ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Facebook offers HTTPS browsing, but not yet by default

By | January 26, 2011, 9:16am PST

Summary: Facebook has finally added a new feature to browse the popular social network on a secure connection. However, it is not yet turned on by default.

Facing a wave of criticism for not offering a secured browsing option, Facebook has finally added a new feature to browse the popular social network on a secure connection (https).

However, the https:// browsing is not turned on by default and must be manually activated from an “Account Settings” page on Facebook.

Here’s the company’s explanation:

If you’ve ever done your shopping or banking online, you may have noticed a small “lock” icon appear in your address bar, or that the address bar has turned green. This indicates that your browser is using a secure connection (”HTTPS”) to communicate with the website and ensure that the information you send remains private. Facebook currently uses HTTPS whenever your password is sent to us, but today we’re expanding its usage in order to help keep your data even more secure.

Starting today we’ll provide you with the ability to experience Facebook entirely over HTTPS. You should consider enabling this option if you frequently use Facebook from public Internet access points found at coffee shops, airports, libraries or schools.

Facebook offers peek at incoming malware attacks

However, instead of being on by default (as it is with GMail, for example), Facebook is urging users to activate secure browsing via the ”Account Security” section of the Account Settings page.

The new feature will effectively kill tools like Firesheep which were created to highlight the weaknesses of Web sites that don’t offer a secure browsing option.   Firesheep, released as a Firefox plug-in, offered a point-and-click interface to fully compromise Facebook browsing sessions.

Facebook says the new feature may slow down surfing on the site because encrypted sessions typically take longer to load.  In addition, some Facebook features, including many third-party applications, are not currently supported in HTTPS, which will cause problems.

The company says it hopes to offer HTTPS as a default setting “sometime in the future.”

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

44
Comments

Join the conversation!

Just In

RE: Facebook offers HTTPS browsing, but not yet by default
aygulum 29th Jul
expover microsoft internet working at sites with the
fesbuk - and sohbet odalari - and mynet - mynet sohbet -
turkey the microsoft is a good format is also face -
sohbetci - metin2 pvp -
operiation facebok - twitter
Behaviour of desdek bigger role in these sites sohbet Microsoft A network connection to the game s dada gubve unwanted surprises
metin2 pvp serverlar - pvp indir -
facesohbet -
yonja - and facebok - sex sohbet - sex hikayeleri -
sohbet -
facebook -
fesbuk -
sohbet -
?et -
I just logged into my FB acct and that option does not show up. Is this something that's currently available to everyone or are they(FB) rolling it out over the next few weeks? What's up?
0 Votes
+ -
Same here
Daniel Breslauer 26th Jan 2011
Here alo, no such option available yet.
@reebus856 None for me either.
0 Votes
+ -
Contributr
@reebus856 Same here. My guess is that it's gradually being rolled out to everyone.

_ryan
@reebus856 No such option for me either. Has it got to do with one's language setting? Mine is set to Dutch
0 Votes
+ -
Firefox Noscript plugin asserts https for ANY site that supports SSL
Dietrich T. Schmitz, ~ Your Linux Advocate 26th Jan 2011
Set Options->Advanced "Force the following sites to use secure (HTTPS) connections: *.facebook.com
0 Votes
+ -
@Dietrich T. Schmitz, Your Linux Advocate

Is it just me or did that disable chat?
0 Votes
+ -
https anywhere does disable chat
pattas@... 26th Jan 2011
@Cylon Centurion 0005
I've been using https anywhere and it does prevent chat from loading. I guess the chat is not SSL enabled.
@Cylon Centurion 0005

Yup, it disables chat sad
Yes, HTTPS has been available for quite a long time. My big beef with Facebook's former/existing HTTPS implementation is that it directs you to a HTTP login screen. Duh. Also, many of the UI links are hard coded to HTTP.

@Cylon Centurion 0005 Yes, no chat via HTTPS. Although, Facebook chat is available via XMPP with your account as username@chat.facebook.com. I use Xabber on my Android devices and Pidgin on my desktops to chat. I find that more convenient anyway. I can stay on FB chat 24/7 without a browser being stranded there.
@Cylon Centurion 0005

excellent! i HATE that freakin' chat. i've wanted a way to turn it off, so this makes me happy.
@Dietrich T. Schmitz, Your Linux Advocate

that only partially works, with that enabled in noscript, you can't actually access the account privacy settings sad

You get (in Firefox)

The page isn't redirecting properly

Firefox has detected that the server is redirecting the request for this address in a way that will never complete.

* This problem can sometimes be caused by disabling or refusing to accept
cookies.
0 Votes
+ -
@Dietrich T. Schmitz, Your Linux Advocate
No such setting on mine.
0 Votes
+ -
Add the "s" yourself
R_Connelie@... 26th Jan 2011
If the Facebook setting is not available for your account yet, you could always switch to secure browsing using the manual method: add the "s" yourself.
(And then bookmark it so next time you start with the secure connection.)

On a related note, I'm pleased as punch that many third-party applications don't work when using an HTTPS connection to Facebook. (Stay away from my data, you leeches!)
@R_Connelie@...

problem is after you login, it automatically switches to http:// only so that's not much of a solution.
0 Votes
+ -
@sibblezdnet

Perhaps I don't log out often enough, because it's never been a problem for me - I'm usually not asked to login, so my https shortcut works as desired. (Does this mean I'm on the site too much...?)

