What is SSL (the little padlock)?

SSL ("Secured Socket Layer") is a protocol used to encrypt the communication between the user's browser and the web server. When SSL is active, a "little padlock" appears on the user's browser, usually in the status line at the bottom (at the top for Mac/Safari users.)

This assures the user that sensitive data (such as credit card numbers) can't be viewed by anyone "sniffing" the network connection (which is an increasing risk as more people use wireless networking).

Common web site owner questions about SSL:

How do I get the little padlock on my site?

To get the little padlock, your site must have an SSL Certificate from a Certificate Authority. Once an SSL Certificate has been purchased and installed, it provides three things:

  • The ability to show a page in "Secure Mode", which encrypts the traffic between the browser and the server, as indicated by the "little padlock" on the user's browser.
  • A guarantee by the issuing Certificate Authority that the domain name the certificate was issued for is indeed owned by the specific company or individual named in the certificate (visible if the user clicks on the little padlock).
  • An assurance that the domain name the certificate was issued for is the domain name the user's browser is now on.
  • Once obtained, the certificate must be installed on the web server by your web host. Since your web host also has to generate an initial cypher key to obtain the certificate, very often they will offer to handle the process of obtaining the certificate for you.

    My web host has a "shared certificate" that I can use. Should I?

    It's still fairly common for small sites to use a shared certificate from the host. In this circumstance, when a page needs to be shown in secured mode, the user is actually sent to a domain owned by the web host, and then back to the originating domain afterwards.

    A few years ago, when SSL Certificates were quite expensive (around $400 per year), this was real attractive for new sites just getting their feet wet in e-commerce. Today, with a number of perfectly functional SSL certificates available for under $100 (exclusive of installation, etc.), it is a lot less attractive. Since your user can look a the address line of his or her web browser and see that the site asking for the credit card number is not the site he or she thought they were on, the cost savings is probably not worth the risk of scaring off a sale.

    What's the difference between the expensive SSL Certificates and the inexpensive ones?

    Usually, mostly price. Some expensive certificates have specific functions, like securing a number of different subdomains simultaneously (a "wildcard" certificate), but the effective differences between basic single site certificates are very slight, despite the wide range of prices:

    The encryption mechanism used by all of them is the same, and most use the same key length (which is an indicator of the strength of the encryption) common to most browsers (128 bit).

    Some of them ("chained root" certificates) are slightly more of a pain for your web host to install than others ("single root" certificates), but this is pretty much invisible to the site owner.

    The amount of actual checking on the ownership of the domain varies wildly between vendors, with some (usually the more expensive) wanting significant documentation (like a D&B number), and others handling it with an automated phone call ("press #123 if you've just ordered a certificate").

    Some of them offer massive monetary guarantees as to their security (we'll pay you oodles of dollars if someone cracks this code), but since it's all the same encryption mechanism, if someone comes up with a crack, all e-commerce sites will be scrambling, and the odds of that vendor actually having enough cash to pay all of its customers their oodle is probably slim.

    The fact is that you are buying the certificate to insure the safety of the user's data, and to make the user confident that his or her data is secure. For the vast majority of users, simply having the little padlock show up is all they are looking for. There are exceptions (I have a client in the bank software business, and they feel that their customers (bank officers) are looking for a specific premier name on the SSL certificate, so are happy to continue using the expensive one), but most e-commerce customers do not pick their sellers based on who issued their SSL Certificates.

    My advice is to buy the cheaper one.

    I have an SSL certificate -- why shouldn't I serve all my pages in "Secured" mode?

    Because SSL has an overhead -- more data is sent with a page that is encrypted than a page that isn't. This translates to your site appearing to run slower, particularly for users who are on dial-up or other slow connections. Since this also increases the total amount of data transfered by your site, if your web host charges by transfer volume (or has an overage fee, as most do), this can increase the size of your monthly hosting bill.

