This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Facebook instigates secure-by-default surfing for users

by James Dohnert

20 Nov 2012

View Comments

  • Tweet this
facebook-like

Facebook has started to make HTTPS the default protocol for all its webpages.

Previously, Facebook users had the option to make HTTPS the default protocol for connecting to the social networking site. Last year, Facebook announced its plans to roll out default HTTPS encryption, following the example of companies such as Twitter. 

"This week, we're starting to roll out HTTPS for all [US] users and will be soon rolling out to the rest of the world," said Facebook platform engineer Shireesh Asthana in a blog post.

HTTPS uses Secure Socket Layer (SSL) protection to bring an added sub-layer of security to webpages accessed using HTTP. The added layer of security is said to help prevent things like man-in-the-middle attacks.

Traditionally, HTTPS was used for logging into websites that require a user's credit card information. However, the protocol has slowly started to be adopted for social networking sites.

Twitter made HTTPS a default for all its webpages last February. Google+ also uses the protocol as a standard.

In 2011, Sophos researcher Graham Cluley wrote a letter to Facebook asking the firm to make HTTPS mandatory.

"We welcome you recently introducing an HTTPS option, but you left it turned off by default. Worse, you only commit to provide a secure connection 'whenever possible'," Cluley wrote in the letter from 2011.

"Facebook should enforce a secure connection all the time, by default. Without this protection, your users are at risk of losing personal information to hackers."

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

16%

55%

11%

9%

9%

Popular Threads

Powered by Disqus
Samsung Galaxy S4 V3

Samsung Galaxy S4 video review

A solid Android smartphone let down by less than stellar software

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Account Director

Account Director - London - up to £50k A dynamic innovative...

Reporting & Data Solution Architect

Reporting / Data Architect / MI / Design Assurance...

Solution Architect

Multiple Solution Architects Required. Fraud, Risk...

Mobile Tester, Innovation, Central London

My client is one of the UK's most innovative, full service...

To send to more than one email address, simply separate each address with a comma.