Where does the encryption happen with SSL?

Posted on 2000-03-06
Medium Priority
Last Modified: 2013-12-25
A question about SSL...

When is the information that is sent by https actually encrypted?  If you request https://www.ordersomethingonline.com/ and it's an order form asking for your credit card number and it's sent to http://www.ordersomethingonline.com/cgi-bin/process.cgi (notice the http instead of https on the cgi call) does that mean:

a. The original form is encrypted when it's sent to the user before he fills it out but then what he actually fills out on the form is NOT encrypted when it's sent to the cgi script


b. The content the user types into the form is encrypted when it's sent to the cgi script, but whatever the cgi script echoes back as confirmation is NOT encrypted?
Question by:rmacmich

Accepted Solution

jhurst earned 300 total points
ID: 2589599
The browser encrypts and dcrypts data just before sending it when the connection is https, and DOES NOT for HTTP.  So, if the submission of the form is to a http-site - your credit card information is being sent in clear text format.

Realistically there is little risk of someone seeing it.  I think the risk is much less than some wait-person making an extra copy of your credit card in a restuarant etc.  

If you note all of the breaches so far have not been in the transmission of the information but of the information when it arrived and was stored at the server site.  https does not solve this problem.

Author Comment

ID: 2591628
Jhurst -- thanks.  I appreciate your answer and agree with you on both points you made.  :)

Have a good one.


Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Making a simple AJAX shopping cart Couple years ago I made my first shopping cart, I used iframe and JavaScript, it was very good at that time, there were no sessions or AJAX, I used cookies on clients machine. Today we have more advanced techno…
In a question here at Experts Exchange, a member was looking for "a little app that would allow sound to be turned OFF and ON by simply clicking on an icon in the system tray". This article shows how to achieve that, as well as providing the same OF…
Learn the basics of lists in Python. Lists, as their name suggests, are a means for ordering and storing values. : Lists are declared using brackets; for example: t = [1, 2, 3]: Lists may contain a mix of data types; for example: t = ['string', 1, T…
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

607 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question