Flow hijacking frequent use https solve

  I believe many people have not met the wrong domain name, the result went to such a situation on a phishing site, user data leakage, hijacking traffic, page tampering frequent security incidents.
  Faced with this situation, using IIS7 web site monitoring, enter the domain name check to see is not a case of hijacking and DNS poisoning found that using this method for real-time inspection is necessary.
  Following Baidu whole station to enable HTTPS encryption, Alibaba's Taobao Mall & Lynx also enable site-wide HTTPS. And Google in the past few years, Google search, Gmail, YouTube, and other products instead of HTTPS encrypted version of HTTP protocol from the protocol, it announced that it would adjust the Google search index system in December 2015, the index will be adjusted after the system HTTPS pages indexed as a priority target. Why HTTPS can do the whole station anti-hijacking, anti-tampering effect, what are the advantages?
  What is HTTPS, to be a simple popularity, please understand the passing ~ ~
  HTTPS (Secure Hypertext Transfer Protocol) Secure Hypertext Transfer Protocol It is a secure communications channel, which is based on HTTP developed for between client computers and servers exchange information. It uses Secure Sockets Layer (SSL) to exchange information, it is simply secure version of HTTP, the use of TLS / SSL encrypted HTTP protocol.
  HTTP protocol to transmit information in plain text, there is information eavesdropping, tampering risk information and information hijacking, and protocol TLS / SSL has authentication, message encryption and integrity checking functionality, you can avoid such problems.
  TLS / SSL stands for Transport Layer Security (Transport Layer Security), security protocol layer is interposed between the TCP and HTTP, does not affect the original TCP protocol and the HTTP protocol, it is not necessary to use HTTPS substantially HTTP pages too many transformation.
  The foregoing discussion of the principles and advantages of HTTPS, but by adding a new protocol to enable more secure communications inevitably comes at a price, performance loss mainly reflected the HTTPS protocol consumes more CPU resources and increase the delay.
  HTTPS delay characteristics of delay is smaller the closer the service node, CDN natural closest to the user, so as to select the use of CDN HTTPS access to the inlet, will be able to greatly reduce the access delay. However, due to the HTTPS protocol requires complex encryption and decryption action, with respect to the HTTP protocol requires large amounts of computing resources, encryption and decryption will consume a longer transmission time, resulting in HTTPS site compared to regular HTTP sites faced in loading, transit greater challenges.

Guess you like

Origin blog.51cto.com/14470319/2427370