Zen Cart Logo
Forums / Other Business Topics / Which SSL certificate should I get?

Which SSL certificate should I get?

Views: 161

Results 1 to 17 of 17
04 Jun 2012, 19:16
#1
stevenkc avatar

stevenkc

New Zenner

Join Date:
Apr 2012
Posts:
6
Plugin Contributions:
0

Which SSL certificate should I get?

Hi All,

I'm looking around at SSL/TLS and there is a wide range starting at free shared SSL all the way up to $3000 per year with 1.5 million warranty for Verisign.

Anyone have a favorite and why they picked it?

Thanks,
Steve

05 Jun 2012, 06:14
#2
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

SteveNkc:

Hi All,

I'm looking around at SSL/TLS and there is a wide range starting at free shared SSL all the way up to $3000 per year with 1.5 million warranty for Verisign.

Anyone have a favorite and why they picked it?

Thanks,
Steve

Many people think I'm weird, but my favourite is none at all.

MOST stores don't need SSL. Many people have problems installing them and configuring their store to use them, and customers are more paranoid about accessing a site with 'SSL warnings' than accessing a site with no SSL at all.

As I say, most people think I'm weird though

Cheers
Rod (adv dip network security)

ps. Regardless of cost, they all use the same methods of encrytption.

05 Jun 2012, 09:34
#3
stevesh avatar

stevesh

Black Belt

Join Date:
Feb 2005
Location:
Lansing, Michigan USA
Posts:
19,793
Plugin Contributions:
2

Re: Which SSL certificate should I get?

I do think RodG is weird, but I've been doing some reading and I'm coming around to agree with him about SSL. If you really think you need one, get the cheapest you can find, or a free one if possible.

05 Jun 2012, 13:17
#4
coolcarpartsonline avatar

coolcarpartsonline

Totally Zenned

Join Date:
Feb 2008
Posts:
1,386
Plugin Contributions:
0

Re: Which SSL certificate should I get?

I have tried Verisgn, Comodo and godaddy...

Each has their advantages, however I won't go without SSL no matter what. Considering the low cost of an SSL it is a must have if you want to sell online, it is not worth losing sales over few bucks.

IMO it all depends on what you are selling and who your target market is, if you are marketing to nerds or tech savvy customers, having Verisign or McAFee might be helpful, but for majority of customers goDaddy offers a $12.99 SSL that will do even if you do million dollar sales.

05 Jun 2012, 14:53
#5
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

CoolCarPartsOnline:

I have tried Verisgn, Comodo and godaddy...
Each has their advantages,

I'm curious to know these percieved adavantages are. None of the above do anything to authenticate that the certificate purchasers are who they say they are, or whether they are entitled to purchase a certificate for any given host/domain name.

CoolCarPartsOnline:

however I won't go without SSL no matter what.

I know many others that have the same opinion, many of them finally got wise though :)

CoolCarPartsOnline:

Considering the cost of an SSL

That's not the only cost to consider. There is also the cost of a private IP address to go with the SSL, then there is the extra hassle of migrating to a different server because most people start out with a store using a shared IP address....

CoolCarPartsOnline:

it is a must have if you want to sell online,

Only if you wish to accept credit card payments directly by the store, in which case you also need a CC merchant account and/or a payment gateway.. More expense/hassle...................

CoolCarPartsOnline:

it is not worth losing sales over few bucks.

This is highly debateable hearsay with no statistical data to back it up. In my experience, SSL enabled sites have actually had a reduction in sales, which increased again after SSL was removed. I've no empirical data to prove it though. At worst, the difference in sales has been negligable.

CoolCarPartsOnline:

IMO it all depends on what you are selling and who your target market is, if you are marketing to nerds or tech savvy customers,

One could make a fair assumtion that the market would consist of 99.9% 'nerds or tech savvy customers'. They wouldn't be online otherwise, and I feel that very few 'n00bs' make online shopping one of their top priorities.

