{"id":62,"date":"2016-01-29T18:06:11","date_gmt":"2016-01-29T18:06:11","guid":{"rendered":"http:\/\/unsafehex.com\/?p=62"},"modified":"2016-03-15T11:37:39","modified_gmt":"2016-03-15T11:37:39","slug":"do-you-know-what-you-just-logged-in-to","status":"publish","type":"post","link":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/","title":{"rendered":"Do you know what you just logged in to?"},"content":{"rendered":"<p>What&#8217;s that padlock icon in your address bar all about? There are lots of places where you can get an explanation of what the symbol means, but in a lot of cases they&#8217;re pitched at tech nerds like myself, not the rest of the world &#8211; would a junior actuary or a retired interior decorator have a chance of understanding those? Not likely! And then there are some which swing the other way and reduce it to &#8220;Padlock = you&#8217;re safe&#8221;. What about the middle? The people who&#8217;d like to understand it a bit better but without having to learn half a networking degree? Now, I wouldn&#8217;t be able to plaster a wall for love nor money, but I can explain how that symbol is relevant to <strong>you <\/strong>in a way that you might understand.<\/p>\n<p>You might have learned enough about the internet to know you need to look for a green padlock in your address bar when you&#8217;re doing something involving your password or credit card details but for a lot of people, that&#8217;s where it stops. Unless you understand <strong>why<\/strong> you&#8217;re looking for it, though, you could still be risking your email, the money in your bank account, and anything else that depends on information being sent securely over the internet. If you read the rest of this article hopefully by the end you&#8217;ll know why you&#8217;re doing it, and how to make sure you&#8217;re doing it right.<\/p>\n<p>A few days ago several people <a href=\"https:\/\/twitter.com\/Scott_Helme\/status\/691558852643389440\" target=\"_blank\">pointed out on twitter<\/a> that Waitrose&#8217;s shopping login form was delivered on a normal page instead of an encrypted one. This is what the presence or absence of the green padlock is telling you &#8211; green padlock = page was encrypted when it was sent to you, no green padlock = it wasn&#8217;t. What&#8217;s the big deal? You&#8217;ve only browsed to the site, not put in your password, so it should be fine, right? Obviously not, or I wouldn&#8217;t be writing this post.<\/p>\n<p>(If you <strong>are <\/strong>a tech nerd like myself and you <strong>do <\/strong>want technical mumbo-jumbo, there is an excellent writeup of the issue <a href=\"http:\/\/www.troyhunt.com\/2016\/01\/thank-you-waitrose-now-fix-your.html\" target=\"_blank\">on the blog of the security pro<\/a> to whom the issue was originally highlighted)<\/p>\n<p>When you request a web page, your computer first finds the server on the internet that holds the web page. If the page is encrypted your computer first arranges a secret key with the server that only those two computers will know (how they do this without revealing the key is a huge topic of its own &#8211; if you&#8217;re curious, look up &#8220;Public Key Cryptography&#8221;). The server then sends the web page, encrypted with the key if using that, or in plain text if not.\u00a0 The same thing happens when your computer needs to deliver information to the web server &#8211; such as which product it was that you clicked &#8220;add to basket&#8221; on, or your password, or your credit card details when you go to pay.<\/p>\n<p>So how does this affect Waitrose? When your web browser sends information to a web server, there has to be something in the code of the page to tell it where and how to send whatever it is you plan on sending. If you go to their site, the page you get back will have a login form on it and the code that creates that form has a section that determines where your browser sends the information you enter into the form. The code that does so is defined with the &#8220;action&#8221; parameter inside a &lt;form&gt; tag:<\/p>\n<pre><code>&lt;form action=\"destination page goes here\"&gt;<\/code><\/pre>\n<p>Or, as it appeared on Waitrose&#8217;s site:<\/p>\n<p><a href=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action.png\" rel=\"attachment wp-att-79\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-79\" src=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action.png\" alt=\"1 Form action\" width=\"828\" height=\"71\" srcset=\"https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action.png 828w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action-300x26.png 300w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action-768x66.png 768w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action-624x54.png 624w\" sizes=\"(max-width: 828px) 100vw, 828px\" \/><\/a><\/p>\n<p>You can see in this example from Waitrose&#8217;s site that it is sending its information to an encrypted page (the address starts &#8220;https:\/\/&#8221;). Happy days! Or is it? Remember that the page you\u00a0<strong>received<\/strong> from Waitrose wasn&#8217;t encrypted (no &#8220;https:\/\/&#8221; in the address bar and no green padlock):<\/p>\n<p><a href=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page.png\" rel=\"attachment wp-att-80\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-80\" src=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page.png\" alt=\"2 Waitrose