Re: https-Question



In article <e95k2m$66q$1@xxxxxxxxxxxxxxxxxxxxxxxxx>,
Wilhelm Kutting <wkutting@xxxxxxxx> wrote:

Hello, i got a little understanding Problem.
on some http-Sites i can log into my Account with Name/Passwort.
The Form-Login-Page ist only http with form action directing to a
"secure" https page.
So - in my understanding the username and password is send uncrypted
over the Net.
Only the later Communication is done secure.

Am i right that only a https login-Form-page would be safe?

Wilhelm,
Basically, yes.

HTTP = not secure, name and password sent without encryption

HTTPS = secure, name and password sent encrypted


Hope this helps

--
Philip
http://NikitaTheSpider.com/
Whole-site HTML validation, link checking and more
.



Relevant Pages

  • RE: Secure Transactions over HTTPS????
    ... different keys). ... encryption is weak and the Linux world with vouch for that. ... Subject: Secure Transactions over HTTPS???? ... How secure is HTTPS?? ...
    (Security-Basics)
  • RE: Secure Transactions over HTTPS????
    ... different keys). ... encryption is weak and the Linux world with vouch for that. ... Subject: Secure Transactions over HTTPS???? ... How secure is HTTPS?? ...
    (Focus-Microsoft)
  • Re: Will rpc over http provide certian encryption?
    ... (WEB pull) ... Do you think the rpc over https can replace this solution? ... What 3rd party encryption solutions are you using now? ... The connection/communication is secure, but the actual messages - though ...
    (microsoft.public.exchange.admin)
  • Re: Will rpc over http provide certian encryption?
    ... Once again, you'll be using *HTTPS*, wouldn't you (uses SSL encryption)? ... If you do, yes, the session is secured. ... The connection/communication is secure, but the actual messages - though ...
    (microsoft.public.exchange.admin)
  • Re: Is this REALLY a secure site?
    ... >> How can anyone really know if an SSL or HTTPS connection is truly ... Even if it is theoretically secure ... major credit card company wound up making the authorization against my ... > site uses a numerical IP address: those are always bogus. ...
    (microsoft.public.windowsxp.general)