CoolCarPartsOnline:

having Verisign or McAFee might be helpful,

The real nerds are laughing at this. They know that all certs use the same encryption techniques so none is any more 'secure' than another. That only leaves a difference of authentication, and I'd be more trusting of a self signed certificate than one that can be purchased for a small amount of cash. This way, if I'm being scammed its probably by a real scammer, rather than a script kiddy. IOW, I'll have reduced my chances of being scammed by factor of many thousands.

FWIW, most large businesses/organisations use Self Signed certificates for all of their internal use for this very reason (as well as the ongoing cost savings).

The only certs actually worth a dime are those issued by Thawte, because they still authenticate the certificates they issue (but even then it's not foolproof because they now 'advertise' three of the authentication methods they use). Bit of a catch-22 there.

There may be one or two others that also authenticate, but off the top of my head I can't think of any (which makes them worthless in regards to my sense of security).

CoolCarPartsOnline:

but for majority of customers goDaddy offers a $12.99 SSL that will do even if you do million dollar sales.

Or better yet, Self-sign one and it costs nothing. Most customers will never know the difference, and those that do will simply 'click through' the initial alert anyway. As per my opening comments, having no SSL even bypasses this problem.

If you have something in your store that the customer wants, they will buy it. SSL or not. I know you've gotta spend money to make money, but it needs to be spent in the right places for the right reasons, and even at the right time.

I fully understand and respect that a business decision has been made in this regard, and I also understand your point of view, neither of which I am saying are wrong or incorrect, especially when there are times and places where I'll fully agree with you on this same matter. IOW I don't know your business so I'm in no position to give you advice that may not be in your best interests.

My intent is to expand on some of the reasons why I appear to be anti-SSL (I'm neither pro or con). I may appear mad, but I do have reasons behind this madness) :)

Cheer
Rod

05 Jun 2012, 21:17
#6
coolcarpartsonline avatar

coolcarpartsonline

Totally Zenned

Join Date:
Feb 2008
Posts:
1,386
Plugin Contributions:
0

Re: Which SSL certificate should I get?

My opinion reflects the point of view of a business owner that have to deal with customers on daily bases not of a developer...

I have had sites without SSL of any kind that made sales but every once in a while you get an angry customer that will complain about not having SSL and threaten to shop elsewhere. So if you are in business to make money. I phone bill will cost you more than the SSL, Dedicated IP and shared hosting with cheap company so if you are willing to lose sales all because of $2.5/month dedicated IP, $12.99/year SSL and $3.95/month hosting (All Hostmonster Prices) then maybe you shouldn't be in business.

I agree my views may be different but I have been in business for a long time and my SSL cost $1000/year and the security scan cost over $2000. However I believe you should cover all your basis before putting a site online.

06 Jun 2012, 08:52
#7
schoolboy avatar

schoolboy

Totally Zenned

Join Date:
Jun 2005
Location:
Cumbria, UK
Posts:
10,327
Plugin Contributions:
0

Re: Which SSL certificate should I get?

Our research (done rather unscientifically, but over several years now) shows that web shoppers are increasingly regarding SSL as important on eCommerce sites. Our last focus group (March 2012) on shopping trends gathered together 30 people, selected on the basis of their web shopping habits.

18/30 (60%) said that they would not complete a transaction unless the site was using SSL. The main reason for wanting SSL is to verify that the URL is genuine.

This compares with just 8/30 (27%) from our focus group 18 months earlier.

SSL may not "technically" be necessary - but as more people look for it on eComm sites, it makes sense to have it. You need not spend more than $50 to $75 on a certificate. The expensive verisign seals are for large organisations that need a range of additional security and tracking features.

06 Jun 2012, 14:33
#8
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

schoolboy:

18/30 (60%) said that they would not complete a transaction unless the site was using SSL. The main reason for wanting SSL is to verify that the URL is genuine.

This compares with just 8/30 (27%) from our focus group 18 months earlier.

