Skip to Content
Mac® Security Bible
book

Mac® Security Bible

by Joe Kissell
January 2010
Beginner to intermediate
936 pages
27h 45m
English
Wiley
Content preview from Mac® Security Bible

10.2. Using SSL Encryption

By default, all information that moves between your web browser and a web server (in either direction) is sent over the Internet in its raw, unencrypted form using HTTP (Hypertext Transfer Protocol). Ordinarily, this is no problem because most of the information on the web is, by definition, public, and most of the information sent by your web browser simply contains requests for that information. However, because it's relatively easy for someone to observe Internet traffic as it travels between browser and server, unencrypted HTTP isn't a safe way to transmit sensitive information, such as passwords, bank account numbers, and medical records.

Most sites that let you send or receive any sort of private information use SSL to encrypt the entire session between your browser and the server so that if anyone were to intercept the data, all he or she would see is a seemingly random stream of scrambled characters. SSL-protected sites use the HTTPS protocol (S for secure), and thus their URLs begin with the scheme https:// rather than http://. In addition, when you're connected to a secure website, your browser usually displays the icon of a locked padlock — often in the corner of the window, in the title bar, or (in the case of Safari 4, for example) in the tab corresponding to that page.

NOTE

SSL isn't the only way of securing data sent and received by web pages, but it's the most commonly used. Apple's MobileMe service, for example, uses SSL only for the ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Practical Internet of Things Security - Second Edition

Practical Internet of Things Security - Second Edition

Brian Russell, Drew Van Duren
How to Develop a Great Digital Strategy

How to Develop a Great Digital Strategy

Jeanne W. Ross, Cynthia M. Beath, Ina M. Sebastian
Access Control, Authentication, and Public Key Infrastructure, 2nd Edition

Access Control, Authentication, and Public Key Infrastructure, 2nd Edition

Mike Chapple, Bill Ballad, Tricia Ballad, Erin Banks
Practical Security

Practical Security

Roman Zabicki

Publisher Resources

ISBN: 9780470474198Purchase book