Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

eCommerce Tycoon


You are currently viewing our eCommerce Tycoon as a guest. Please register to participate.
Login



Reply
Login page - under SSL before submitting or not?
Old 07-17-2008, 12:38 PM Login page - under SSL before submitting or not?
mg1313's Avatar
Skilled Talker

Posts: 94
Location: Phoenix, AZ
Trades: 0
In short should be the login page (where you enter your user and password) under SSL before submitting the page or it's ok that the login page to be on regular HTTP but when you submit to go to HTTPS (SSL)?

Which way assures you a encrypted communication?

Like Apple has it here: http://store.apple.com/1-800-MY-APPL...2.0.26.9.5.7.1

Or Hotmail has it here: http://login.live.com/login.srf?wa=w....aspx&id=64855

Or like Target has it here: http://www.target.com/gp/flex/sign-i...604016-7503003
__________________

Please login or register to view this content. Registration is FREE
(get paid to post reviews)

Please login or register to view this content. Registration is FREE
mg1313 is offline
Reply With Quote
View Public Profile Visit mg1313's homepage!
 
 
Register now for full access!
Old 07-17-2008, 02:37 PM Re: Login page - under SSL before submitting or not?
willcode4beer's Avatar
Super Moderator

Posts: 1,533
Name: Paul Davis
Location: San Francisco
Trades: 1
in short, it doesn't matter if the login page is encrypted or not, as long as it is submitting to an encrypted URL (via POST.
__________________

Please login or register to view this content. Registration is FREE

willcode4beer is offline
Reply With Quote
View Public Profile
 
Old 07-17-2008, 09:53 PM Re: Login page - under SSL before submitting or not?
mg1313's Avatar
Skilled Talker

Posts: 94
Location: Phoenix, AZ
Trades: 0
Well, I found this info.

These articles are saying the opposite...that the Login page and the action page should be both under SSL (mostly because of the phishing problem):

- http://blogs.msdn.com/ie/archive/2005/04/20/410240.aspx
- http://my.opera.com/yngve/blog/show.dml/281609
- http://blogs.zdnet.com/Ou/?p=226
- http://blogs.zdnet.com/Ou/?p=201

If we think a bit they are right: how do I know that the login page is the one I want to be and it wasn't phished? But if it's under SSL then I will know to whom that page belongs.
__________________

Please login or register to view this content. Registration is FREE
(get paid to post reviews)

Please login or register to view this content. Registration is FREE
mg1313 is offline
Reply With Quote
View Public Profile Visit mg1313's homepage!
 
Old 07-21-2008, 10:37 AM Re: Login page - under SSL before submitting or not?
Novice Talker

Posts: 9
Trades: 0
willcode4beer is right that it will always be encrypted as long as you POST to https but the first article you posted clearly demonstrates why you should really have the login page encrypted as well.
__________________

Please login or register to view this content. Registration is FREE
gadiandi is offline
Reply With Quote
View Public Profile
 
Old 07-21-2008, 09:24 PM Re: Login page - under SSL before submitting or not?
willcode4beer's Avatar
Super Moderator

Posts: 1,533
Name: Paul Davis
Location: San Francisco
Trades: 1
the issue mentioned in the first article could affect "secure" pages too.
If a third party can get javascript running in the page, it doesn't matter if it's https or not.

The only useful info in that page is the reference to the UI element not being present on non-secure pages. Most people never bother checking for it anyway, as mentioned in the article, many banks have non-secure login pages.
__________________

Please login or register to view this content. Registration is FREE

willcode4beer is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Login page - under SSL before submitting or not?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.70969 seconds with 12 queries