Free tech support / small logo


How can I use https to securely access Facebook?

I often use public wifi networks to access my Facebook account and am a bit paranoid about my privacy and security. Is there some way to force Facebook to use SSL (https) to securely connect me each time, encrypting information both sent and received?


Dave's Answer:

After the appearance of alarming hacker utilities like Firesheep (which monitors wifi networks to find people logging in to Facebook, then saves a copy of their account and password) it didn't take long for Facebook to join the many different sites that support full-time secure socket layer (SSL) connections between browsers and their server. Another service that supports this full-time SSL connect, btw, is Google's Gmail, so if you're a Gmail user, check it out in the preferences too!

Problem is, as with much of what Facebook does, the secure connection option is something that's being slowly introduced to users. Facebook calls it "a gradual rollout". I call it "darn it, how come other people can do this and I can't?"

Fortunately I now can, so I can show you exactly how I enabled secure browsing with "https" on my Facebook account and you can check to see if you also have this capability. Hopefully you do!

First step is to go to "Account Settings":

facebook https secure browsing 1

Once you're at your account settings, scroll down until you find "Account Security". If you have the option of using the secure https connection, it'll look like this:

facebook https secure browsing 2

If you just see the option related to getting emails and text messages when different systems log in to your account, well, then I guess you need to wait a day or two and try again. Eventually you'll get the new secure connection option, I'm sure.

Hopefully you do have it, however, in which case this is what you'll see:

facebook https secure browsing 3

Looks good! Just click on the box adjacent to "Browse Facebook on a secure connection (https) whenever possible", then click on the "Save" button.

That's it.

Now when you're on Facebook, you should see a nice secure "https" displayed, not the usual -- and insecure -- "http":

facebook https secure browsing 4

Hope that helps you out. If you're really concerned with security, I also encourage you to check out my article on how to use one-time passwords on Facebook so that you don't have to worry about your password being stolen through a keystroke logger or similar.


Also check out:








Subscribe!
Never miss another Q&A article! Click to subscribe: Add to Google Reader Add to My Yahoo! Subscribe in NewsGator RDF XML
Comments (3) · Add Comment

Excellent info Dave! I've been pretty lucky so far in that my account hasn't been hacked (knock on wood), but I've also been preparing myself for the time when it finally was.

Hopefully I won't have to worry about that now!

Thanks for sharing.

Posted by: Chestin Salisbury at February 2, 2011 10:11 AM

Indeed. Excellent info, Dave.

Question. Couldn't you just type https://facebook.com on your address bar, though?

Or was this option not yet available during time of posting?

Thanks.

Reil

Posted by: Reil Gin at March 4, 2011 6:22 AM

Rell, that'll work until you click on a link and it flips you back to non-SSL connection. The new feature works for your entire session.

Posted by: Dave Taylor at March 4, 2011 10:55 AM
Starbucks coffee cup I do have a lot to say, and questions of my own for that matter, but first I'd like to say thank you for all your efforts on this Web site by buying you a cup of coffee!

I do have a comment, now that you mention it!











Remember personal info?


Please note that I will never send you any unsolicited email. Ever.

While I'm at it, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site.









Recent Entries


Search
I Need Help!
Need Help? Ask Dave Taylor!


© 2002 - 2012 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site.

[whiteboard marker tray]
"Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.