FlyerTalk Forums - View Single Post - Do I need a VPN for added security?
View Single Post
Old Dec 18, 2012 | 6:19 am
  #9  
star_world
Suspended
 
Join Date: Jan 2001
Location: ORD / DUB / LHR
Programs: UA 1K MM; BA Silver; Marriott Plat
Posts: 8,240
Originally Posted by Braindrain
This is true if the entire session is encrypted. As you mentioned, you've got to enable this in gmail or whatever other site. Unless people know about it, only the login is encrypted but people can steal the cookies and login as you.
The use of SSL is much, much more widespread than that. And to look at this from a different angle - if it was as easy to capture cookies and login details like this from mainstream websites they just wouldn't be useable. Look at the vast numbers of people that log in every day from Starbucks, McDonalds, airports around the world, etc. all without encryption on the wireless link. How many of these people regularly use VPNs?

Best practices for the last 5-10 years have involved putting the security into the web application, primarily using SSL for anything even remotely sensitive, precisely because you can't depend on the security of the network link.

From a personal perspective, I have no hesitation about logging into my online banking, credit card accounts, webmail, etc. and using business applications such as Outlook and Salesforce from any public WiFi hotspot. The only thing I use a VPN for is to get around geographical restrictions for certain sites, as mentioned above.
star_world is offline