New Zenner
- Join Date:
- Jan 2010
- Posts:
- 19
- Plugin Contributions:
- 0
How to secure contact us page with SSL?
Is it possible to secure the contact us page or any certain page with SSL?
Views: 6,598
New Zenner
Is it possible to secure the contact us page or any certain page with SSL?
Sensei
What's the point? The contact-us message is sent by email, which is the least secure communications method available. So, protecting the Contact-Us page with SSL would be pointless from a security perspective.
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
New Zenner
DrByte:
What's the point? The contact-us message is sent by email, which is the least secure communications method available. So, protecting the Contact-Us page with SSL would be pointless from a security perspective.
why do ppl have to argue the point, the point is we want to secure the contact form, anyone know how? :frusty:
Totally Zenned
You sad fellow...
I take it you don't know that DrByte is one of the key developers of zencart.
Perhaps you should respect his opinion.
20 years a Zencart User
Zen Follower
DR.BYTE is technically right.
But people always have different ideas, that's allowed right?
change every link of contact_us page to be SSL enabled, or you may have to change zen_href_link definition as following:
if find currnet page is contact_us, force it to be SSL enabled.
Totally Zenned
ebusinessman:
But people always have different ideas, that's allowed right?
Agreed... but when the idea makes no sense, it opens itself up to legitimate challenges.
Making the contact us page SSL is akin to putting 100 padlocks on your house's front door, only to leave the big bay-window next to it wide open.
20 years a Zencart User
Zen Follower
haha, that's interesting. Maybe he just want to make customers feel secure.
Totally Zenned
ebusinessman:
haha, that's interesting. Maybe he just want to make customers feel secure.Well his customers may THINK they are secure, but they are not secure.. So WHY create a FALSE sense of security by implementing something that is NOT secure because it LOOKS secure..
My Site - Zen Cart & WordPress integration specialist
I don't answer support questions via PM. Post add-on support questions in the support thread. The question & the answer will benefit others with similar issues.
Zen Follower
If he want to make it secure, it can be secure.
This man asked a question, 3 people don't agree, in technical view, business view and even ethic related. Let's imagin, when you said "aha, I want to fly", other people said "it does not worth fly; it's not safe to fly; fly gives other people wrong feeling about you, please don't fly". How do you feel?
I do remeber my college time, once professor James said "there's no question that is stupid". This forum is just like an open campus. We should be open to hear and help. If we can not help, then the best way is listening. The engineers of Apple said they can't make a device that can find out any song from the list within 3 clicks, but they did.
So let's consider JC.M has a strong wish to improve Contact Us page even many said it's not practical. Here's my solution:
By enable SSL for contact us page and doing step 3, you got a perfect secured contact us page. Even visitors' (not registered customers) privacy is under the strongest protection. If you did this, please contribute the add-on to community, and we shall owe you a favour.
BTW, I use TXT file to store the message in case the email fails. It did fail sometimes.
Totally Zenned
I could see a benefit to this if the contact us page has been extended to collect additional and personal or commercially sensitive information, since it submits back to itself, but only if you have encrypted email between your server and wherever you receive the mail.
In this case you would need to find all instances of zen_href_link(FILENAME_CONTACT_US) and change them to zen_href_link(FILENAME_CONTACT_US, '', 'SSL')
But you'd then need to maintain those changes (and there's quite a few of them) through future upgrades. So I would double check against DrByte's point and make sure that you really do have a sufficiently secure infrastructure and a really valid benefit for doing this before going ahead.
Kuroi Web Design and Development | Twitter
(Questions answered in the forum only - so that any forum member can benefit - not by personal message)
New Zenner
I can't get the Contact US page to work, it crashes, since everything else is SSL. HOW DO I GET IT TO BE SSL.
Black Belt
PatriciaWhipp:
HOW DO I GET IT TO BE SSL
Read kuroi's post #3
Zen-Venom Get Bitten
Zen Follower
1 reason would be that it is required by law in The Netherlands that the contact us page should be in SSL.
I came, I saw, I got zenned... :)
Obaa-san
1 reason would be that it is required by law in The Netherlands that the contact us page should be in SSL.
Can you please provide references (preferably in English) to this law and its scope?
Please do not PM for support issues: a private solution doesn't benefit the community.
Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.
Totally Zenned
Kim:
Can you please provide references (preferably in English) to this law and its scope?
I saw something just yesterday about that, can't find it now of course
http://www.networking4all.com/en/ssl+certificates/legal+obligations/
Webzings Design
Semi retired from Web Design
Obaa-san
So - here's the act/proclamation/law that the company promoting their SSL certificates is touting ... We'll review it.
Please do not PM for support issues: a private solution doesn't benefit the community.
Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.
Zen Follower
Article 13 is the article from which through jurisprudence has been derived that SSL is mandatory for all pages on a website that transmits personal information.
Article 13
The responsible party shall implement appropriate technical and organizational measures to
secure personal data against loss or against any form of unlawful processing. These measures
shall guarantee an appropriate level of security, taking into account the state of the art and the
costs of implementation, and having regard to the risks associated with the processing and the
nature of the data to be protected. These measures shall also aim at preventing unnecessary
collection and further processing of personal data.
Basically that law states that whenever personal information (name, address etc. ) is transmitted from an individual to a webshop that this transmission has to be as safe as possible taking into account that the technical solutions to do this is widely available and affordable for the average webshop owner.
Although this law is not (yet) being enforced actively, it could be used as a stick to beat some more.
I came, I saw, I got zenned... :)
Totally Zenned
That piece of legislation is very similar to the UK's Data Protection Act, which is not a surprise, since they are the local laws necessary to enable the same European Directive.
However, we certainly don't interpret it anywhere near as tightly as you are. Indeed, from your post it sounds as though you authorities there don't either ... you're just saying that they might (even though the legislation has been in force for 11 years and they haven't).
From a close reading of the translation, I'd say that you're over-interpreting the legislation. However, if it's a real concern to you, I'd recommend that you have Philip build it into his fork.
Kuroi Web Design and Development | Twitter
(Questions answered in the forum only - so that any forum member can benefit - not by personal message)
Zen Follower
No it is not enforced actively by which i mean that if your contact us pages are not secured by SSL you will not get fined or cuffed right away.
But it is necessary to get certified then they check.
There is jurisprudence that SSL is mandatory. (sorry only i can find atm are in Dutch)
And why would i want Phillip have to write that in his fork? and what has it to do with this subject? Seriously i don't get that... i might not be very active on this forum as i am mostly active on the dutch and German zen-cart fora (yes there are really people in this world that find it hard to read English especially when it comes to technical stuff)
I came, I saw, I got zenned... :)
Totally Zenned
eentje:
But it is necessary to get certified then they check.Certified by whom?
Kuroi Web Design and Development | Twitter
(Questions answered in the forum only - so that any forum member can benefit - not by personal message)
Tell staff why this post should be reviewed.