Below is a screenshot of how to enable https on Facebook.
This will protect you from people trying to see what is being transmitted over the network, and also things like Firesheep, a free Firefox extension that allows people to log in as YOU.
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts
Tuesday, February 1, 2011
Wednesday, January 26, 2011
A more secure Facebook connection
Nice! Facebook is now making secure connections to it possible.
From today's Facebook blog entry:
I tried going to the "Account Security" section of my Account settings, but did not see the option available yet. Maybe tomorrow.
See my previous blog entry about using free public internet.
From today's Facebook blog entry:
Starting today we'll provide you with the ability to experience Facebook entirely over HTTPS. You should consider enabling this option if you frequently use Facebook from public Internet access points found at coffee shops, airports, libraries or schools. The option will exist as part of our advanced security features, which you can find in the "Account Security" section of the Account Settings page.This protects any information (including profile pages, contact information, location of you and your friends, etc) sent to/from your browser and Facebook's server from any eavesdroppers. So, if you are in a public area, such as an airport, library, coffee shop, where there are many people (possibly malicious), you'll definitely want to enable this. Because you have to log in to turn it on, you'll probably just want to go ahead and enable it.
I tried going to the "Account Security" section of my Account settings, but did not see the option available yet. Maybe tomorrow.
See my previous blog entry about using free public internet.
Monday, August 9, 2010
Secure searches
Saw this while browsing the web today.. Secure Google searches..
Basically to perform a secure search (over SSL), use https://encrypted.google.com.
This prevents people (such as the people who run the network you're using, such as your employer, or someone sniffing around on your network) from being able to see what words you're searching on (and the search results pages that Google suggests.)
There's also a Google Chrome extension for this.
Basically to perform a secure search (over SSL), use https://encrypted.google.com.
This prevents people (such as the people who run the network you're using, such as your employer, or someone sniffing around on your network) from being able to see what words you're searching on (and the search results pages that Google suggests.)
There's also a Google Chrome extension for this.
Sunday, June 7, 2009
How can I tell if my connection to this web site is encrypted?
As mentioned before, just because you are sending information through your computer (versus a physical form like a letter) does not mean it is completely private. And just because you use a password to log into a site does not mean the information you send/receive is completely private. In my last post, we looked at the importance of having an encrypted connection when using wireless internet, especially the free public kind.
How can you tell that your connection with a certain web site is secure and private?
Encrypted web sites have the URL "https://yourwebsite.com" instead of "http://yourwebsite.com". Note the extra 's' in "https". This shows that you are connected using secure http (and not just regular http).
Most web browsers show a picture of a padlock in the lower right-hand corner of the browser if your connection is encrypted. Note that a web page can display any pictures that it wants, including a picture of a padlock - but that doesn't necessarily mean anything. You must look for the browser's padlock picture. Below are pictures highlighting the "https" and the padlock in Internet Explorer 6 and in Firefox 3.


Even if you have an encrypted session, you should make sure you have an encrypted session to the right site. Are you connected to "https://www.amazon.com" or are you connected to "https://www.amazon.org"? Are you connected to "https://www.paypal.com" or are you connected to "https://www.paypal.online-site.com"?
Someone could set up a fake web site that looks like the web site you want to go to, and just wait for you to enter and send him your username and password.
If you log into a web site using regular http, your username and password is sent unencrypted, and anyone trying to "overhear" what you said will be able to know your username and password. So, to be sure, use https when possible. (Windows Hotmail uses http by default unless you click on "Use enhanced security" to use https.) Some web sites where security is a priority (such as any online banking web site) will automatically switch you over from http to https when you go to their site. (Try going to http://www.bankofamerica.com and you'll see this happen.)
Many online webmail sites use https to log you in (so your username and password are kept secret), but switch to regular http afterwards (which means someone can eavesdrop on the mail you send/receive at the very least.) Yahoo! mail does this, and so does Gmail by default, unless you turn on the https setting mentioned before.
Not all web sites are set up to use https. But if you had a choice, would you choose to use http or https? Hopefully you answered https! Make it a habit and type in https://...!
More on how you can tell a site is who it says it is later.
How can you tell that your connection with a certain web site is secure and private?
Encrypted web sites have the URL "https://yourwebsite.com" instead of "http://yourwebsite.com". Note the extra 's' in "https". This shows that you are connected using secure http (and not just regular http).
Most web browsers show a picture of a padlock in the lower right-hand corner of the browser if your connection is encrypted. Note that a web page can display any pictures that it wants, including a picture of a padlock - but that doesn't necessarily mean anything. You must look for the browser's padlock picture. Below are pictures highlighting the "https" and the padlock in Internet Explorer 6 and in Firefox 3.


