Solved A question re. http and https

FranzB

New member
Local time
4:26 PM
Messages
208
I have a long running feud with my internet provider. They have a site where i can log in to view my personal data (email, bills, etc.) and my user name and password has to be given. This is an http site! However, when you do log in on this http site you are transferred to an https site. ???????????
My point is that the transfer of my user name and password is not secure since it is done via an http connection. They deny and claim everything is secure.
The funny (but not haha) part of it is that they also have an https site where you can log in (found when googling but way down in the listings given by Google).

I am confused. Totally.
They even told me once i had a redirecting virus. Nonsense, of course, because google gives the https as well as the http site for logging in.
Any information to clear up my confusion? Am i nuts or are they?
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Hello FranzB

Don't worry, they are the incompetent ones. You're perfectly right about the dangers of using http over https. Have you seen this addon before? If forces https to be used wherever possible :)

https://www.eff.org/https-everywhere

Tom
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Build #1
OS
Windows 8.1 Pro x64
CPU
Intel i7 3770K @4.5GHz
Motherboard
ASUS P8Z77-V PRO
Memory
Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
Graphics Card(s)
Gigabyte Radeon HD 7850 (2GB GDDR5)
Sound Card
Integrated on motherboard
Monitor(s) Displays
23" LG LCD/LED IPS
Screen Resolution
1920*1080
Hard Drives
Samsung EVO 128GB SSD
Seagate Barracuda 2GB 7200rpm
2x Seagate FreeAgent [500gb]
PSU
Corsair TX650W V2 (80+ Bronze)
Case
NZXT Phantom 410 White
Cooling
Corsair H100 Water Cooler
Keyboard
Microsoft Desktop 2000 Wireless Keyboard
Mouse
Microsoft Desktop 2000 Wireless Mouse
Internet Speed
95 Mb/s Download 70 Mb/s Upload
Antivirus
MSE + MBAM Pro
Browser
Firefox
Hello FranzB

Don't worry, they are the incompetent ones. You're perfectly right about the dangers of using http over https. Have you seen this addon before? If forces https to be used wherever possible :)

https://www.eff.org/https-everywhere

Tom

Thanks, Tom, for the link.
What especially gets me is that you can login to your account on an http webpage but that the page you get then and where you can click on several options (e.g. the bills) is an https. It's simply weird. And then the help desk telling me that i have a redirect virus. It took me hours checking with all kinds of programs. And it's not just any provider (the old Postal Services). After three months and three emails they called me by phone today and asked whether the problem was solved. They don't even check themselves. Idiots.
 

My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Purely out of interest, which ISP do you use?

It might pay you to shop around and consider switching.

I did recently and got a better telephone,TV and broadband bundle AND a £20 ($35) a month saving.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Elite 495UK
OS
Windows 7 Ultimate SP1 64-Bit
CPU
Intel Core i7 870 @ 2.93GHz
Motherboard
MSI 2A9C (CPU1)
Memory
8Gb Dual-Channel DDR3 @ 664MHz
Graphics Card(s)
nVidia GeForce GTX 460 1024MB dedicated RAM
Sound Card
Realtek HD Audio
Monitor(s) Displays
HP2310i
Screen Resolution
1920 x 1080
Hard Drives
1x1954GB Hitachi HDS22020ALA 330 (RAID), 1x1954GB Hitachi External for backup and storage
PSU
460W
Case
HP Elite
Cooling
Air cooled
Keyboard
Logitech K750 solar-powered keyboard
Mouse
Logitech Wireless M180 mouse
Internet Speed
2Mb
Other Info
Pure Avanti Flow Internet Radio with iPod Dock, 64Gb iPod, HP USB Speakers, Sony MDR-V500 Headphones, Sony Vaio F-Series Laptop
@ seavixen32

Well, i don't know whether i should give the name here -- they might take legal action for "false accusations" should they see it. But it is not any GB or US provider. And i am on an old "grandfather" clause whereby they don't check my traffic (in MB). So no bundle to pay for and the speed is ok. They tried, however, to have me change my subscription which i declined, smiling.
 

My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Since I cannot see the page in question. Is the form where you are putting the details of your user account, does the URI in the "action" attribute use HTTPS or HTTP as the scheme. If the "action" attribute has an HTTPS scheme then the values of your username and password are sent over a secure line, even if the page is served as HTTP. As long as the form's "action" attribute is HTTPS.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Since I cannot see the page in question. Is the form where you are putting the details of your user account, does the URI in the "action" attribute use HTTPS or HTTP as the scheme. If the "action" attribute has an HTTPS scheme then the values of your username and password are sent over a secure line, even if the page is served as HTTP. As long as the form's "action" attribute is HTTPS.

Hmmm......... how do i find out? The page on which i fill in my username and password is shown in the address bar as http or www. What happens when i ckick on the "login" button i don't know. How do you find out? Take the sevenforums.com page as an example. Is it a secure login when i have given my username and password? Even when i am logged in (as now when i am writing this posting) it still shows www.sevenforums etc. in the address bar, i.e. no sign of https.
 

My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
And another thing. Even if it is like you suggest, then why have an http as well as an https page where you can login?
Doesn't make sense. Why not simply remove the http page from the net?
 

My Computer

Computer Manufacturer/Model Number
Acer Extensa 5235
OS
Windows 7 Home Premium 32bit, Linux Mint Julia, in dual boot mode
CPU
Intel Celeron 900 @2.2 GHz
Motherboard
Acer BA50-MV(U2E1)
Memory
DDR3 2048 Mbytes
Sound Card
Conexant HD Audio
Back
Top