    The server should go into secure mode when asking a user for financial or other sensitive data (which may well be "name, address and phone number", with today's risk of identity theft), and operate in normal mode otherwise.

    Updates to this article, and many other great articles and tutorials for small business web site owners can be found at Insanely Great Sites!

    In The News:


    Google News
    Updated : Sun, 12 Oct 2008 11:51:06 GMT

    ARM Holders Would Do Well to Shop Around Now - Washington Post


    Sify
    ARM Holders Would Do Well to Shop Around Now
    Washington Post - 4 hours ago
    By Nancy Trejos The global financial crisis has affected virtually every aspect of personal finance, from mortgages to student loans to credit cards to retirement savings.
    Finance giants reportedly ordered to buy $40 bln of mortgage bonds ... MarketWatch
    Fannie, Freddie to Buy $40 Billion a Month of Troubled Assets Bloomberg
    The Miami Herald - Orlando Sentinel - Sunday Paper - San Jose Mercury News
    all 227 news articles

    Publ.Date : Sun, 12 Oct 2008 07:07:17 GMT

    Many homers, and pitches, in Game 2 - MLB.com


    Los Angeles Times
    Many homers, and pitches, in Game 2
    MLB.com - 2 hours ago
    By Bryan Hoch / MLB.com ST. PETERSBURG -- Five hours and 27 minutes elapsed during Saturday's American League Championship Series Game 2, bookending the moments when Scott Kazmir threw the game's first pitch over home plate and BJ Upton popped its ...
    Up, up, and away Boston Globe
    Mike Timlin shoulders blame Boston Herald
    Los Angeles Times - Washington Times - Tampa Tribune - ESPN
    all 495 news articles

    Publ.Date : Sun, 12 Oct 2008 09:22:57 GMT

    Theatrical Review of Body of Lies - DVDTOWN.com

    Theatrical Review of Body of Lies
    DVDTOWN.com - 11 hours ago
    By Jason P. Vargo "Body of Lies" is a certain type of movie designed for a certain type of moviegoer. I think the tagline describes the movie perfectly, actually.
    Will 'Chihuahua' take a bite out of 'Body of Lies'? Los Angeles Times
    Body of Lies Entertainment Weekly
    E! Online - San Francisco Chronicle - Reuters - Washington Post
    all 1,041 news articles

    Publ.Date : Sun, 12 Oct 2008 00:19:39 GMT

    Japan says will tap FX reserve if IMF steps up bailout - Reuters


    Voice of America
    Japan says will tap FX reserve if IMF steps up bailout
    Reuters - 6 hours ago
    WASHINGTON, Oct 11 (Reuters) - Japan said on Saturday it is ready to offer a part of its $1 trillion foreign reserves to the International Monetary Fund (IMF) if the multi-national lender is to support countries facing economic crisis.
    Video: IMF: Timing right for G7 ReutersVideo
    IMF Calls for Aggressive Response to Crisis New York Times
    Bloomberg - MarketWatch - Financial Times - Voice of America
    all 2,310 news articles

    Publ.Date : Sun, 12 Oct 2008 05:32:02 GMT

    American space tourist blasts off in Soyuz rocket - The Associated Press


    Washington Post
    American space tourist blasts off in Soyuz rocket
    The Associated Press - 39 minutes ago
    BAIKONUR, Kazakhstan (AP) - A Soyuz spacecraft with two Americans and a Russian on board lifted off from Kazakhstan on Sunday for the international space station.
    Space Toilet Fixed – For Now eFluxMedia
    Russia launches spacecraft with sixth space tourist China Daily
    KGAN - MarketWatch - Spaceflight Now - USA Today
    all 615 news articles

