Jump to content

Hello security experts,

 

As the title says, I´m wanting to buy from www.dhgate.com but I have one major concern and it is that I´m not sure if the https is secure. This is the checkout certificate:

 

Untitled.png
 
It says that the connection is private but someone on the network might be able to change the look... so I´m guessing that it is a risk to buy from this site? From what I´ve researched, I´ve not found anyone complaining about credit theft or security issues or related news. The worst I´ve seen is ppl not happy with their order but that is to be expected. 
Link to comment
https://linustechtips.com/topic/478144-internet-security-buying-from-dhgatecom/
Share on other sites

Link to post
Share on other sites

 

Hello security experts,

 

As the title says, I´m wanting to buy from www.dhgate.com but I have one major concern and it is that I´m not sure if the https is secure. This is the checkout certificate:

 

Untitled.png
 
It says that the connection is private but someone on the network might be able to change the look... so I´m guessing that it is a risk to buy from this site? From what I´ve researched, I´ve not found anyone complaining about credit theft or security issues or related news. The worst I´ve seen is ppl not happy with their order but that is to be expected. 

 

Did you read the message?

They use an obsolete encryption so it may not be secure.  

Link to post
Share on other sites

It look like chinese hosted website.. no point of encryption... all traffic is monitor by the government ... it happening around the world. 

Magical Pineapples


 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Link to post
Share on other sites

Did you read the message?

They use an obsolete encryption so it may not be secure.  

 

The obsolete cipher message is pretty common even in website with full green secure padlock (you may wanna try with your online banking website in Chrome and click on the green padlock and you will see the obsolete cipher message), I don´t know how Google is managing certificates with Chrome but it doesn't mean its not secure. That part of the certificate I'm not worry about, the part that intrigues me is the part that says that "someone on the network might be able to change the look"

Link to post
Share on other sites

The bit about changing the look just means that some images/etc were loaded over an insecure connection. While this isn't ideal, it doesn't actually compromise your security.

The obsolete cipher suite just means that the encryption is slightly easier to crack than industry standards, but not easy to crack by any means, and it only matters at all if you are subject to a man in the middle attack (though even if you were, it's likely that the attacker isn't capable of decrypting your data, even in the order of magnitude tens of years).

HTTP/2 203

Link to post
Share on other sites

The bit about changing the look just means that some images/etc were loaded over an insecure connection. While this isn't ideal, it doesn't actually compromise your security.

The obsolete cipher suite just means that the encryption is slightly easier to crack than industry standards, but not easy to crack by any means, and it only matters at all if you are subject to a man in the middle attack (though even if you were, it's likely that the attacker isn't capable of decrypting your data, even in the order of magnitude tens of years).

 

Good to know! :D

 

I was worried that the "secure" fields (credit card info text boxes) were not actually secured but changed to look like so.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×