The problem with asking questions of a focus group is that they tend to answer questions according to what they think is the 'right' answer, which in practice is totally different from what they actually do.

The same focus group will probably also tell you that they never click on links contained in emails, and that they never ever visit ######## sites.

schoolboy:

SSL may not "technically" be necessary - but as more people look for it on eComm sites,.

But thats the thing, people DON'T look for sites with SSL when shopping. This is self evident by the sheer volume of people that get scammed by following email links to bogus websites (PayPal, Banks, etc) and entering their logon or CC details.

IF what you say is correct then this type of scam would be a miserable failure, but their ongoing popularity is proof that they are still very effective, and makes a mockery over what people say and what they actually do.

schoolboy:

it makes sense to have it. You need not spend more than $50 to $75 on a certificate. The expensive verisign seals are for large organisations that need a range of additional security and tracking features.

The large organisations require SSL as a part of their iso9001 acceditation. It is usually also an essential part of their IT security policy. None use them for the benefit of their customers, and almost all medium to large businesses that I've dealt with over the years will use self-signed certs for their internal use.

I have no idea what you mean by 'tracking features'. SSL and 'tracking' are as different as chalk and cheese.

Cheers
Rod

06 Jun 2012, 15:55
#9
coolcarpartsonline avatar

coolcarpartsonline

Totally Zenned

Join Date:
Feb 2008
Posts:
1,386
Plugin Contributions:
0

Re: Which SSL certificate should I get?

IT seems that the original poster have gone silence with all these complicated answers.

#RodG
I don't know what kind of sites you shop at but I have been a business owner for 5 years and I have never came across a good website that doesn't have SSL from a known company for that matter such as Verisign, Comodo or even goDaddy.

How are you going to get EV SSL with self signing? It takes on average 2 weeks to complete the EV SSL verification with most SSL retailer so you assuming that SSL has no value is rather ridiculous.

I am not going to give statistics or proof because all my posts are my pure opinion and what I have learned from running a business. So if you think a $100/year on SSL is worthless you shouldn't be in online business. After all this is an Ecommerce forum and all users on here are expected to be selling something online, hence collecting customer data of some sort or accepting payment so having an SSL will be worth it, like I said I have had sites with no SSLs and had customer email or call to yell at me for not having SSL.

With as much competitions as there is on the internet, any logo (such as BBB, Trust and Verified, SSL, Google Trusted Store) may just give you an edge over the small competitors and get you closer to the big league.

06 Jun 2012, 15:55
#10
coolcarpartsonline avatar

coolcarpartsonline

Totally Zenned

Join Date:
Feb 2008
Posts:
1,386
Plugin Contributions:
0

Re: Which SSL certificate should I get?

IT seems that the original poster have gone silence with all these complicated answers.

#RodG
I don't know what kind of sites you shop at but I have been a business owner for 5 years and I have never came across a good website that doesn't have SSL from a known company for that matter such as Verisign, Comodo or even goDaddy.

How are you going to get EV SSL with self signing? It takes on average 2 weeks to complete the EV SSL verification with most SSL retailer so you assuming that SSL has no value is rather ridiculous.

I am not going to give statistics or proof because all my posts are my pure opinion and what I have learned from running a business. So if you think a $100/year on SSL is worthless you shouldn't be in online business. After all this is an Ecommerce forum and all users on here are expected to be selling something online, hence collecting customer data of some sort or accepting payment so having an SSL will be worth it, like I said I have had sites with no SSLs and had customer email or call to yell at me for not having SSL.

With as much competitions as there is on the internet, any logo (such as BBB, Trust and Verified, SSL, Google Trusted Store) may just give you an edge over the small competitors and get you closer to the big league.

