Solved

http vs https : when is a login safe ?

Posted on 2014-07-30
10
319 Views
Last Modified: 2014-07-30
when I am on some site such as http://www.sample.com/, and there are 2 form fields, such as username and password on that site, and a SUBMIT button: is this login safe or unsafe ? After pressing SUBMIT, I come to a https site.
Same question, in other words: is the ssl protection active depending on the presence/absence of the https in the the starting site xor in the  destination site ?
0
Comment
Question by:Sonja_M
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 83

Accepted Solution

by:
Dave Baldwin earned 363 total points
ID: 40230115
It's not the current page but the connection to the next page that is important.  The current page using 'http' has already been requested and received.  What you want to keep the form data secure is for the next request (from the form to the destination page) to be using 'https'.
0
 
LVL 5

Assisted Solution

by:Sean Jackson
Sean Jackson earned 40 total points
ID: 40230122
If you're on a page hosted at http:// and you hit submit, that data will travel from your browser to that server unencrypted.  If that page is on https:// and you hit submit, the data is going to travel through an encrypted tunnel.  

Entering a username and password on http:// is not safe.  It can be subject to others who are watching the traffic.
0
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 363 total points
ID: 40230144
Sean, that's Not The Way It Works.  It's the form 'action' URL that needs to be 'https', not the current page.  The current page is already done.  There is nothing that can read from it anymore.
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 58

Assisted Solution

by:Gary
Gary earned 92 total points
ID: 40230150
Whilst login forms should really be on an HTTPS page to prevent any hacking Dave's comment is the correct one
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 92 total points
ID: 40230183
Just to be clear - When I say hacking I mean of the unsecure form data being sent to the browser initially not hacking the posted data

p.s.
No points for this, was just to backup Dave's answer.
0
 
LVL 5

Assisted Solution

by:Sean Jackson
Sean Jackson earned 40 total points
ID: 40230257
Dave, are you saying that the page is rendered in plaintext, and then if I hit submit, and the form action is GET or POST, when it connects back to the server, that's when the SSL handshake occurs?  Not when the authenticated user gets their privileged page?
0
 
LVL 58

Assisted Solution

by:Gary
Gary earned 92 total points
ID: 40230267
Thats correct.
0
 
LVL 52

Expert Comment

by:Scott Fell, EE MVE
ID: 40230402
No points.   I concur with Dave's original answer.
0
 
LVL 83

Assisted Solution

by:Dave Baldwin
Dave Baldwin earned 363 total points
ID: 40230404
Yes, that's what I'm saying.  It's fine if both pages are SSL / https like Gary suggested but the important page, the request with the info you want to protect, is the 'action' page in the form.  That's when the info needs to be secure.  When you're typing your info into the form, it has already been loaded into your browser.  It's when you submit the form, that you need it to be encrypted to prevent people from reading it.
0
 

Author Closing Comment

by:Sonja_M
ID: 40230654
thank you all for your detailed and precise answers and interesting additional aspects
0

Featured Post

ScreenConnect 6.0 Free Trial

At ScreenConnect, partner feedback doesn't fall on deaf ears. We collected partner suggestions off of their virtual wish list and transformed them into one game-changing release: ScreenConnect 6.0. Explore all of the extras and enhancements for yourself!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
I've been an avid user and supporter of Malwarebytes Premium Version 2.x for years. It's an excellent product that runs alongside just about any Anti-Virus application without issues. It seems to have an uncanny ability to pick up many things that A…
Learn how to set-up custom confirmation messages to users who complete your Wufoo form. Include inputs from fields in your form, webpage redirects, and more with Wufoo’s confirmation options.
Learn how to set-up PayPal payment integration in your Wufoo form. Allow your users to remit payment through PayPal upon completion of your online form. This is helpful for collecting membership payments, customer payments, donations, and more.

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question