Even if you have an encrypted session, you should make sure you have an encrypted session to the right site. Are you connected to "https://www.amazon.com" or are you connected to "https://www.amazon.org"? Are you connected to "https://www.paypal.com" or are you connected to "https://www.paypal.online-site.com"?
Someone could set up a fake web site that looks like the web site you want to go to, and just wait for you to enter and send him your username and password.
If you log into a web site using regular http, your username and password is sent unencrypted, and anyone trying to "overhear" what you said will be able to know your username and password. So, to be sure, use https when possible. (Windows Hotmail uses http by default unless you click on "Use enhanced security" to use https.) Some web sites where security is a priority (such as any online banking web site) will automatically switch you over from http to https when you go to their site. (Try going to http://www.bankofamerica.com and you'll see this happen.)
Many online webmail sites use https to log you in (so your username and password are kept secret), but switch to regular http afterwards (which means someone can eavesdrop on the mail you send/receive at the very least.) Yahoo! mail does this, and so does Gmail by default, unless you turn on the https setting mentioned before.
Not all web sites are set up to use https. But if you had a choice, would you choose to use http or https? Hopefully you answered https! Make it a habit and type in https://...!
More on how you can tell a site is who it says it is later.
Monday, May 25, 2009
Using free public wireless internet
What do you do when you want to use the internet, but don't have your own connection? Most people will search for a wireless signal and try to get "free internet." Most coffee shops, airports, hotels, schools, etc., provide free WiFi. Everyone likes FREE stuff, but if you are sending any personal information, you may want to think twice because Mr. Stranger might be able to read it.
Imagine you are at a party, and you see two of your best friends. You have some wonderful personal news to tell them, and you get them together to share your news (in the middle of the crowd.) As you talk with your two friends, a nosy Mr. Stranger is curious about what's going on, walks by casually, listens intently, and overhears your conversation. Something similar could also happen when using free public wireless internet.
When you are using a wireless network, you are sending and receiving messages back and forth with the wireless router to which you are connected via radio waves. You're having a conversation with the router (although not a very personal one - the router is more like a middleman. It just relays the messages.) Any computers within distance (i.e. the radio waves can reach them) can also hear your conversation. Usually computers ignore messages that are not addressed to them. However, a malicious Mr. Stranger could use various tools on his computer to read those messages. (This is called packet sniffing, although packet sniffing is not always malicious.)

For example, in the picture above - all the computers could potentially see what messages others are sending to and receiving from the router (if the messages aren't encrypted.) Computer ABC can see the username and password Computer XYZ is using to log into the insecure web site toothbrush.com, as well as the email to Bob that you are sending. If you are just surfing the web, such as checking sports scores or the weather forecast, then you may not care if others can see what you're doing.
This is why it is important to make sure you are using encryption when sending confidential information over a wireless connection. Using encryption is like using your own invented language with your friends so that no one else can understand. People can still hear what you're saying, and who you are saying it to, but they won't understand what you're saying (unless they figure out your invented language.)
Turning on the gmail security setting suggested in the last post makes your computer and the gmail server use their own invented language.
Other web sites that require a password may or may not use encryption. Most will at least encrypt your password, but some possibly do not. If you use your own wireless network and have configured it so that you need a password to connect to your own router (e.g. using WEP or WPA,) then you are using encryption over your wireless connection - your computer and your wireless router are using their own language to talk.
More on what uses encryption (and how you can tell), and how to secure your own wireless network later.
Imagine you are at a party, and you see two of your best friends. You have some wonderful personal news to tell them, and you get them together to share your news (in the middle of the crowd.) As you talk with your two friends, a nosy Mr. Stranger is curious about what's going on, walks by casually, listens intently, and overhears your conversation. Something similar could also happen when using free public wireless internet.
When you are using a wireless network, you are sending and receiving messages back and forth with the wireless router to which you are connected via radio waves. You're having a conversation with the router (although not a very personal one - the router is more like a middleman. It just relays the messages.) Any computers within distance (i.e. the radio waves can reach them) can also hear your conversation. Usually computers ignore messages that are not addressed to them. However, a malicious Mr. Stranger could use various tools on his computer to read those messages. (This is called packet sniffing, although packet sniffing is not always malicious.)

For example, in the picture above - all the computers could potentially see what messages others are sending to and receiving from the router (if the messages aren't encrypted.) Computer ABC can see the username and password Computer XYZ is using to log into the insecure web site toothbrush.com, as well as the email to Bob that you are sending. If you are just surfing the web, such as checking sports scores or the weather forecast, then you may not care if others can see what you're doing.
This is why it is important to make sure you are using encryption when sending confidential information over a wireless connection. Using encryption is like using your own invented language with your friends so that no one else can understand. People can still hear what you're saying, and who you are saying it to, but they won't understand what you're saying (unless they figure out your invented language.)
Turning on the gmail security setting suggested in the last post makes your computer and the gmail server use their own invented language.
Other web sites that require a password may or may not use encryption. Most will at least encrypt your password, but some possibly do not. If you use your own wireless network and have configured it so that you need a password to connect to your own router (e.g. using WEP or WPA,) then you are using encryption over your wireless connection - your computer and your wireless router are using their own language to talk.
More on what uses encryption (and how you can tell), and how to secure your own wireless network later.
Subscribe to:
Posts (Atom)
