Thread: http vs https
View Single Post
  #3 (permalink)  
Old 01-10-2009, 01:37 PM
onefastmustang's Avatar
onefastmustang onefastmustang is offline
CC Member
Visit my Photo Gallery

 
Join Date: Jun 2005
Location: Fairfield, ca
Cobra Make, Engine: CRII with a Stroked Windsor
Posts: 976
Not Ranked     
Default

Quote:
Originally Posted by Don View Post
Article explains the difference between http and https protocols:

Anyone with the technical expertise desire to comment ?

http://www.snopes.com/computer/internet/https.asp
The article doesn't however take into account that once that data passes through the SSL portion of the communication it can be converted back into non-ssl traffic. A company that i had dealings with once did this. They transferred the clients data into their private network via SSL (HTTPS) but once it passed into there it was transmitted in open format the rest of the way around their private network from server to server. Bear in mind that their network had multiple layers of firewalls but if they had gotten hacked or had an employee that started to become a problem lots of data could be collected. My philosophy since I design secure networks for ecommerce and privacy is that if it goes over the wire, encrypt it, period.
Reply With Quote