Helping people with computers... one answer at a time.
https is an important step to keeping the information you send and get on the web private. Hotmail uses it for login, but not thereafter.
Why is there a "http" in the address bar as a prefix when I log into Hotmail rather than an "https"? Other email servers' addresses (Gmail, Yahoo, etc.) seem to generally have the prefix "httpS" [capitalized for emphasis by me] ("https://www.google.com..." etc.), yet I noticed that Hotmail's reads "http://login.live.com/login..." once I've typed in "www.hotmail.com". Should I feel less safe logging into my Hotmail account rather than my Gmail one since there's no "https"?
•
It depends on what you're attempting to protect yourself from, but in general the answer is: yes. There's a slightly higher risk if Hotmail's not using https.
And unfortunately, it appears that for certain common operations Windows Live Hotmail cannot use https at all.
•
First, logging in.
When you login to Windows Live Hotmail you'll typically see the Windows Live login page sign in form:

Note the "enhanced security" item I've highlighted. That's actually a link. If you click on it, you'll see the same sign in form, but with this URL displayed in your address bar:

Note that it's https. In fact, it's "enhanced" https, indicated by the green bar naming Microsoft Corporation as the owner.
That's great, and it's safe to assume at this point that your Windows Live Hotmail login information is being encrypted - your username and password are safe from network sniffing.
Then things take a disappointing turn.
Once you login you'll see your address bar return to something like this:

That's not https. It's not encrypted.
That means that while your login information has been encrypted and could not be sniffed, the actual contents of your email as you read and send messages is being transmitted in the clear. Are you reading your Hotmail using an open hotspot in an internet cafe? Anyone within range and with the right software could be reading it along with you.
As I said: disappointing.
As far as I can tell, there's no way Windows Live Hotmail can be coerced to use an https connection for reading.
Contrast that to this option in GMail:

Select that option and no matter how you get to GMail it will always switch to an https connection, encrypting not only your login, but your email as you read and send it.
It's not a trivial problem for Microsoft to solve, but in my opinion, solve it they must. Hotmail just isn't as secure as it should be without it.
The good news is that Windows Live Hotmail's recently released POP3 and SMTP access use encryption, and connections using your desktop email clients are safe from sniffing.
Article C3653 - February 18, 2009
Yes, I am having troubles logging on as always. As for as reading all that stuff, takes too much time, would cost too much to print and I still don't understand it anyway. I have had an on-going troubles with my windows live hotmail, such as even now. As it seems a lot of us have had. Some people seem truly, understandably annoyed. Please I wish you'd fix this problem ASAP thank you Naomi Paulette
Reading this stuff takes too much time? Unfortunately using computers requires education of some sort, and that means that yes, you need to read and understand information about the services you're trying to use. While it would be nice if everything "just worked", it's not going to happen. We all need to understand the tools we're using, there's no escaping it.
08-Mar-2009
Hi, thanks for this article and the confirmation of the missing https service with Hotmail. I just noticed this (the lack of http security when using Hotmail) a few days ago and you article confirms what I suspected. Hotmail cant and don't provide any https service. This is not acceptable!! From now on I will not use Hotmail for personal correspondence at all. As I see it Hotmail is only usable as a "spam" mail service, i.e. I give out my Hotmail address whenever I need to supply one to use a Internet service. /Lars
Posted by: Lars Norlin at November 25, 2009 5:22 AMThe primary benefit of HTTPS for webmail systems is not protecting your email from being compromised on forums or by the receiver. It's to protect your personal email and login information from interception by prying eyes when you're using public computer systems (cafe, wifi, etc.). And, while the server may or may not encrypt your email in storage, it's more unlikely to be compromised in this state than if it were saved on the hard drive of the sender or recipient. The webmail providers generally do a reliable job of preventing hackers from breaking into mailboxes. Also, HTTPS web pages are generally not stored in your browser's cache.
Posted by: dijitul at December 4, 2009 2:34 AMyou could pop3 and smtp from gmail to hotmail!
Posted by: Justin Goldberg at January 5, 2010 8:23 AMYo!
Some tips for you, boys and girls:
You CAN go "secure" on the Hotmail. Just replace http with https.
Next, accept certificate exception (idiotic, yes).
After, you'll be asked by the hotmail itself whether to always use https. Say YES. And, voila.. that's it!
:)
And then, use Gmail instead.
Posted by: Miles Bennet at April 14, 2011 1:00 PM