Author Topic: How safe is https connection for facebook?  (Read 5452 times)

0 Members and 1 Guest are viewing this topic.

true indian

  • Guest
How safe is https connection for facebook?
« on: January 24, 2012, 03:00:30 PM »
i was thinking of switching over to https connections for FB...

Is it a good idea?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: How safe is https connection for facebook?
« Reply #1 on: January 24, 2012, 03:08:37 PM »
i was thinking of switching over to https connections for FB...
Is it a good idea?

IMO, the best idea is to ditch FB altogether. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

true indian

  • Guest
Re: How safe is https connection for facebook?
« Reply #2 on: January 24, 2012, 03:10:24 PM »
i was thinking of switching over to https connections for FB...
Is it a good idea?

IMO, the best idea is to ditch FB altogether. ;)

No way! my Sister wont do that...she is real FB addict

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: How safe is https connection for facebook?
« Reply #3 on: January 24, 2012, 03:17:57 PM »
Hi true indian,

You really consider that after the "Firesheep" extension with the HTTPS Connection Flaw drama in Febr. last year? Just think again.
You need the full shield detection of avast on normal http connections allways.
With https you loose that additional protection.
I know our forum friend, DavidR, did advise against this forcing of HTTPS-connections on several occasions and in several of his postings. I have to agree with his opinion.. Not all browsers will tell you when https is in part insecure, and not all browsers then block the insecure javascript.
re: http://techie-buzz.com/browsers/google-chrome-blocks-insecure-scripts.html (link article author =  Keith Dsouza)
I would not like to run the additional risks, but that is just my personal opinion,
I would install the Ghostery plug-in with all the new total blocking options and enable bug blocking there, re: http://www.ghostery.com/  

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

true indian

  • Guest
Re: How safe is https connection for facebook?
« Reply #4 on: January 24, 2012, 03:20:21 PM »
Thanks! plonus i will stick with http  ;D
« Last Edit: January 24, 2012, 03:31:01 PM by true indian »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: How safe is https connection for facebook?
« Reply #5 on: January 24, 2012, 03:48:22 PM »
Even if you switched to https, that doesn't make facebook safer as https has nothing to do with security, but privacy.

The fact that the web shield doesn't scan https (secure encrypted) content would effectively leave you more vulnerable rather than more secure.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: How safe is https connection for facebook?
« Reply #6 on: January 24, 2012, 04:06:57 PM »
Thanks! plonus i will stick with http  ;D

His name isn't plonus..!! ::)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: How safe is https connection for facebook?
« Reply #7 on: January 24, 2012, 04:13:41 PM »
i was thinking of switching over to https connections for FB...

Is it a good idea?

What good is a HTTPS connection if you're posting personal data on your own on a public webspace?
Visit my webpage Angry Sheep Blog


YoKenny

  • Guest
Re: How safe is https connection for facebook?
« Reply #9 on: January 24, 2012, 04:53:54 PM »
i was thinking of switching over to https connections for FB...
Is it a good idea?

IMO, the best idea is to ditch FB altogether. ;)
I need Facebook as I use it to keep up with many friends and my daughter that live far away from me and I like to see the pictures she posts of my grandson.

I do use https to connect to Facebook plus I have other Facebook security settings VERY HIGH.

https://www.facebook.com/security?v=wall

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: How safe is https connection for facebook?
« Reply #10 on: January 24, 2012, 06:31:05 PM »
Hi Hanziness & JoKenny,

The Google Analytics tracking code is now the same for both secure and non-secure websites.
So privacy wise it does not make any difference. Better to use a combination of extensions like NoScript and RequestPolcicy. Here I have to agree with DavidR. Then the rendering of javascript code differs as per browser, a comma transition in the code for GoogleChrome gives an undefined error for instance. There is also browser dependant malware and we want avast on the ball all of the time all the time,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Sartigan

  • Guest
Re: How safe is https connection for facebook?
« Reply #11 on: January 24, 2012, 07:16:40 PM »
Hi polonus.

Oh.. I didn't know that about Google Analytics! Thank you for informing me (anyway, NoScript and ABP blocks it... :D)

Of course I use NoScript in my Firefox (which is up-to-date) to keep my browser and computer secure. I also have FlashBlock, AdBlock Plus (with its Pop-Up extension) and NoRedirect intalled.

I tried out RequestPolicy once, but it blocked everything, and I thought I don't really need it, because I always scan unknown websites with Sucuri, Virustotal and URLVoid. I also use OA.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: How safe is https connection for facebook?
« Reply #12 on: January 24, 2012, 09:21:13 PM »
The problem is you don't know what other web sites the one you are visiting connects to (so you can't physically check them all) as for the most part you only find out about the connections to third party sites (regarding cross site scripting) using something like RequestPolicy or check the page source code, by which time it is too late.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

true indian

  • Guest
Re: How safe is https connection for facebook?
« Reply #13 on: January 25, 2012, 09:59:57 AM »
Thanks! for the input guys!

I will stick with http as polonus adviced ;)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: How safe is https connection for facebook?
« Reply #14 on: January 25, 2012, 05:23:04 PM »
Remember that the website owner also has a responsibilty towards the visitor of his site.
Sensitive information stays secure when everything om the site is encrypted. Changing plugin configurations, updating passwords, these data should always be encrypted and are not so by default. And when on a mixed content site you better should know that SSL/Non-SLL links issues were fixed.
For instance run fiddler under your browser session and grow aware to what goes on over the wire under the hood inside your browser while you are clicking away,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!