For those few times I do have to login in, it's easy enough to add that "s" and the rest of my facebook session is secure.
Still don't see the option anywhere.
If someone figures out how to use https, please, please explain ? I cannot find the "force web sites" or anything like that. Help !
0 Votes
+ -
force https
janitorman 27th Jan 2011
@pjsvalli@... That was mentioned for people that have FIREFOX installed, and have the NOSCRIPT add-on installed in it. That's the only place those instructions make any sense.
0 Votes
+ -
So what?
james347 26th Jan 2011
Faceplant is a total fool's site, they are about as serious about security as Microsoft was with Windows 95.
I don't seem to have this option available, yet. I did notice that when I go to Account Security, the browser automatically switches me to HTTPS. But, no option available for me to force it.
0 Votes
+ -
No 3rd party apps? Sign me up!
techboy_z 27th Jan 2011
"In addition, some Facebook features, including many third-party applications, are not currently supported in HTTPS, which will cause problems."

Problems? Sounds like a feature to me!!!
If everyone switches to https Facebook's servers will fall on their knees and I won't be able to find out what my neighbor's third cousins's inlaws' dogs are having for breakfast in a timely fashion!
nope, not in mine either, and the help center has nothing for https
0 Votes
+ -
Excellent. Hopefully, all networks follow suit to stamp out malware attacks and false friends.
Niall Mulrine Pc Clean www.pcclean.ie
Wow, how completely and totally useless!

This non-event was worthy of a blog post...

http://worldwizards.blogspot.com/2011/01/new-facebook-with-securodyne.html
CallingID LinkAdvisor 2.0 protects users when they login to Facebook. If the data may be sent to a different site the user is warned and he can easily avoid it.
This tool is free and I know that I won't be exposed to identity theft or account take-over
Chrome has built in mechanisms to (a) tell you if the site you are visiting really is facebook (to prevent phishing) and (b) warn you before you load a page that might have malware.

Im sure the other browsers will follow suit soon.

Thats likely to be MUCH more effective then this nonsense.
This is excellent, but does it also work through the smartphone FB apps? The whole point is to prevent wi-fi phishing (which is uber-easy), but if it only protects PC-based browser access, I'm still leaving my phone's wi-fi disabled when I leave home sad
https when i type it in the address bar. but also cannot see it in my security settings. for fb chat i used to use ichat which works great for that. windows users can use Digsby
What BS the Kids at Schools have been slipping into facebook using Https for quite some time now found out about it from our daughter..
I have two questions: doesn't the 'in-private' browsing option on ie and several other browsers accomplish the same thing as https? And if so then is chat also disabled when using 'in-private'? I'm not a computer geek and don't pretend to know as much as other commentators on this board so my questions are honest, if perhaps naive.
Such addicts to FB! I loved it, and have forced mysef free of the addiction. Soon however I believe that one will NOT be able to communicate via any OTHER option than FB. QUIT IT! Just QUIT the habit. We are all such SHEEP in the hands of this WOLF!
0 Votes
+ -
If anyone finds my boring day to day activities interesting enough to want to break into my FB interactions, then fhn go ahead. I really dont see what they could do that could be of significance to me. I just go on once in a while, read messages and occasionally chat live or by back and forth messages. My SSN, bank account number, credit card numbers, and the likes are not stored there. So what is this all about? Who gives a shti
Using Firefox 3.6.13...It works just fine for me via Account Security and Chat also works.
NO such option for me yet either.
0 Votes
+ -
Firesheep
Madushan Siriwardena 27th Jan 2011
Oh By the way... Great job firesheep -- you made your mark grin
0 Votes
+ -
I think in time, https will be the standard for web sites, it just takes time to get it all going.
Yes, ditto to others' experience that it is not available (yet) for everyone -- my own account page does not offer the choice; and yes, since the published API for chat (that many 3rd-party clients are already plugged into) does not operate securely, this feature may be ignored by the majority of users who are ready to sacrifice security for functionality. However, I am pleased to see Facebook making progress in this regard -- I'll call it a 'win' for today.
Just add the 's' to the http that's at the beginning of FB's website URL and reload the page. Just a second... chat is disabled, so, what sort of improvement in choice is this?
0 Votes
+ -
None of the settings anywhere on mine. Maybe because my account is locked tight?
I have mine enabled, but anytime you open any Facebook apps or any other unsecured part of Facebook, it asks you if you want to leave the secured portion of Facebook. Which is fine, but when you return to the normal Facebook browsing, it doesn't return it to https. You have to manually switch it over again.
expover microsoft internet working at sites with the
fesbuk - and sohbet odalari - and mynet - mynet sohbet -
turkey the microsoft is a good format is also face -
sohbetci - metin2 pvp -
operiation facebok - twitter
Behaviour of desdek bigger role in these sites sohbet Microsoft A network connection to the game s dada gubve unwanted surprises
metin2 pvp serverlar - pvp indir -
facesohbet -
yonja - and facebok - sex sohbet - sex hikayeleri -
sohbet -
facebook -
fesbuk -
sohbet -
?et -

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix