
News sites a prime example of needing https, imagine if the contents of the BBC news or any other news site was intercepted as per my link above?

There is no excuse for not having https these days, can be done totally for free with a little work.

Last edited by MikeyB; 27-09-2021 at 14:21.
MikeyB is offline   Reply With Quote
Old 27-09-2021, 13:44   #22
pip08456
Sad Doig Fan!
 
pip08456's Avatar
 
Join Date: Aug 2007
Location: Barry South Wales
Age: 68
Services: With VM for BB 250Mb service.(Deal)
Posts: 11,654
pip08456 has a nice shiny starpip08456 has a nice shiny star
pip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny starpip08456 has a nice shiny star
Re: http - how secure is it?

Quote:
Originally Posted by mrmistoffelees View Post
Correction TLS has been in use for many years and in fact TLS 1.0 & 1.1 are considered not safe and havent been since the back end of 2019. Only TLS 1.2 and above are considered secure.
An unnecessary correction. Heero's post contained correct info and included a link for those who wished more info.
pip08456 is online now   Reply With Quote
Old 27-09-2021, 14:40   #23
mrmistoffelees
067
 
mrmistoffelees's Avatar
 
Join Date: Jul 2007
Location: Middlesbrough
Age: 48
Services: Many
Posts: 4,605
mrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronze
mrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronzemrmistoffelees is cast in bronze
Re: http - how secure is it?

Quote:
Originally Posted by pip08456 View Post
An unnecessary correction. Heero's post contained correct info and included a link for those who wished more info.

ssssh, qualified people talking....
__________________
Nerves of steel, heart of gold, knob of butter......
mrmistoffelees is offline   Reply With Quote
Old 27-09-2021, 19:57   #24
BenMcr
Virgin Media Staff
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: http - how secure is it?

Quote:
Originally Posted by tweetiepooh View Post
HTTPS doesn't just encrypt the data securing it, it also uses certificates to prove that the site is who it says it is. That's probably more important even if just reading data and that no-one is impersonating the site.
Though I think it's always worth making clear that a certificate that doesn't generate a browser warning just means that the site has a security certificate that has been issued by a valid authority for the site domain.

You could have a valid https certificate for cableforum.uk or cablef0rum.uk.

A valid certificate doesn't guarantee anything about the trustworthiness of the site you're on.
__________________
I work for Virgin Media but all views are my own.

Last edited by BenMcr; 27-09-2021 at 20:00.
BenMcr is offline   Reply With Quote
Old 27-09-2021, 21:59   #25
Carth
cf.mega poster
 
Join Date: Jul 2004
Location: At the Leaving door
Posts: 4,050
Carth has a bronze arrayCarth has a bronze arrayCarth has a bronze array
Carth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze arrayCarth has a bronze array
Re: http - how secure is it?

I vaguely recall a year or two ago, I had quite a few certificate warnings on various sites/pages that normally were ok . . . not sure if it was down to a change in how they're done or a cock up somewhere in the system?
Carth is offline   Reply With Quote
Old 28-09-2021, 02:08   #26
Paul
Dr Pepper Addict
Cable Forum Team
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 61
Services: Flextel SIP : Sky Mobile : Sky Q TV : VM BB (1000 Mbps) : Aquiss FTTP (330 Mbps)
Posts: 27,709
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: http - how secure is it?

Quote:
Originally Posted by MikeyB View Post
News sites a prime example of needing https, imagine if the contents of the BBC news or any other news site was intercepted as per my link above?
Try taking off your tin foil hat for a few minutes.
News sites do not need to use https, of course, they can choose to.

Quote:
Originally Posted by tweetiepooh View Post
What is causing pain now are the alternate DNS names being enforced on the main name where previously only needing for additional names.
I dont really know what you are trying to say here.
A single SSL certificate can have many alt names, hundreds if you are daft enough (our own cerificate here has nine).
You can also get wildcard certificates to cover all the sub domains on a main domain.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Old 28-09-2021, 07:16   #27
BenMcr
Virgin Media Staff
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: http - how secure is it?

