TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The lack of HTTPS at Amazon: identifying items purchased via information leakage

128 pointsby Smerityabout 10 years ago

8 comments

yandieabout 10 years ago
Amazon is moving to HTTPS everywhere in this June. The whole website is a complex machinery with multiple components and it takes time to move those components to HTTPS.
评论 #9320806 未加载
throwaway5060about 10 years ago
There are definitely plans to enable https on www.amazon.* and people are working on this right now.
评论 #9320587 未加载
hannobabout 10 years ago
It is actually worse than that. Given an active attacker one can easily steal passwords using SSL stripping attacks. Ebay is also affected. Cookie stealing also works.<p>Pretty much every mixed http&#x2F;https setup (&quot;encrypt only the login&quot;) is broken.
评论 #9320793 未加载
coderdudeabout 10 years ago
I wonder if the lack of HTTPS during normal browsing is a deliberate choice (one motivated by testing) or if it&#x27;s only like that out of legacy (preservation of URLs). It&#x27;s difficult to imagine all of the possible issues they may know about that we don&#x27;t, given their scale.<p>The author mentions that removing the ref parameter would be a solution to one of the problems discussed in the article but I put forward that they could also just encrypt the value for transmission and store the information in plain on the backend. If they won&#x27;t move to HTTPS then that should solve at least one of the issues.
评论 #9320220 未加载
greglindahlabout 10 years ago
In an era where American ISPs charge extra to not spy on your non-encrypted traffic, it seems odd that Amazon doesn&#x27;t care... improving the non-Amazon ads that you receive surely causes Amazon to lose money.
评论 #9320743 未加载
评论 #9320160 未加载
liareyeabout 10 years ago
Mr Bezos, tear down this HTTP
aareetabout 10 years ago
I had a scare regarding this a few days ago. I was searching for a Bose airline adapter on DuckDuckGo and clicked the top result without looking at the URL. [1] I ended up hitting some page on www.casselsonline.com that exactly mirrored Amazon&#x27;s website right down to suggested items and everything. I didn&#x27;t even notice I wasn&#x27;t on amazon.ca until I went to sign in and found the certificate broken.<p>Couldn&#x27;t find a place to report URLs on DDG, so I reported them to Google.<p>[1] These bad results still show in the index - <a href="https:&#x2F;&#x2F;duckduckgo.com&#x2F;?q=bose%20airline%20adapter%20canada+site:www.casselsonline.com" rel="nofollow">https:&#x2F;&#x2F;duckduckgo.com&#x2F;?q=bose%20airline%20adapter%20canada+...</a>
评论 #9321607 未加载
sarciszewskiabout 10 years ago
With an HTTP connection, it becomes easy for an attacker in the middle to prompt the user to re-enter their password and have it re-transmitted in the clear.<p>I&#x27;m surprised more attackers don&#x27;t do this.