<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Logging into PayPal the Right Way</title>
	<atom:link href="http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/</link>
	<description>The home and home office computer security center</description>
	<pubDate>Tue, 06 Jan 2009 11:58:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dd</title>
		<link>http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/comment-page-1/#comment-18</link>
		<dc:creator>dd</dc:creator>
		<pubDate>Wed, 06 Dec 2006 22:13:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/#comment-18</guid>
		<description>I did some investigation. If the email and/or password is saved for paypal.com then it will be redirected to https://www.paypal.com. If no login information is saved then it goes to http://www.paypal.com. I tried this in IE7 and Firefox 2.0.
Of course always clicking on Login brings you to https://www.paypal.com.

Doug</description>
		<content:encoded><![CDATA[<p>I did some investigation. If the email and/or password is saved for paypal.com then it will be redirected to <a href="https://www.paypal.com" rel="nofollow">https://www.paypal.com</a>. If no login information is saved then it goes to <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a>. I tried this in IE7 and Firefox 2.0.<br />
Of course always clicking on Login brings you to <a href="https://www.paypal.com" rel="nofollow">https://www.paypal.com</a>.</p>
<p>Doug</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gabb17</title>
		<link>http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/comment-page-1/#comment-16</link>
		<dc:creator>gabb17</dc:creator>
		<pubDate>Wed, 06 Dec 2006 01:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/#comment-16</guid>
		<description>I'm curious what browser are you using ? I have tried this from 3 different browsers on windows also on linux and mac os. The only thing that didn't take the redirect right was the old text mode lynx. Whenever typing http://www.paypal.com the browser redirects me to https://www.paypal.com/ *before* I can fill any username/password field. Maybe something's wrong with the way your browser is set up. But you're right I have seen the issue you're describing on other web sites.</description>
		<content:encoded><![CDATA[<p>I&#8217;m curious what browser are you using ? I have tried this from 3 different browsers on windows also on linux and mac os. The only thing that didn&#8217;t take the redirect right was the old text mode lynx. Whenever typing <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> the browser redirects me to <a href="https://www.paypal.com/" rel="nofollow">https://www.paypal.com/</a> *before* I can fill any username/password field. Maybe something&#8217;s wrong with the way your browser is set up. But you&#8217;re right I have seen the issue you&#8217;re describing on other web sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: webmaster</title>
		<link>http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/comment-page-1/#comment-15</link>
		<dc:creator>webmaster</dc:creator>
		<pubDate>Mon, 04 Dec 2006 18:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/#comment-15</guid>
		<description>If I go to www.paypal.com it is not secure because it is http://www.paypal.com. There is no lock on the browser to see if I'm really on paypal.com. The web page may be spoofed. If I enter in my email address and password then click on login I do not have any guarantee that the information is being sent to paypal.com - eventually I see it is redirected to a secure page.
Unfortunately, this flawed technique is popular with banks: you type in your login information on an unsecured page then it is redirected to a secure page. Microsoft and others have warned against this very security problem.

Doug</description>
		<content:encoded><![CDATA[<p>If I go to <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> it is not secure because it is <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a>. There is no lock on the browser to see if I&#8217;m really on paypal.com. The web page may be spoofed. If I enter in my email address and password then click on login I do not have any guarantee that the information is being sent to paypal.com - eventually I see it is redirected to a secure page.<br />
Unfortunately, this flawed technique is popular with banks: you type in your login information on an unsecured page then it is redirected to a secure page. Microsoft and others have warned against this very security problem.</p>
<p>Doug</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gabb17</title>
		<link>http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/comment-page-1/#comment-14</link>
		<dc:creator>gabb17</dc:creator>
		<pubDate>Mon, 04 Dec 2006 08:47:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mysecurepc.com/2006/11/29/logging-into-paypal-the-right-way/#comment-14</guid>
		<description>not true, when going to www.paypal.com or paypal.com you're automatically redirected to https://www.paypal.com 
check the facts before posting ...</description>
		<content:encoded><![CDATA[<p>not true, when going to <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> or paypal.com you&#8217;re automatically redirected to <a href="https://www.paypal.com" rel="nofollow">https://www.paypal.com</a><br />
check the facts before posting &#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
