FlyerTalk Forums - View Single Post - Is https Secure Over Airport, Coffee Shop, Hotels Wifi?
Old Sep 2, 2015, 9:19 pm
  #9  
nerd
FlyerTalk Evangelist
 
Join Date: Jun 2002
Location: n.y.c.
Posts: 13,989
Originally Posted by docbert
However if you instead typed "http://www.bankofamerica.com", and didn't notice that you were actually redirected to https://www.bankofamercia.com, then you've got a problem... Because the original site you went to wasn't over httpS then someone intercepting the traffic can easily redirect you to another site. Even though your access to that site might be over https/SSL, the certificate verification will still succeed (and the lock will show) because at the end of the day you ARE talking to the "real" bankofamercia.com! (You did notice the difference, right?)
But, how would I be fooled by the login page presented by Bankofamercia.com?

After I enter my UserID at BofA.com, it then shows me a graphic I'd previously selected, as well as a phrase below it that I'd hand entered. If that doesn't appear, then I know something is wrong.
nerd is offline