06 Jun 2012, 17:36
#11
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

CoolCarPartsOnline:

I have been a business owner for 5 years

Is that all? I've been running my own businesses for well over 30 years. I've been buying and selling online for over 15 years, I was a 'power seller' on ebay for several years. I've also done ~5 years full time study leading an advanced diploma in Network security, so if this is a my ######## is bigger than yours comparison you have a long way to go. :)

CoolCarPartsOnline:

any logo (such as BBB, Trust and Verified, SSL, Google Trusted Store) may just give you an edge

This may well be true, and if so, it merely highlights the point(s) I'm trying to make, one of which is that SSL leads to a FALSE SENSE of Security!

Will people think my site is 'secure' if I create my own 'RodsTrust' logo? (sadly, yes many will)

Take a look at the following 'pop quiz' that I recently posted in another thread.
http://www.zen-cart.com/showthread.php?196978-SSL-Certificate-indicator-not-showing-in-browser-address-bar&p=1130695#post1130695

Simply put, until people understand the purpose of SSL and what it actually does, then it really doesn't provide the security that they think it does.

Take your own site & SSL for example.. If you click on the non existant padlock (that people are told to look for) the first thing you see is a popup that clearly states that the site is run by "unknown". Does that give confidence that the site is legit? Not in MY book it doesn't.

Do the same thing on a PayPal site and the same popup clearly shows that the site is run by "PayPal Pte Ltd". Now THAT instills confidence.

Now check the data fields in your SSL, take note of the "Certificate Basic Constraints" - It reads

Critical
Is not a Certificate Authority

Oh dear. This means this critical information relating to your certificate has been signed by a non authoritive party. Should I trust this CA? Why?

The same critical field from PayPal shows

Critical
Is a Certificate Authority

No problems there... I think I can trust this site.

Based on your SSL certificate I have no more reason to trust your site than I would with a site with no SSL at all, because all it is really telling me is that you have paid for a certificate that appears as though it may be authentic.. It's about as good as showing me a fake drivers licence to prove your identity. Scammers are good at both. <g>

Again, I am NOT saying that you are wrong for using SSL, because it does prevent 'man in the middle' exploits, but that is ALL it does. The problem is, very few people have a clue what this even means, and somewhere along the line people have been made to** assume **that any site with SSL is 'safe', even though nothing could be further from the truth.

It is my job (as a certified Trainer & Assessor in NetWork Security) to teach/demonstrate/show people, both customers and merchants what SSL really means. I am trying to separate the facts from fiction/opinion.

I have little to no interest in whether the use (or non use) of SSL will have any effect on sales, mainly because any such effects are based on the misunderstanding of SSL in the first place (not to mention that that is no statistcal evidence to back up any claims made in this regard).

I appreciate that we have a difference of opinion here, but shouldn't the facts be more important than either of our opinions?

Cheers
Rod.

ps. I have no more to say in this thread, unless someone can provide other/newer/different facts than those I've expounded upon. I'm always willing to update my knowledge, else I'd still believe the world was flat :)

06 Jun 2012, 18:09
#12
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

Oop, I almost forgot this:

CoolCarPartsOnline:

How are you going to get EV SSL with self signing? It takes on average 2 weeks to complete the EV SSL verification with most SSL retailer

EV SSL is almost as worthless as SSL itself. Form wikipedia:

"Certificates issued by a CA under the EV guidelines are not structurally different from other certificates (and hence provide no stronger cryptography than other, cheaper certificates)"

And

"Effectiveness against phishing attacks
In 2006, researchers at Stanford University and Microsoft Research conducted a usability study[8] of the EV display in Internet Explorer 7. Their paper concluded that "participants who received no training in browser security features did not notice the extended validation indicator and did not outperform the control group", whereas "participants who were asked to read the Internet Explorer help file were more likely to classify both real and fake sites as legitimate".

CoolCarPartsOnline:

so you assuming that SSL has no value is rather ridiculous.

I have NEVER made this assumption. SSL is important to prevent 'man in the middle' exploits, but nothing more. I'd much rather be assured that my personal data is encrypted in the merchants database than being assured it is encrypted during transmission, because the database is much more vulnerable and far more likely to be exploited. Do you encrypt your customers personal data?

