Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 7th, 2011, 15:54 GMT · By

Facebook Clears Persistent HTTPS Setting Without Warning

SHARE:

Adjust text size:


Facebook clears persistent HTTPS setting when apps are allowed
Enlarge picture
Despite recently starting to allow users to opt for HTTPS on all sessions, Facebook clears the setting with no warning when people try to access most apps.

Two weeks ago, the social networking site proudly announced a new "secure browsing" option located under the Account Security menu which would allow people to enable HTTPS for all future visits.

However, at the moment, third-party apps don't not work via HTTPS, because they load external content into the page.

This content cannot be signed by Facebook, therefore, the secure connection is broken each time an HTTPS client opens such an app.

Facebook prevents this from happening automatically via a dialog that reads "Sorry! We can't display this content while you're viewing Facebook over a secure connection (https). To use this app, you'll need to switch to a regular connection (http)."

Pressing the continue button, however, doesn't just remove HTTPS for that session, but clears the checkbox from the persistent "secure browsing" setting without any indication of doing so.

A dialog allowing users to break HTTPS temporarily or at least one that would clearly indicate that the permanent option is also modified, would be much more appropriate.

Users could determine the risks at a particular moment and take a decision to drop HTTPS temporarily based on that.

For example, a person who's frequently on the go, might feel ok with not using HTTPS when he's connected from home, but would probably expect their connection to revert back to a secure one when connecting through wireless hotspots.

Under current conditions, giving that the vast majority of apps load external content, the persistent secure browsing option seems almost futile if it's going to be removed every time.

TELL US WHAT YOU THINK:

3,051 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Facebook Makes First Step Towards Default Full-Session HTTPS

EFF Asks US Internet Giants to Help Tunisian Activists

Microsoft to Implement Full-Session HTTPS in Hotmail

READER COMMENTS:


Comment #1 by: Redcat on 09 Feb 2011, 20:21 UTC reply to this comment

Very sneaky and why are the general public not informed? If are by friend looking out for their best interset of their email collegues then the cooporation sends a threatening emails?
UM........?
Beach of personal information of the general public and violation of privacy too..unconstutional!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM