Ask Leo! by Leo A. Notenboom

Why is there no Windows Live Hotmail https connection?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » EMail » EMail Providers » Windows Live Hotmail

Summary: https is an important step to keeping the information you send and get on the web private. Hotmail uses it for login, but not thereafter.

Why is there a "http" in the address bar as a prefix when I log into Hotmail rather than an "https"? Other email servers' addresses (Gmail, Yahoo, etc.) seem to generally have the prefix "httpS" [capitalized for emphasis by me] ("https://www.google.com..." etc.), yet I noticed that Hotmail's reads "http://login.live.com/login..." once I've typed in "www.hotmail.com". Should I feel less safe logging into my Hotmail account rather than my Gmail one since there's no "https"?

It depends on what you're attempting to protect yourself from, but in general the answer is: yes. There's a slightly higher risk if Hotmail's not using https.

And unfortunately, it appears that for certain common operations Windows Live Hotmail cannot use https at all.

First, logging in.

When you login to Windows Live Hotmail you'll typically see the Windows Live login page sign in form:

Windows Live Hotmail Enhanced Security Link

Note the "enhanced security" item I've highlighted. That's actually a link. If you click on it, you'll see the same sign in form, but with this URL displayed in your address bar:

Windows Live Hotmail Enhanced Security URL

Note that it's https. In fact, it's "enhanced" https, indicated by the green bar naming Microsoft Corporation as the owner.

That's great, and it's safe to assume at this point that your Windows Live Hotmail login information is being encrypted - your username and password are safe from network sniffing.

Then things take a disappointing turn.

Once you login you'll see your address bar return to something like this:

Windows Live Hotmail URL when reading

"As far as I can tell, there's no way Windows Live Hotmail can be coerced to use an https connection for reading."

That's not https. It's not encrypted.

That means that while your login information has been encrypted and could not be sniffed, the actual contents of your email as you read and send messages is being transmitted in the clear. Are you reading your Hotmail using an open hotspot in an internet cafe? Anyone within range and with the right software could be reading it along with you.

As I said: disappointing.

As far as I can tell, there's no way Windows Live Hotmail can be coerced to use an https connection for reading.

Contrast that to this option in GMail:

GMails always use https option

Select that option and no matter how you get to GMail it will always switch to an https connection, encrypting not only your login, but your email as you read and send it.

It's not a trivial problem for Microsoft to solve, but in my opinion, solve it they must. Hotmail just isn't as secure as it should be without it.

The good news is that Windows Live Hotmail's recently released POP3 and SMTP access use encryption, and connections using your desktop email clients are safe from sniffing.

Related:

Helpful? Get new articles weekly by email in my FREE newsletter!

Your Name:
Your Email:


Why Subscribe?

Article C3653 - February 18, 2009

Recent Comments
8 Comments

SSL only protects sending receiving the emails from my browser, right? My emails are still not encrypted in Gmail or hotmail mail servers. Also are the emails transfer in encrypted form between email servers?

You are very correct. Email is not encrypted when stored on mail servers, and it's also typically not encrypted when transmitted between servers.

More to the point, it may also not be encrypted when your recipient views or downloads it depending on their connection settings.
- Leo
22-Feb-2009

Posted by: John O at February 21, 2009 9:22 PM

Thanks for the answers. So the SSL thing in Gmail only solves a small part of the problems, my emails are still pretty much not secure. I guess at least having SSL is the first step towards more secure emails. Baby steps...

Posted by: John O at February 22, 2009 6:52 PM

The most unsecure thing for most emails is what the person who receives it does with it. All the security in the world (short of making it unreadable by anyone) is lost if the receiver posts it on many forums.

A lot depends on what you are sending and why somone would want to look at it.

If you are sending bank account information to a trusted receiver, I certainly wouldn't do it from a public computer or via an unencrypted site. If a crook goes to the work to hack into Google's servers he is not likely to find your information among the billions of messages there unless he has some way of knowing what to look for.

Posted by: bill at February 24, 2009 10:42 AM

Thanks fot the giving the setting for Gmail - so you access it http - I didn't have that selected (I just did it now.) I looked into encrytion for email and cryptainer wasn't bad but the recipient has to have the program as well making that a difficult solution sometimes. I am hoping there will be software in the future that addresses the need for encryption for email.

Posted by: Sandy Smith at February 24, 2009 9:26 PM

What software do you guys use to encrypt emails?
Leo, do you have any recommendations for email encryption software (preferably free)?

I ended up writing a new article on that: How do I encrypt email?
- Leo
25-Feb-2009

Posted by: John O at February 25, 2009 1:58 AM

Just an update to my earlier comment... I had to disable "Always use https" for Gmail because I could no longer access Gmail from my Blackberry.

Posted by: Sandy Smith at February 25, 2009 10:51 AM

A further update... I kept screwing around with the Blackberry and got it to run Gmail with "always use https." I just kept trying. I recently upgraded my Blackberry OS from 4.2 to 4.5 so that could be why - that OS is relatively new. So, if anybody having trouble just keep trying - keep signing in - keep loading it... it eventually took.

Posted by: Sandy Smith at February 25, 2009 7:12 PM

Yes, I am having troubles logging on as always. As for as reading all that stuff, takes too much time, would cost too much to print and I still don't understand it anyway. I have had an on-going troubles with my windows live hotmail, such as even now. As it seems a lot of us have had. Some people seem truly, understandably annoyed. Please I wish you'd fix this problem ASAP thank you Naomi Paulette

You wish I would solve this problem? I can't. I'm not Hotmail. I'm not Microsoft.

Reading this stuff takes too much time? Unfortunately using computers requires education of some sort, and that means that yes, you need to read and understand information about the services you're trying to use. While it would be nice if everything "just worked", it's not going to happen. We all need to understand the tools we're using, there's no escaping it.
- Leo
08-Mar-2009

Posted by: Naomi Paulette Hamm at March 7, 2009 10:37 AM

Post a comment on "Why is there no Windows Live Hotmail https connection?":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...


Question? Ask Leo!