Facebook offers HTTPS encryption

 

Sacrifices some of its apps.

Facebook has taken heed of calls to bolster its security, announcing an "opt-in" session encryption feature that temporarily threatens the functionality of many of its apps customers.

"If you've ever done your shopping or banking online, you may have noticed a small "lock" icon appear in your address bar, or that the address bar has turned green," explained Facebook security engineer, Alex Rice, on Wednesday.

"This indicates that your browser is using a secure connection ("HTTPS") to communicate with the website and ensure that the information you send remains private."

Facebook's new security feature comes at a price for both customers and users, according to Rice, which may explain why Facebook had not deployed the feature earlier.

"Some Facebook features, including many third-party applications, are not currently supported in HTTPS. We'll be working hard to resolve these remaining issues," said Rice.

Another cost to users was that encrypted pages may take longer to load. "You may notice that Facebook is slower using HTTPS," Rice warned.

Facebook's opt-in strategy appears to have been aimed at harm-minimisation for its apps customers, with the feature requiring activation via Facebook's Account Settings page.

The new security feature follows concerns raised over Facebook's lack of HTTPS after session hijacking tool Firesheep was released last year. The tool exploited security gaps available when users accessed Facebook from public WiFi hotspots.

Rice recommended users consider enabling the option if they regularly accessed Facebook from, for example, at libraries or coffee shops.

The new feature would be available in the coming weeks while a default encrypted session may be on the cards, according to Rice.

"We hope to offer HTTPS as a default whenever you are using Facebook sometime in the future," he said.

Copyright © iTnews.com.au . All rights reserved.


Facebook offers HTTPS encryption
"Great move! Others should do it too!"
By Shay
 
 
 
Comments: 3
Corsair
Jan 28, 2011 9:41 AM
Well this is long overdue.

Granted you have always been able to log in to Facebook with https (all you had to do was add an "s" to the http of the home/login page) but this always the whole site to be browsed with https which is great.
emelyzu
Jan 28, 2011 5:30 PM
yeah this is fantastic news because he related for security i used this and actually this is depend for his work.but i don't know so thanks for this info.
http://www.wellnessstarts.com/bellaplex-wrinkle-reduction-prevention-review.html

Shay
Jan 28, 2011 8:54 PM
Great move! Others should do it too!
Comments have been disabled for this article.
 
 
 
Top Stories
Australia turns to homegrown drones
Debating the finer points of unmanned aerial vehicle design.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  20%
 
No
  80%
TOTAL VOTES: 522

Vote