Sinisterly
How to do encryption of my website cods - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Design (https://sinister.li/Forum-Design)
+--- Forum: Web Design (https://sinister.li/Forum-Web-Design)
+--- Thread: How to do encryption of my website cods (/Thread-How-to-do-encryption-of-my-website-cods)

Pages: 1 2 3


RE: How to do encryption of my website cods - Ex094 - 02-16-2014

Does Facebook hide it's HTML Source code? Huge number of site don't do that, Why? Because sometimes when a person see's a cool feature lets say a Floating Box and he wants to know how to do it. Well it's pretty simple that he'll be viewing the HTML and CSS code, hence he's simply Learning!

It again comes down to the matter of perspective that how others perceive a particular thing, I too think that HTML shouldn't be protected and I believe that it helps other learn.

One more reason to believe it's useless is that there are only few methods to encrypt the code and they are totally weak and can be bypassed.

For you here it is http://stackoverflow.com/questions/9679323/how-to-encrypt-html-source-code

Have Fun Smile


RE: How to do encryption of my website cods - Ex094 - 02-16-2014

Does Facebook hide it's HTML Source code? Huge number of site don't do that, Why? Because sometimes when a person see's a cool feature lets say a Floating Box and he wants to know how to do it. Well it's pretty simple that he'll be viewing the HTML and CSS code, hence he's simply Learning!

It again comes down to the matter of perspective that how others perceive a particular thing, I too think that HTML shouldn't be protected and I believe that it helps other learn.

One more reason to believe it's useless is that there are only few methods to encrypt the code and they are totally weak and can be bypassed.

For you here it is http://stackoverflow.com/questions/9679323/how-to-encrypt-html-source-code

Have Fun Smile


RE: How to do encryption of my website cods - E.ALISSA - 02-16-2014

I got these info to share (also thanks for replies above Smile ):

"Here are some tips for using HTTPS:

- Point to all Web forms on the https:// server. Whenever you link to Web forms on your Web site, get in the habit of linking to them with the full server URL including the https:// designation. This will insure that they always are secured.
- Use relative paths to images on secured pages. If you use a full path (http://www...) for your images, and those images are not on the secure server, your customers will get error messages that say things like: "Insecure data found. Continue?" This can be disconcerting, and many people will stop the purchase process when they see that. If you use relative paths, your images will be loaded from the same secure server as the rest of the page.
- Secure only the pages that request and collect data. It is possible to run your entire Web site on https://, but it slows down the connection and some SSL providers charge you on the bandwidth secured. You should only secure those pages that collect data."

source: http://webdesign.about.com/od/ecommerce/a/aa070407.htm

Then=>

"Question: Can I Use a Free SSL Certificate for my HTTPs Pages?

Most Certificate Authorities (CA) charge a lot of money to verify your company to use an SSL certificate. So it can be very tempting to use a self-signed, free certificate for your https server. But is that okay?
Answer:

The short answer is that it is most definitely possible to set up a secure website without buying an SSL certificate from a CA. But there are some problems with doing this:
Web Browser Warning Messages

When a customer comes to your website that is secured with a self-signed or free SSL certificate, most Web browsers will post a scary error message like the one displayed here. While some people will click past this message, install the certificate and go to your site, most will click the "Get me out of here!" button and never come back.
Security Risks

The other, more serious problem is that if you have an self-signed certificate on your server and somehow your site is hacked, that server is now compromised even though it apears secure. Customers who ignored the error message above would then be even more vulnerable because they would believe they were secure.
When to Pay for an SSL Certificate

There are a few situations when paying for an SSL certificate is just the cost of doing business, including:

ecommerce
All ecommerce sites must have a signed SSL certificate if they expect customers to enter their credit card information. You can get around this if you use a company like Paypal to handle your transactions. Then the purchasing process is handled on their secure server.
collecting private information
If your website needs to collect private or sensitive information like addresses or social security numbers then you should collect that information on a secure server with a signed SSL certificate. Otherwise, you are asking your customers to send private and sensitive information over the Internet in clear text, which can easily be hacked and used for identity theft.
sites that are expected to be secure
If you are running a site for a security conscious community such as an Internet security services company, then if you do not have a signed SSL certificate your site will not look secure, and your customers will not believe what you're providing.

When a Self-Signed SSL Certificate is Okay

I don't believe that any site that needs a SSL certificate for customer-facing pages should use a self-signed certificate. I also don't think it's a good idea to use a self-signed certificate on any Web server that is live on the Internet. That is just asking for hackers to set up a man-in-the-middle or other hack on your server to try and trick people into providing information they shouldn't.

The only time a self-signed cerificate should be used is for testing behind a firewall. Such as your desktop computer that is behind a software or hardware firewall on your home network."

Source: http://webdesign.about.com/od/ssl/f/use-free-ssl-certificate.htm


RE: How to do encryption of my website cods - E.ALISSA - 02-16-2014

I got these info to share (also thanks for replies above Smile ):

"Here are some tips for using HTTPS:

- Point to all Web forms on the https:// server. Whenever you link to Web forms on your Web site, get in the habit of linking to them with the full server URL including the https:// designation. This will insure that they always are secured.
- Use relative paths to images on secured pages. If you use a full path (http://www...) for your images, and those images are not on the secure server, your customers will get error messages that say things like: "Insecure data found. Continue?" This can be disconcerting, and many people will stop the purchase process when they see that. If you use relative paths, your images will be loaded from the same secure server as the rest of the page.
- Secure only the pages that request and collect data. It is possible to run your entire Web site on https://, but it slows down the connection and some SSL providers charge you on the bandwidth secured. You should only secure those pages that collect data."

source: http://webdesign.about.com/od/ecommerce/a/aa070407.htm

Then=>

"Question: Can I Use a Free SSL Certificate for my HTTPs Pages?