Quote:
Originally Posted by Carth View Post
I vaguely recall a year or two ago, I had quite a few certificate warnings on various sites/pages that normally were ok . . . not sure if it was down to a change in how they're done or a cock up somewhere in the system?
There have been incidents in the last few years where a certificate authority made errors that meant they couldn't be relied on and their certificates were distrusted.

One of the biggest was Symantec

https://www.thesslstore.com/blog/sym...usted-tuesday/

Quote:
Google Chrome 66 will distrust any Symantec, GeoTrust, Thawte & RapidSSL certificate issued before June 1, 2016

On Tuesday, April 17 [2018], Google will push the newest version of its web browser, Chrome 66, to stable, effectively distrusting any Symantec CA brand (Symantec, GeoTrust, Thawte and RapidSSL) SSL certificate issued before June 1, 2016. Once Chrome 66 goes live and its users begin to update their browsers, any website still using one of the affected Symantec CA brand SSL certificates will be slapped with a browser warning.
But smaller authorities are impacted too https://www.zdnet.com/article/google...a-from-chrome/
__________________
I work for Virgin Media but all views are my own.

Last edited by BenMcr; 28-09-2021 at 07:20.
BenMcr is offline   Reply With Quote
Old 28-09-2021, 08:21   #28
Dude111
An Awesome Dude
 
Join Date: Mar 2009
Posts: 3,868
Dude111 has a bronzed appealDude111 has a bronzed appeal
Dude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appealDude111 has a bronzed appeal
Quote:
Originally Posted by MikeyB
If your friend does allow http then he may as well disable https altogether, no point in having it then.
Well more people use the https side. Some on older browsers cant so they use the HTTP side...

Or the site can install 'NO BROWSER LEFT BEHIND' which lets even older browsers connect HTTPS

http://blog.cloudflare.com/sha-1-dep...er-left-behind


Quote:
Originally Posted by Paul
Honestly, just ditch them all.
I agree...I dont have any!!
Dude111 is offline   Reply With Quote
Old 28-09-2021, 09:48   #29
tweetiepooh
Virgin Media Employee
 
tweetiepooh's Avatar
 
Join Date: Sep 2005
Location: Winchester
Services: Staff MyRates BB: VM XXL TV: VM XL Phone : VM XL
Posts: 3,114
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
tweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appealtweetiepooh has a bronzed appeal
Re: http - how secure is it?

Quote:
Originally Posted by Paul View Post
Try taking off your tin foil hat for a few minutes.
News sites do not need to use https, of course, they can choose to.


I dont really know what you are trying to say here.
A single SSL certificate can have many alt names, hundreds if you are daft enough (our own cerificate here has nine).
You can also get wildcard certificates to cover all the sub domains on a main domain.
It used to be that you didn't have to put the main cert name in the alt DNS names now you do. At work where we gen our own certificates with own signing authority (internal) it's meaning that sometimes we need to get new certificates as newer browsers flag up that the site isn't in cert Alt DNS names. Mostly not a problem but the software we use in one case only allows one name in the Alt DNS names so we have to put main site name in. Now add we have multiple domains as well and it all gets fun if you want to make it easy to access site(s).
__________________
I work for VMO2 but reply here in my own right. Any help or advice is made on a best-effort basis. No comments construe any obligation on VMO2 or its employees.
tweetiepooh is offline   Reply With Quote
Old 28-09-2021, 11:58   #30
MikeyB
cf.geek
 
MikeyB's Avatar
 
Join Date: Jun 2003
Location: Swindon
Age: 52
Services: BT FTTP, Humax Foxsat HDR Freesat+
Posts: 810
MikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud ofMikeyB has much to be proud of
Re: http - how secure is it?

Quote:
Originally Posted by Paul View Post
Try taking off your tin foil hat for a few minutes.
News sites do not need to use https, of course, they can choose to.
Of course that is an extreme example, but today, what benefit is there for a site not running https?


Quote:
Originally Posted by Dude111 View Post
Well more people use the https side. Some on older browsers cant so they use the HTTP side...
And herein lies your issue with https, you are using an unsupported & insecure browser on an unsupported & insecure OS, not much anyone apart from you can do about that.

As I said before, there is no excuse today, for any website not to allow only https connection.
MikeyB is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:18.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.