Lets take this up to the next level... How many merchants are still running Zen V1.3.8? How many of those use SSL? What is the point of them preventing man in the middle attacks with SSL when the hackers have direct access to the store's database, which they can attack at thier leisure (as opposed to a specific instant in time). Security is a multi facetied beast, it's no good locking the front door when the house has the entire back wall missing!

Cheers
Rod

06 Jun 2012, 18:18
#13
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,760
Plugin Contributions:
9

Re: Which SSL certificate should I get?

Rather than two cents worth, I offer two comments.

  1. Some merchant accounts will require SSL for your site even if you process the transaction off-site. Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.
  2. If you purchase an SSL, make sure you are getting a version that will satisfy your merchant account's requirements. SSLv2 is an automatic fail in PCI Compliance. It has been for some time.

Now a question. If one of the main requirements of PCI compliance is to> Encrypt transmission of cardholder data across open, public networkshow can one accomplish this without an SSL?

07 Jun 2012, 02:17
#14
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

dbltoe:

I offer two comments.
Some merchant accounts will require SSL for your site even if you process the transaction off-site.
Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.

This is ridicularly incorrect. What if a merchant doesn't even have a website (or one used as a showcase only, with orders to be made by phone only)?. In the first instance it isn't possible to have SSL on a site that doesn't exist. In the second instance, the customers CC details are never transmittted across the 'net anyway, so SSL is a non player.

dbltoe:

Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.

Yes, it is true that merchant taking orders by phone (and even in a physical store) must be PCI compliant, but this compliance has more to do with how/where the customers data is stored than it does in regards to how the data is obtained.

SSL only comes into play if the CC data is transfered across the internet, and if a store doesn't do thier own CC processing, for example, using PayPal IPN or PayPal Express then the SSL encryption is performed between the customer and the payment processor (not the merchants store), therefore such sites are PCI compliant in this regard. The merchants own site isn't required to have SSL.

If this were NOT the case then surely PayPal itself would be in breach of the PCI requirements?

PayPal Payments Pro is a different ballgame, because the CC details are sent from the customer to the merchant (and then processed via PayPal), therefore SSL is mandatory. Other payment processors work the same way, with the same requirements.

dbltoe:

Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.

I need to be a bit pendatic here. There is no PCI requirement for storing (or transmitting) of customer data. Any such requirements would be store policy, or some other policy (ISO accreditation for example, and even then it becomes more of a side effect of the manadory customer privacy policy, with nothing to do with PCI).
PCI compliance covers the transmission & storage of data that will identify any given customer with his/her CC details. If the CC details aren't stored (on the merchants site) then this is no connection between the CC information and whatever other information a merchant may or may not choose to store on their site.

dbltoe:

Now a question. If one of the main requirements of PCI compliance is to Encrypt transmission of cardholder data across open, public networks how can one accomplish this without an SSL?

Isn't this obvious? By using a Payment processor, such as PayPal where the transmission of the cardholder data is transmitted from the card holder directly to the payment processor and never touches the merchants store in any way, shape or form. The data is enctryped by PayPal's SSL. The stores SSL (if they had one) doesn't come into play.

Incidently, SSL is nowhere near one of the 'main' requirements of PCI,which "provides an actionable framework for developing a robust account data security process - including preventing, detecting and reacting to security incidents". SSL is just an essental but minor component of this framework.

Since most merchants don't do their own CC processing these days then PCI compliance it a complete non issue (but it does highlight good security practices).