Most Certificate Authorities (CA) charge a lot of money to verify your company to use an SSL certificate. So it can be very tempting to use a self-signed, free certificate for your https server. But is that okay?
Answer:

The short answer is that it is most definitely possible to set up a secure website without buying an SSL certificate from a CA. But there are some problems with doing this:
Web Browser Warning Messages

When a customer comes to your website that is secured with a self-signed or free SSL certificate, most Web browsers will post a scary error message like the one displayed here. While some people will click past this message, install the certificate and go to your site, most will click the "Get me out of here!" button and never come back.
Security Risks

The other, more serious problem is that if you have an self-signed certificate on your server and somehow your site is hacked, that server is now compromised even though it apears secure. Customers who ignored the error message above would then be even more vulnerable because they would believe they were secure.
When to Pay for an SSL Certificate

There are a few situations when paying for an SSL certificate is just the cost of doing business, including:

ecommerce
All ecommerce sites must have a signed SSL certificate if they expect customers to enter their credit card information. You can get around this if you use a company like Paypal to handle your transactions. Then the purchasing process is handled on their secure server.
collecting private information
If your website needs to collect private or sensitive information like addresses or social security numbers then you should collect that information on a secure server with a signed SSL certificate. Otherwise, you are asking your customers to send private and sensitive information over the Internet in clear text, which can easily be hacked and used for identity theft.
sites that are expected to be secure
If you are running a site for a security conscious community such as an Internet security services company, then if you do not have a signed SSL certificate your site will not look secure, and your customers will not believe what you're providing.

When a Self-Signed SSL Certificate is Okay

I don't believe that any site that needs a SSL certificate for customer-facing pages should use a self-signed certificate. I also don't think it's a good idea to use a self-signed certificate on any Web server that is live on the Internet. That is just asking for hackers to set up a man-in-the-middle or other hack on your server to try and trick people into providing information they shouldn't.

The only time a self-signed cerificate should be used is for testing behind a firewall. Such as your desktop computer that is behind a software or hardware firewall on your home network."

Source: http://webdesign.about.com/od/ssl/f/use-free-ssl-certificate.htm


RE: How to do encryption of my website cods - Ligeti - 02-16-2014

There is nothing to hide in HTML... I mean there is nothing that you can code in HTML that others don't know how to do, CSS can sometimes be tricky, not because the programmer is smart, but because she/he is a mess (just like their code).

JavaScript can be encrypted, but to decrypt it is not a big deal (there are many online tools for that), so... it's not good!

Flash can also be decompressed and decrypted, ... in fact, Adobe proved that they are not trustworthy by the way they handling security in their product (mainly Flash)!

Server scripting side, on the other hand (PHP, JavaServlet, ASP, ... ), they can protect your code in the sense that they isolate and hide the DB connection strings, files handling, input checking,... and much more!

SSL can (in theory) protect end-users, but ... search for Ettercal + SSLStrip, and you will understand that security is only an illusion!

So, how to protect your code... don't code at all! Use smoke signal:
http://www.warpaths2peacepipes.com/native-american-culture/smoke-signals.htm
http://www.ehow.com/how_8237042_read-smoke-signals.html
http://mentalfloss.com/article/52774/how-send-smoke-signals

*joking*

Smile

Peace


RE: How to do encryption of my website cods - Ligeti - 02-16-2014

There is nothing to hide in HTML... I mean there is nothing that you can code in HTML that others don't know how to do, CSS can sometimes be tricky, not because the programmer is smart, but because she/he is a mess (just like their code).

JavaScript can be encrypted, but to decrypt it is not a big deal (there are many online tools for that), so... it's not good!

Flash can also be decompressed and decrypted, ... in fact, Adobe proved that they are not trustworthy by the way they handling security in their product (mainly Flash)!

Server scripting side, on the other hand (PHP, JavaServlet, ASP, ... ), they can protect your code in the sense that they isolate and hide the DB connection strings, files handling, input checking,... and much more!

SSL can (in theory) protect end-users, but ... search for Ettercal + SSLStrip, and you will understand that security is only an illusion!

So, how to protect your code... don't code at all! Use smoke signal:
http://www.warpaths2peacepipes.com/native-american-culture/smoke-signals.htm
http://www.ehow.com/how_8237042_read-smoke-signals.html
http://mentalfloss.com/article/52774/how-send-smoke-signals

*joking*

Smile

Peace


RE: How to do encryption of my website cods - The Real Slim Shady - 02-16-2014

If the browser is capable of displaying it, then any one is capable of reading the code. its that simple.


RE: How to do encryption of my website cods - The Real Slim Shady - 02-16-2014

If the browser is capable of displaying it, then any one is capable of reading the code. its that simple.


RE: How to do encryption of my website cods - E.ALISSA - 02-19-2014

Thank you @Ligeti your reply has very nice info's


RE: How to do encryption of my website cods - E.ALISSA - 02-19-2014

Thank you @Ligeti your reply has very nice info's