Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » RapidSSL and no https: ???
Search Topic:
Uniqs:
248
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Zyxel p660r-elink Security - Adding a router? »
« Norton Antivirus 2008  
AuthorAll Replies

ken5

join:2003-08-20
Princeton Junction, NJ

RapidSSL and no https: ???

Howdy,

I ordered something online from a local store. When I went to the order page I got the message that I was going to a secure connection and there was a rapidSSL logo on the page. I ordered. After doing so I realized it did not have the https address. Does this sound right?

Should I be concerned about using my card as I did? I do know it is a legit business or I would not have ordered.


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T Midwest

It is possible that the data you sent used SSL, even though the page itself did not use SSL. With firefox as browser you can check this by right clicking on the page and selecting "page info". Then look at the forms. The url associated with submitting the form data should be using "https:" if the data is to be sent encrypted.

Or set your browser to ask you before data is sent insecurely. It can get annoying (you have to click a button on lots of sites), but you will have a better idea on whether data is being sent encrypted.
--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14


SnowyOne
Premium
join:2003-04-05
Kailua, HI
reply to ken5
A properly formed rapidssl session should show the "https'
»https://www.rapidssl.com/test/rapidssl.htm
I'd contact the store & ask them what's up with their cert.


NetFixer
Snarl for the camera please
Premium
join:2004-06-24
Murfreesboro, TN
·Vonage
·Cingular Wireless
·AT&T CallVantage
·AT&T Southeast
·Comcast

said by SnowyOne See Profile :

A properly formed rapidssl session should show the "https'
»https://www.rapidssl.com/test/rapidssl.htm
I'd contact the store & ask them what's up with their cert.
Of course you can also to to a "test" page that displays the RapidSSL logo that is not SSL encrypted.

»www.rapidssl.com/test/rapidssl.htm

That is not much of a test page if it does not even detect that it has not been entered properly.

Here is an example of a real SSL test page:

»https://webhost.dcs-net.net/ssltest.html
»webhost.dcs-net.net/ssltest.html

Notice the difference?
--
We can never have enough of nature.
We need to witness our own limits transgressed, and some life pasturing freely where we never wander.
Test your firewall.


SnowyOne
Premium
join:2003-04-05
Kailua, HI
·Clearwire Wireless
·RoadRunner Cable

Click for full size
tm
Click for full size
tm
said by NetFixer See Profile :

That is not much of a test page if it does not even detect that it has not been entered properly.
It's not much of an ssl test page if it randomly serves up an ssl session or an http session when clicking the ssl link.
»https://www.rapidssl.com/test/rapidssl.htm
I checked it before posting it to make sure it did what it was supposed to & it did, but I guess with Rapidssl it a matter of chance where the encryption actually kicks in.
-
Forums » Up and Running » Security » SecurityZyxel p660r-elink Security - Adding a router? »
« Norton Antivirus 2008  


Saturday, 30-Aug 07:19:28 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [333] Comcast 250GB Cap Goes Live October 1
· [223] FBI To Allow Warrantless Investigations
· [159] Industry Reacts To Comcast Cap Plans
· [130] AT&T Thanks Democrats For Telecom Immunity
· [123] Time Warner Cable Cripples TiVO, Gets FCC Fine
· [120] Why Run FTTH When You Can Pretend You Do?
· [73] Friday Open Thread
· [67] Telus CAPS 'Unlimited' EVDO Data Plans
· [65] Game Publishers Follow The RIAA's Lead
· [60] Qwest Defends Not Running FTTH
Most people now reading
· Bandwidth Monitor for Computers-Suggestions? [Comcast HSI]
· [iPhone] Did I Buy A Fake iPhone? [All things Macintosh]
· Comcast has new Acceptable Use Policy besides the 250GB cap [Comcast HSI]
· Unlocking Factory Reset sunrocket linksys 2102-R. [Teleblend]
· NY and NNJ officially reach 102 HD Channels!!! What's next? [Verizon FIOS TV]
· Battlegrounds Auto-queue, Auto-Join Add-ons [World of Warcraft]
· Steele vs Paypal - Hoax or Not - You Make the Call [Spam, Scam and Phishbusters]
· Philly Metro VHO8 Update [Verizon FIOS TV]
· If anyone wants to see pictures [Home Repair & Improvement]