Re: secure without the https???

From: Whoever (nobody@devnull.none)
Date: 04/06/03


From: Whoever <nobody@devnull.none>
Date: Sun, 06 Apr 2003 05:29:01 GMT

On Sun, 6 Apr 2003, sponge wrote:

> On Sat, 5 Apr 2003 15:15:00 +0000 (UTC), "Simon" <sjh@yabadabado.com>
> wrote:
>
> >Hi.
> >
> >Was confused by a site which proposed to offer secure credit card
> >transactions.
> >
> >The page containing the form does not begin https (it merely displayed the
> >company's main address beginning http) and the padlock icon (using IE6) does

> >So, is this secure or not? In my experience the page I was entering my
> >details on always displayed the secure features.
> >
>
> Secure pages (SSL) presents something of a false sense of security; it
> will do absolutely nothing to protect you against spyware or the like,
> who'se purpose is to grab info *BEFORE* it gets encrypted and sent out
> over the Internet. SSL only gives you protection against sensitive
> data being read in transit.

It also gives you verification that you are really connected to the
website that you think you are connected to. The use of certificates
provides this.

However, most browsers have been found in the past to have flaws in their
handling of certificates (or rather the certificate chain). I am not sure
if IE has been properly fixed yet.



Relevant Pages

  • Re: Web service Security
    ... Direct Authentication thru SSL ... X.509 certificates ... we need to secure the soap header as well as message itself. ... Is there any effective & secure solution which doesnt use SSL ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Commercial Certificate
    ... I created a new one based on Secure Remote Password ... Sends Username in the clear. ... > where in Williams scenario strong named assemblies are used I have found ... > for someone who DOES NOT WANT TO USE X509 certificates, Kerberos, or SSL ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • SSL CA signed certficates
    ... It surprises me that SSL certificates signed by CAs are (fully ... If I need to secure ... I have to generate a new request and have that hostname ...
    (comp.security.misc)
  • Re: IPSEC with non-domain Server
    ... Certificates are not the "most secure", rather, they are one of the 2 "more ... > authenticate computers and protect traffic integrity and confidentiality ... > Attacks on IPSec and Other Security Concerns ...
    (microsoft.public.security)
  • Re: Flaws IIS6 with AD (2003) Cert Mapping
    ... certificates and that AD uses the "model that MS have adopted for the ... So you have two choices, a secure legacy method, or an insecure "modern" ... so maybe MS's CA is only good for issuing certs in certain closed ... And you can't make the mapping process ...
    (microsoft.public.inetserver.iis.security)