<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; ssl https</title>
	<atom:link href="http://www.ghacks.net/tag/ssl-https/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 20:14:29 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Force SSL HTTPS Connections In NoScript</title>
		<link>http://www.ghacks.net/2009/03/31/force-ssl-https-connections-in-noscript/</link>
		<comments>http://www.ghacks.net/2009/03/31/force-ssl-https-connections-in-noscript/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 08:07:56 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox security]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[https connections]]></category>
		<category><![CDATA[noscript]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[ssl https]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/31/force-ssl-https-connections-in-noscript/</guid>
		<description><![CDATA[SSL connections which you can identify by the HTTPS protocol in the address bar of the web browser provide additional security in comparison to the HTTP protocol. This is why many companies use SSL on security sensitive pages of their website which usually involve financial transactions or personal information. To put it bluntly: A bank [...]]]></description>
			<content:encoded><![CDATA[<p>SSL connections which you can identify by the HTTPS protocol in the address bar of the web browser provide additional security in comparison to the HTTP protocol. This is why many companies use SSL on security sensitive pages of their website which usually involve financial transactions or personal information. To put it bluntly: A bank not using SSL on their website cannot be trusted. HTTPS connections are encrypted which means the traffic is being protected from local network sniffers. There are however still attack points like keyloggers or viruses on the user&#8217;s system.</p>
<p>There is one additional problem concerning websites that do offer HTTPS connections on most of their network but not everywhere. <a href="http://www.donationcoder.com/Forums/bb/index.php?topic=17702.new#new">Mouser</a> over at Donation Coder mentioned a hidden setting in the NoScript (check my<a href="http://www.ghacks.net/2008/05/28/my-firefox-security-profile/"> Firefox security profile</a> for additional information) add-on of the <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> web browser allowing to force HTTPS connections for listed websites. This is helpful in a few cases. Some websites offer both HTTP and HTTPS connections to their servers. Another possibility are websites that make use of HTTPS connections but not on all pages.</p>
<p>Users with the excellent No Script add-on installed can configure sites to always use a secure https connection when they are visited. This option can be accessed by right-clicking the NoScript icon in the Firefox status bar, selecting Options from the context menu, clicking on the Advanced tab in the configuration and there on the HTTPS tab.</p>
<p><span id="more-11559"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/03/https-500x396.jpg" alt="https" title="https" width="500" height="396" class="alignnone size-medium wp-image-11561" /></p>
<p>New websites or pages that should be forced to use secure HTTPS connections can be added to NoScript in there. The use of wildcards is possible. Users should however note that this will not work on all websites. It will obviously not work on websites that do not offer HTTPS. There are also sites that automatically redirect HTTPS requests to HTTP. Google.com is a prime example of this. If you add google.com to the list you will notice a never ending loop when opening that website because of NoScript trying to force HTTPS and Google redirecting to HTTP.</p>

	Tags: <a href="http://www.ghacks.net/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://www.ghacks.net/tag/firefox-security/" title="firefox security" rel="tag">firefox security</a>, <a href="http://www.ghacks.net/tag/https/" title="https" rel="tag">https</a>, <a href="http://www.ghacks.net/tag/https-connections/" title="https connections" rel="tag">https connections</a>, <a href="http://www.ghacks.net/tag/noscript/" title="noscript" rel="tag">noscript</a>, <a href="http://www.ghacks.net/tag/ssl/" title="ssl" rel="tag">ssl</a>, <a href="http://www.ghacks.net/tag/ssl-https/" title="ssl https" rel="tag">ssl https</a>, <a href="http://www.ghacks.net/tag/web-browser/" title="web browser" rel="tag">web browser</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/15/x-ways-to-manipulate-websites-in-firefox/" title="x Ways To Manipulate Websites In Firefox (June 15, 2009)">x Ways To Manipulate Websites In Firefox</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/03/04/web-browser-firefox-307/" title="Web Browser: Firefox 3.0.7 (March 4, 2009)">Web Browser: Firefox 3.0.7</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/mozilla-firefox-3-0-11-released/" title="Mozilla Firefox 3.0.11 Released (June 11, 2009)">Mozilla Firefox 3.0.11 Released</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/" title="Latest Firefox Web Browser Vulnerable to 0-Day Exploit (March 26, 2009)">Latest Firefox Web Browser Vulnerable to 0-Day Exploit</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/04/27/increase-internet-security-with-safe-ssl/" title="Increase Internet Security With Safe SSL (April 27, 2009)">Increase Internet Security With Safe SSL</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/31/force-ssl-https-connections-in-noscript/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