page\" width=\"1187\" height=\"268\" srcset=\"https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page.png 1187w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page-300x68.png 300w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page-768x173.png 768w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page-1024x231.png 1024w, https:\/\/www.unsafehex.com\/wp-content\/uploads\/2016\/01\/2-Waitrose-page-624x141.png 624w\" sizes=\"(max-width: 1187px) 100vw, 1187px\" \/><\/a><\/p>\n<p>Now, we know that <strong>this <\/strong>time, the destination is going to be Waitrose&#8217;s secure server, because we just checked &#8211; but do you know that will be the case every time? You&#8217;d hope so, but really that&#8217;s based on an assumption: that every time you request the page, what you get is exactly what Waitrose sent you. Now comes the bad news. Devices like routers and other network equipment are generally meant to pass on an exact duplicate of what they receive until it reaches its final destination. But there&#8217;s nothing to stop them from changing the data as it goes through. If the page is sent in plain text and goes through a number of devices between Waitrose&#8217;s server and you (their ISP &gt; some internet motorway or &#8216;backbone&#8217; as it&#8217;s known &gt; your ISP &gt; your router &gt; your computer), any one of those has the opportunity to replace the part that says that says &#8220;https:\/\/www.waitrose.com\/shop\/AjaxLogon&#8221; with, for example, &#8220;http:\/\/www.unsafehex.com\/stealer\/send-me-your-credit-card-details&#8221;.<\/p>\n<p>Think of it like getting your credit card statement with a prepaid envelope: how do you know the address on the envelope is the legitimate one? Unless you looked at the source code every time, you would never know for sure that that destination in the &#8220;action&#8221; field was Waitrose&#8217;s own site &#8211; unless your connection to Waitrose when you loaded their page was encrypted. Getting the page with the login form on encrypted instead of plain is like getting your card statement with the return envelope in larger envelope with the seal intact, instead of just held together with a rubber band (though HTTPS encryption is much more secure than the seal on an envelope). You know that the form will be sending your data to the right place because only the server and your computer know how to decode the data correctly.<\/p>\n<p>The obvious question then becomes, can there really be evil devices between me and a website? There certainly can. This is another subject that could be an entire post (or three) of its own, but one example is that a lot of people out there get a bargain basement router supplied by their ISP, which their ISP sourced from the lowest bidder. It&#8217;s probably <a href=\"http:\/\/www.darkreading.com\/attacks-breaches\/router-based-botnet-on-the-loose\/d\/d-id\/1130625\" target=\"_blank\">full of security holes<\/a>, <a href=\"http:\/\/news.softpedia.com\/news\/threat-group-uses-dating-sites-to-build-a-botnet-of-vulnerable-home-routers-499209.shtml\" target=\"_blank\">easily compromised<\/a> and <a href=\"http:\/\/thehackernews.com\/2015\/05\/ddos-botnet-router-hacking.html\" target=\"_blank\">turned in to a slave<\/a> at the bidding of someone who <a href=\"http:\/\/www.techworld.com\/news\/security\/mystery-botnet-hijacks-broadband-routers-offer-ddos-for-hire-3611408\/\" target=\"_blank\">intends to make money out of it<\/a>. There are plenty of other circumstances &#8211; the router in your local coffee shop or the hotel you stayed at could have been hacked. Someone could have created a fake WiFi hotspot just so they can do things like this&#8230; the list goes on.<\/p>\n<p>At this point I&#8217;m going to hope that I&#8217;ve convinced you that you need to pay more attention to this padlock thing, so let&#8217;s get to the most important part of all: <strong>how <\/strong>do you make sure you&#8217;re secure? Fortunately this part is relatively easy: every time you are about to type in some information that&#8217;s secret, look at the address bar first. If you don&#8217;t see\u00a0 <a href=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/3-https-padlock.png\" rel=\"attachment wp-att-86\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-86\" src=\"https:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/3-https-padlock.png\" alt=\"3 https padlock\" width=\"64\" height=\"22\" \/><\/a>\u00a0 at the beginning (or if you use Microsoft&#8217;s IE or Edge, yours is at the end of the bar), don&#8217;t continue.<\/p>\n<p>Feedback is welcome, especially if there&#8217;s something I haven&#8217;t explained clearly enough, or is technically inaccurate!