Solved

Is a website still secure without HTTPS?

Posted on 2013-01-07
4
433 Views
Last Modified: 2013-01-08
Hello,

I have built a website and when I log in to the site, the site's URL turns to HTTPS. I have a valid certificate from Network Solutions, and the little logo from Network Solutions says the site is secure.  The home page has a HTTPS. However, I can go to a page's address in Internet Explorer and take out the "S" in the URL. The page still comes up, but is the HTTP request being transferred in an encrypted way when I take out the "S"?

Thanks.
0
Comment
Question by:PBIT
  • 2
4 Comments
 
LVL 33

Assisted Solution

by:Dave Howe
Dave Howe earned 350 total points
ID: 38753904
No, it isn't.

Most sites have a listener on 443 (for https) and on 80 (for http) - your browser is smart enough to pick the correct port when you change the url.

you can verify this easily enough by running wireshark or microsoft network monitor (both free!) at same time as testing, and seeing what they can "see" of the traffic.
0
 
LVL 79

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 150 total points
ID: 38754091
You can also force https if wanted. In the website ssl settings, check require ssl
or do a url rewrite
<rule name="Force HTTPS" enabled="true">
        <match url="(.*)" ignoreCase="false" />
        <conditions>
            <add input="{HTTPS}" pattern="off" />
        </conditions>
        <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" appendQueryString="true" redirectType="Permanent" />
    </rule>
0
 

Author Comment

by:PBIT
ID: 38755635
Ve3ofa,  would this code be placed in the aspx page? I am using c# ASP. NET.  Where would this code be?

I would want to force the pages to keep thier https as much as possible.

Thanks.
0
 
LVL 33

Accepted Solution

by:
Dave Howe earned 350 total points
ID: 38755681
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
How to create a custom search shortcut to site-search Experts Exchange using Google in the Firefox browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch your Bookmark Menu: Press 'Ctrl +…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question