While using the internet, there’s a chance that you’ve noticed some websites using HTTP connections while others use HTTPS ones. The major difference between these is that HTTPS connections are considered “secure” while HTTP ones are not. This begs the question, how safe really are HTTPS connections?
When making an online purchase, any reputable website will require a secure HTTPS connection before requesting payment information and completing the transaction. HTTPS is the ubiquitous method used by browsers and websites to securely exchange sensitive data. Its underlying encryption has historically been provided by SSL, which is a familiar term to many Internet users. SSL uses digital certificates and strong encryption to create a secure tunnel between a web browser and web server. For online purchases, it allows you to safely enter your account details, provide your credit card payment information and complete the transaction.
Unfortunately, weaknesses have been discovered in SSL encryption, making HTTPS connections not as safe as you’d expect. Hackers have used these exploits to break through its security projection. So that sensitive data you exchanged over an HTTPS connection may not be as protected as you think. Fortunately, HTTPS can use additional encryptions algorithms that don’t have the weaknesses uncovered in SSL. Specifically, the TLS or Transport Layer Security algorithm can be used, and it’s already supported by a wide range of web browsers and websites.
But which web sites support TLS, and better yet, which ones have disabled SSL altogether so that only more secure TLS algorithms can be used? Unfortunately, without running complicated third-party cryptography tools, it’s almost impossible to tell.
In many ways, you place your trust in those vendors that you do business with. DataMotion specializes in data security and compliance with privacy regulations. Being a trusted supplier to thousands of organizations over the past 16 years, we do not take that trust lightly. As part of our continuous security operations, we stay informed of emerging threats like the SSL vulnerability and apply immediate corrective action. While the security changes occurs behind the scenes, invisible to our users, the relationships we form with our customers are visible in everything that we do.
Frequently Asked Questions
What is the difference between HTTP and HTTPS?
HTTPS connections are considered secure while HTTP ones are not. HTTPS is the standard method browsers and websites use to exchange sensitive data, historically relying on SSL to create an encrypted tunnel between a web browser and web server for safe transactions.
Are HTTPS connections really safe?
Not as safe as you might think. Weaknesses were discovered in SSL encryption, and hackers have exploited them to break through its protection. This means sensitive data exchanged over an HTTPS connection may not be as protected as users expect.
How can HTTPS be made more secure than SSL?
HTTPS can use additional encryption algorithms that lack SSL’s discovered weaknesses. Specifically, the TLS (Transport Layer Security) algorithm can be used and is already supported by a wide range of web browsers and websites, offering stronger protection than SSL.
How can I tell if a website uses secure TLS instead of SSL?
Unfortunately, without running complicated third-party cryptography tools, it is almost impossible to tell which sites support TLS or have disabled SSL altogether. In many ways you place trust in the vendors you do business with to stay current on emerging threats.