Understanding HTTPS (Notice 2018-004)

This is a Fast-Air Tech Talk security notice. The Tech Talk security notice is a free service for all Fast-Air customers. Please suggest security notice topics.

Ensuring online security and privacy is challenging. A common related suggestion is to always use HTTPS.

HTTP is an acronym for Hypertext Transfer Protocol. HTTPS is an acronym for Hypertext Transfer Protocol Secure.

Using HTTP means the connection uses clear text. Using clear text means anybody monitoring the connection can view all content being transmitted. Using HTTPS creates an encrypted connection between two computers. Using an encrypted connection means the contents of the connection are garbled and cannot be monitored directly without decryption.

That’s all HTTPS means — an encrypted connection.

Connecting to a web site using HTTPS does not mean the web site or web site owners are trustworthy.

A common tactic with malware authors who use phishing techniques to trick users into downloading their malware is to use HTTPS. Using HTTPS provides an illusion that a web site is safe.

An illusion.

Using HTTPS only means the connection is encrypted. Using HTTPS implies nothing about the trustworthiness of the email senders or web site owners.

Avoid phishing emails that use HTTPS as a ruse to trick users.

Latest posts by Backwoods Geek (see all)