Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 811263
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 15, 20262026-05-15T01:01:04+00:00 2026-05-15T01:01:04+00:00

Recently I installed a certificate on the website I’m working on. I’ve made as

  • 0

Recently I installed a certificate on the website I’m working on. I’ve made as much of the site as possible work with HTTP, but after you log in, it has to remain in HTTPS to prevent session hi-jacking, doesn’t it?

Unfortunately, this causes some problems with Google Maps; I get warnings in IE saying “this page contains insecure content”. I don’t think we can afford Google Maps Premier right now to get their secure service.

It’s sort of an auction site so it’s fairly important that people don’t get charged for things they didn’t purchase because some hacker got into their account. All payments are done through PayPal though, so I’m not saving any sort of credit card info, but I am keeping personal contact information. Fraudulent charges could be reversed fairly easily if it ever came to that.

What do you guys suggest I do? Should I take the bulk of the site off HTTPS and just secure certain pages like where ever you enter your password, and that’s it? That’s what our competition seems to do.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-15T01:01:04+00:00Added an answer on May 15, 2026 at 1:01 am

    I would take the bulk of the site off HTTPS with some exceptions of course:

    1. Any checkout or account editing screens.
    2. Any screens that would display “sensitive” information.

    To deal with the session hijacking issue, I would add another layer of authentication where you prompt them for their username and password again at checkout or whenever they try to view/update account information – basicly whenever you make a transition from http to https.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I recently installed PHP on IIS/Windows 7, but it isn't working. I am getting
I recently installed a secure certificate for a web site I help maintain. When
I recently installed VS 6.0 after installing VS 2008 and overwrite JIT settings ..
Distribution certificate recently expired so had to create another one. Everything seemed to work
I recently revoked my certificate on apple.developer account. After that I downloaded the new
I recently installed CouchDB, but haven't gotten past the test suite yet. It seems
I recently installed the autotools plugin for eclipse. I made the Makefile.am for each
I recently installed VS2008 in Win2k8R2 machine and opened a VS2005 project(C++). After successful
I recently installed Rails on a cpanel machine using this guide: http://www.cpanel.net/blog/cpanel-whm-admins/2011/07/installing-mod-rails-and-rails-309-on-a-cpanel-machine.html When I
I recently installed mysql server and client, but I can't connect to the server.

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.