    Publ.Date : Sun, 12 Oct 2008 11:11:37 GMT

    Van driver's work in Mass. aided Nobel winners - Boston Globe


    Boston Globe
    Van driver's work in Mass. aided Nobel winners
    Boston Globe - 7 hours ago
    HUNTSVILLE, Ala.—When two American scientists won a Nobel Prize this week in chemistry, the driver of a car dealership's courtesy van had reason to take special interest.
    Video: Nobel Chemistry Prize Goes for Jellyfish Protein AssociatedPress
    The Daily Yomiuri - The Associated Press - Ars Technica - New York Times
    all 1,253 news articles

    Publ.Date : Sun, 12 Oct 2008 04:14:18 GMT

    McCain campaign's tone likened to George Wallace's - Newsday


    Malaysia Star
    McCain campaign's tone likened to George Wallace's
    Newsday - 2 hours ago
    WASHINGTON - Rep. John Lewis, a Georgia Democrat and veteran of the civil rights movement, says the negative tone of the Republican presidential campaign reminds him of the hateful atmosphere segregationist Gov.
    McCain in 'hatred' war of words BBC News
    Obama thanks, jabs at McCain Chicago Tribune
    New York Times - Los Angeles Times - Reuters - AFP
    all 404 news articles

    Publ.Date : Sun, 12 Oct 2008 09:27:11 GMT

    Data Feed Content for Web Pages
    Amazon Associate Store


    PARLOT::Ebooks, Scripts, Websites, and more...

    Adsense websites

    Drop-Shipping ? A Great Way of Making Money Online

    Using the Internet to sell products and services to ever... Read More

    How To Sell Websites Fast !

    This article will explain in depth the steps needed to... Read More

    Electronic Commerce and WTO

    The Internet may not be useful for all businesses, nor... Read More

    Succeed With Your Own Home Based Business

    An internet business is by far the best way to... Read More

    Grow Your Business Using B2B Emarketplace ? Part II

    Selecting the right emarketplaceAlthough, IT spending has been staying flat... Read More

    10 Reasons Why People Wont Buy A Second Product From You

    1. You didn't follow up after the first sale. After... Read More

    Why Arent People Buying From Your Ecommerce Website?

    Your stock is tempting, your prices right - your ecommerce... Read More

    E-Gold

    E-gold is a digital currency, used extensively on the Internet... Read More

    eCommerce Software Solutions

    All of the long, grueling nights and an unknown number... Read More

    E-Currency Exchange: The First Bonanza of the 21st Century?

    The 21st century has introduced the world to a new... Read More

    Saving Money On Your E-commerce Site

    After building and transferring many e-commerce sites it still amazes... Read More

    The Essential Christmas Web-store Makeover

    Ten great tips to turn online holiday shoppers into eager... Read More

    eCommerce, How Much Does It cost?

    Making profits with your existing website design or creating a... Read More

    Is Your Business Afraid of the Internet?

    My Business is Afraid of the InternetBill Gates, CEO of... Read More

    Choosing the Right Online Shopping Cart

    Are you a website owner or a web designer/developer? If... Read More

    Make That 3 Billion

    My previous article I wrote called "One Point Two Billion"... Read More

    12 Powerful Ways To Use Autoresponders That Will Take YOU To The Top

    If only I had known that autoresponders are a necessity... Read More

    Precautions Necessary for an Online Brokerage Business

    Maybe no business requiring little or no capital pays as... Read More

    10 Compelling Benefits of Having A 3rd Party Merchant Account

    If you have been wrestling with the idea of applying... Read More

    The Rise of Multinational Virtual Corporations

    The virtual corporation is the emerging organisational form, which best... Read More

    Choosing an Ecommerce Shopping Cart

    Choosing an online shopping cart is a big decision. Unlike... Read More

    How To Prevent Your 3rd Party Merchant Account From Suspension

    What would you do if you were sent an email... Read More

    7 Must Have Scripts to Look for When Shopping for E-commerce Hosting

    When shopping for e-commerce hosting there are a lot of... Read More

    Business Online ? Blind Hunt

    Do you sell something online? Do you have a business... Read More

    Do You Need A Merchant Account?

    Deciding when to get your own merchant account for internet... Read More