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What&#8217;s that padlock icon in your address bar all about? There are lots of places where you can get an explanation of what the symbol means, but in a lot of cases they&#8217;re pitched at tech nerds like myself, not the rest of the world &#8211; would a junior actuary or a retired interior decorator [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[20,19,22,23,21,24],"class_list":["post-62","post","type-post","status-publish","format-standard","hentry","category-encryption","tag-confidentiality","tag-encryption","tag-forms","tag-https","tag-login","tag-nontechnical"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Do you know what you just logged in to? &#8211; unsafehex<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Do you know what you just logged in to? &#8211; unsafehex\" \/>\n<meta property=\"og:description\" content=\"What&#8217;s that padlock icon in your address bar all about? There are lots of places where you can get an explanation of what the symbol means, but in a lot of cases they&#8217;re pitched at tech nerds like myself, not the rest of the world &#8211; would a junior actuary or a retired interior decorator [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/\" \/>\n<meta property=\"og:site_name\" content=\"unsafehex\" \/>\n<meta property=\"article:published_time\" content=\"2016-01-29T18:06:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-03-15T11:37:39+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action.png\" \/>\n<meta name=\"author\" content=\"http_error_418\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@http_error_418\" \/>\n<meta name=\"twitter:site\" content=\"@http_error_418\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"http_error_418\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/\",\"url\":\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/\",\"name\":\"Do you know what you just logged in to? &#8211; unsafehex\",\"isPartOf\":{\"@id\":\"https:\/\/www.unsafehex.com\/#website\"},\"datePublished\":\"2016-01-29T18:06:11+00:00\",\"dateModified\":\"2016-03-15T11:37:39+00:00\",\"author\":{\"@id\":\"https:\/\/www.unsafehex.com\/#\/schema\/person\/69a7fc817171b5a3c4770875a1918652\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.unsafehex.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Do you know what you just logged in to?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.unsafehex.com\/#website\",\"url\":\"https:\/\/www.unsafehex.com\/\",\"name\":\"unsafehex\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.unsafehex.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.unsafehex.com\/#\/schema\/person\/69a7fc817171b5a3c4770875a1918652\",\"name\":\"http_error_418\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.unsafehex.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/fe9a4cdd9d9f058529884ce588767baf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/fe9a4cdd9d9f058529884ce588767baf?s=96&d=mm&r=g\",\"caption\":\"http_error_418\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Do you know what you just logged in to? &#8211; unsafehex","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/","og_locale":"en_GB","og_type":"article","og_title":"Do you know what you just logged in to? &#8211; unsafehex","og_description":"What&#8217;s that padlock icon in your address bar all about? There are lots of places where you can get an explanation of what the symbol means, but in a lot of cases they&#8217;re pitched at tech nerds like myself, not the rest of the world &#8211; would a junior actuary or a retired interior decorator [&hellip;]","og_url":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/","og_site_name":"unsafehex","article_published_time":"2016-01-29T18:06:11+00:00","article_modified_time":"2016-03-15T11:37:39+00:00","og_image":[{"url":"http:\/\/unsafehex.com\/wp-content\/uploads\/2016\/01\/1-Form-action.png"}],"author":"http_error_418","twitter_card":"summary_large_image","twitter_creator":"@http_error_418","twitter_site":"@http_error_418","twitter_misc":{"Written by":"http_error_418","Estimated reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/","url":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/","name":"Do you know what you just logged in to? &#8211; unsafehex","isPartOf":{"@id":"https:\/\/www.unsafehex.com\/#website"},"datePublished":"2016-01-29T18:06:11+00:00","dateModified":"2016-03-15T11:37:39+00:00","author":{"@id":"https:\/\/www.unsafehex.com\/#\/schema\/person\/69a7fc817171b5a3c4770875a1918652"},"breadcrumb":{"@id":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.unsafehex.com\/index.php\/2016\/01\/29\/do-you-know-what-you-just-logged-in-to\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.unsafehex.com\/"},{"@type":"ListItem","position":2,"name":"Do you know what you just logged in to?"}]},{"@type":"WebSite","@id":"https:\/\/www.unsafehex.com\/#website","url":"https:\/\/www.unsafehex.com\/","name":"unsafehex","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.unsafehex.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.unsafehex.com\/#\/schema\/person\/69a7fc817171b5a3c4770875a1918652","name":"http_error_418","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.unsafehex.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/fe9a4cdd9d9f058529884ce588767baf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/fe9a4cdd9d9f058529884ce588767baf?s=96&d=mm&r=g","caption":"http_error_418"}}]}},"_links":{"self":[{"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/posts\/62"}],"collection":[{"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/comments?post=62"}],"version-history":[{"count":15,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/posts\/62\/revisions"}],"predecessor-version":[{"id":128,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/posts\/62\/revisions\/128"}],"wp:attachment":[{"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/media?parent=62"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/categories?post=62"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.unsafehex.com\/index.php\/wp-json\/wp\/v2\/tags?post=62"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}