Ordering or paying online, is it SAFE?

Probably, but you must be AWARE.

If you are paying for something online and it says anything OTHER than "HTTPS://"  It isn't SAFE to enter your credit card information.

Any trustworthy site should have https://.

I recently came across a group of entrepreneurs who were in the process of starting online businesses. One of them asked for volunteers to test their payment page with the reward being their course for an extremely low cost price.

So I thought I would check it out since I love to learn. 

I went to the page, and was looking around and as I was pulling out my card to type in the information I paused because something wasn't right.  I noticed it did not say HTTPS yet was asking for a credit card. (I look for those things AUTOMATICALLY.  I don't even have to think.)    I then looked at the certificate of the page and the certificate for the site did not match. On modern browsers you can view site certificates with a single or two clicks of a mouse depending on the browser.

Why is this important for you?   
Never enter your payment information unless the site says HTTPS and that LOCK icon is CLOSED! (See below)

What is a certificate? 
Certificates mean that the owner of the site, registered the site, and paid to create a SECURE connection so that YOU know you are connecting to THEM and NO ONE ELSE.

Why do I care if the certificate matches?   If the certificate doesn't match the site name, then you could be on a FAKE site trying to steal your information. 

This is from CHROME.  Notice the SECURE and the HTTPS:
HTTPS means it is encrypted using SSL (or the more modern TLS).
SECURE means that the certificate is valid and matches what has been registered with the DNS services across the internet.



This is from EDGE (Think IE but on windows 10).  The square where it says website identification is the certificate information and pops up the same on Chrome if you click on the Lock or the word Secure.

This is how you can check that the site is who they say they are (99.9% confidence).  But this is a MINIMUM STANDARD that must be met.

If you send your data to a site that does not have https it is sent as clear text (meaning not encrypted.

I'm not going to explain encryption in this post, (I need much more coffee for that,) but without it your information is visible to every single device it travels through on the internet.  If you are in Seattle and looking at a Website in New York your information could flow through dozens of different devices each with an opportunity to capture and steal your information.

With the increased use of online everything, the burden of safety and security awareness falls on YOU.   You need to be aware.

Needless to say I pointed out to my fellow entrepreneur that the site was NOT safe and that they should contact their payment processor and hosting provided to have that fixed

I'll keep posting information to help prevent you from being a victim.

New posts, weekdays Mon - Thursday at noon.  (Yes I'm cutting back to 4 days a week, new baby arrival approximately 30 days.)

Thank you for reading.  Feel free to post questions or topic requests for future posts.

Comments

Popular posts from this blog

Virtualization: What is it and do I need it?

Smart Home tips.

Is it possible to have to much security?