Re: https-Question



Wilhelm Kutting <wkutting@xxxxxxxx> writes:

Nikita the Spider schrieb:
In article <e95k2m$66q$1@xxxxxxxxxxxxxxxxxxxxxxxxx>,
Wilhelm Kutting <wkutting@xxxxxxxx> wrote:

Hello, i got a little understanding Problem.
on some http-Sites i can log into my Account with Name/Passwort.
The Form-Login-Page ist only http with form action directing to a
"secure" https page.
So - in my understanding the username and password is send
uncrypted over the Net.
Only the later Communication is done secure.

Am i right that only a https login-Form-page would be safe?
Wilhelm,
Basically, yes.
HTTP = not secure, name and password sent without encryption
HTTPS = secure, name and password sent encrypted
Hope this helps

So if the loginform is http, the username and password is send via
cleartext.

No.

It's the URL in the form element's "action" attribute that determines whether
the user name and password are encrypted, not the URL of the form itself.

As others have mentioned, fetching the form itself via https:// does provide
user feedback in many browsers which display "lock" icons and such. But it
technically makes no difference whatsoever in how the form data is sent to
the action URL.

sherm--

--
Web Hosting by West Virginians, for West Virginians: http://wv-www.net
Cocoa programming in Perl: http://camelbones.sourceforge.net
.



Relevant Pages

  • Re: https-Question
    ... HTTP = not secure, name and password sent without encryption ... So if the loginform is http, the username and password is send via ... The protocol used to *retrieve* the form only affects the protocol ...
    (comp.infosystems.www.authoring.html)
  • Re: is that a good offer for a server installation?
    ... SO linux based upon kernel 2.6xx ... installation of cwfm (a software that manages files, at first I believed that should be created by them, but then I found out to be free on the net http://cwfm.sourceforge.net) upload and download are managed via http ... they told him that ftp is not secure for this and their program is based ... they use a https connection then it should be secure enough. ...
    (comp.infosystems.www.servers.unix)
  • Re: Encrypted or Not Encrypted
    ... Optimally they should enter their creds after ssl has setup the secure session, ... The handshake requires that the client initiate the SSL connection. ... The agent acting as the HTTP client should also act as the TLS ...
    (Security-Basics)
  • Re: Video conference via Webcam with audio ??
    ... transport protocol for encrypted communications. ... which details the port useage of application protocols like SIP, H323, ... They say they can use SIP, RTP with TLS encryption layers. ... >And the can only use http, and I need to encrypt the video/audio (SSL ...
    (microsoft.public.windowsmedia.encoder)
  • Re: Help, my machine has been hacked
    ... > being used to perform port scans on a bank. ... > closed HTTP) ... > DSLReports and they all report that my machine is secure. ... > 4) Recommendations for a hardware firewall? ...
    (comp.os.linux.security)