You’ve probably seen a message like “Your connection is not private.” at some time in your online travels. An attack on your information may be underway. It’s common for a page to provide you the choice to continue to the website. But is it advisable?

Why did I end up on this page in the first place?

Paying payments, shopping for groceries, and communicating with physicians are just a few examples of the many tasks we now do on the internet. Our web browser’s security procedures are becoming important as more websites ask for personal information.

When you visit a website, your web browser (such as Chrome, Safari, or Firefox) initially checks to see whether a Transport Layer Security (TLS) or Secure Sockets Layer (SSL) certificate is present. Two things are evident from this. To begin, they verify the website’s legitimacy by verifying that it is, in fact, the one it claims to be. Second, they make sure that the data you give with the website is safe and secure. Whether it’s a credit card number or a home address, encryption assures that the information you give will not be readable if intercepted.

Clicking on the little padlock to the left of the URL or checking for “HTTPS”—not “HTTP”—at the top of the website link will inform you whether the website has a valid certificate. A secure certificate is used to transmit data over the internet when HTTPS is used.

Search results will now prioritise sites with certificates, as Google revealed in 2014. This means that sites with certificates will appear higher in search results. As a result, the business stated in 2018 that its Chrome browser will show the “Connection Not Private” warning for any websites that do not have a properly configured certificate (either TLS or SSL). Similar precautions have been taken by other browsers.

As a consequence, if you attempt to access certain websites while surfing the web, you may get this notice.

Will my personal data be compromised if I go to the website?

Possibly. It’s possible that the Connection Not Private display appears because of a certificate that’s been set incorrectly, has just expired, or is absent altogether.

It is possible to become a victim of a variety of cyberattacks by accessing websites that lack adequate security measures like encryption.

In a “man-in-the-middle” assault, your data might be intercepted as it travels over the internet. As a senior staff technologist at the Electronic Frontier Foundation (EFF), Bill Budington, said, the most common way this happens is when someone hijacks your Wi-Fi connection, deceiving your device into believing the hacking programme is the access point your device should be connected with. The attacker has access to all of your internet traffic and any data you provide to a website using this method.

It doesn’t matter if a nation-state fools its population into believing it’s google.com or a hacker fools a coffee shop client into disclosing the sites they view, according to Budington. On other words, “It implies that sensitive data that was never handed to that untrusted party, and the prospect of impersonating the target or obtaining a history of communications in the sites that they’ve frequented.”

E-commerce websites are particularly vulnerable to this kind of attack since clients often submit personal information like their address and credit card number. Theft of one’s identity, which reached a record high in 2021, might be made easier with the information that has been intercepted. Hackers who aren’t black hats conducted their own tests to assess just how simple it is to capture unencrypted data sent over the internet. In a single day at the mall, his programme linked to 49 devices despite the fact that it did not capture any personal information about the users.

Ransomware attacks may occur if a user visits an infected website and malware is covertly downloaded to the user’s device when they browse unencrypted websites. Users’ data might be held hostage until they pay the ransom demanded by the attackers thanks to the software.

Another danger of disregarding the warning is that you may be vulnerable to scammers who act as reputable websites to trick you into handing over personal information, such as your bank account or credit card information. When a website’s certificate isn’t legitimate, a Connection Not Private notification is generated. Because the bank’s website would have a functional certificate, if a user enters in their bank’s URL and gets this warning, something is amiss.

What should I do if I come across a notice like this?

Bruce Schneier, a security expert and Harvard teaching associate, suggests checking to see whether you’re connecting to the proper URL. In the end, Schneier argues, it’s typically just a matter of making an educated guess.

Do not click on any links in an email from an unknown sender, for example. You will get an alert. Do not click on any links in that email. It’s probably simply a “embarrassment” to enter in a well-known URL incorrectly, he said. Schneier says the alarm may be triggered for a variety of good reasons, such as a certificate that has recently expired or a URL that does not match the certificate’s name.

The cause of the alert may be tracked down in many ways. Error codes may be found by searching for them on the Internet. As an example, if you get the message NET::ERR:CERT COMMON NAME INVALID, it typically signifies that the name on the certificate does not match the URL that you supplied.

If you’re using public Wi-Fi at a library or an airport, you’ll likely see the pop-up window. If someone on your home network attempts a man in the middle attack on public Wi-Fi, you’re more likely to be targeted. This makes it more more crucial to utilise HTTPS while using public Wi-Fi so that you may avoid being targeted by others nearby.

Whether the issue remains, you may try restarting your computer, cleaning your cache, or connecting to a private Wi-Fi network to check if the problem persists.

If that’s the case, why do you insist on going to the website? Under most cases, if you’re using Chrome or Firefox, you may just click the “Advanced” option in the error message and continue to the page. Remember to use caution when entering any sensitive information, like passwords and addresses, since this data will not be safeguarded.

Despite the fact that a validated certificate verifies that a website is encrypted, Schneier warns that a website’s proprietors may have malevolent intents despite the fact that the website is encrypted.

Source