Those merchants that DO process CC payments ON THEIR OWN WEBSITE OR BY PHONE, etc, MUST be fully compliant with the PCI requirements, but sadly, many aren't. Sure, they'll comply with the "Encrypt transmission of cardholder data across open, public networks" by purhasing a $12.00 SSL (even though a self signed certificate is also fully compliant), and sure, many of them will do a "PCI compliance scan" of their website to meet the 'prevention' requirements, but that is generally where their compliance ends. Very few merchants (ISO accredited companys excluded) have any policy or plans to cover the detection of 'security incidents' and even less have a policy as to how to react to any such incidents. With no written policy in place these merchants are only partially PCI compliant. Fortunately<?> (for them, but not thier customers) audits are rare, so most get away with this partial compliance - Well, that is until their database gets compromised and all of their stored CC data is released to the public, and THEN they have some serious question to answer, and will be subject to prosecution... In the meantime they are quite happy to live in ignorance because they appear to be compliant because they have SSL and are using a server that has at some time or other been scanned for vulnerabilities.

I didn't spend ~5 years of training just to learn how to set up a firewall, or how encyrption works, it also covered topic as PCI compliance, ISO900x compliance, Government Security policy, and a shop load of other 'boring paperwork' that is essential for someone trained to act in a IT security advisory capacity.

I don't expect to be able to teach all I have learned in these forums, but I can at least put my training into practice by dispelling some of the myths and replacing them with facts. Not to show how 'clever' I am, but for the benefit of those few people that are willing to read and learn.

Nothing I have stated is a 'secret', and every word of it can be verified from many different sources. The hard part is wading through all the information availalbe, most of which is provided by companies that sell SSL certificates, so naturally they only write about what is in thier best interests and make little or no attempt to go any deeper than that, because to do so is going to cost them sales.

By all means, feel free to discuss PCI compliance further (if you must), but please don't make the mistake of thinking that SSL is a 'main part' of compliance because nothing could be further from the truth.

Cheers
Rod (adv dip network security)

07 Jun 2012, 03:30
#15
coolcarpartsonline avatar

coolcarpartsonline

Totally Zenned

Join Date:
Feb 2008
Posts:
1,386
Plugin Contributions:
0

Re: Which SSL certificate should I get?

dbltoe:

Rather than two cents worth, I offer two comments.

  1. Some merchant accounts will require SSL for your site even if you process the transaction off-site. Certainly, if you gather any customer data, PCI compliance is mandatory whether the transaction is made on the site, off-site, by phone, etc.
  1. If you purchase an SSL, make sure you are getting a version that will satisfy your merchant account's requirements. SSLv2 is an automatic fail in PCI Compliance. It has been for some time.

Now a question. If one of the main requirements of PCI compliance is tohow can one accomplish this without an SSL?

I guess you and I are assuming the original poster is going to be running an ecommerce store not just a showcase hence our response.

Maybe for average business owner like myself it will be hard to convince the PCI scanning company or even make a good argument for the case of not having SSL on our website.

I don't accept PayPal on some of my websites so the merchant does require SSL some of the security companies I have only accept data from Secure link. It is much easier for me to pay for something than having to sign my own certificate and show my own made up logo like some people do.

My rule of thumb is what works for my big competitors should work for me. I don't mind paying for services whether they are helping or not.

FYI, the links in my sig don't reflect all my business. I do have EV SSL that will show the company name and the owner is verified just like PayPal. I had to go through so much paper work to verify the company identity with Verisign and Comodo.

Back to the original poster question (Who must of ran away already), invest into an SSL if you are going to accept CC. If you want to only accept PayPal then that is your choice but if you only accept PayPal you are losing on a lot of sales because not everyone has PayPal and most of my customers don't use PayPal on the sites which I accept PayPal on. Plus PayPal rates are much higher than CC and remember if you partner with PayPal they own you and you can only imagine what they can do to you when you do have issues with orders.

07 Jun 2012, 07:29
#16
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Which SSL certificate should I get?

CoolCarPartsOnline:

My rule of thumb is what works for my big competitors should work for me. I don't mind paying for services whether they are helping or not. .

I must've missed your ad on the superbowl? :smartalec:

Cheers
Rod.

29 Jul 2012, 07:05
#17
digitalvision avatar

digitalvision

New Zenner

Join Date:
Aug 2010
Posts:
49
Plugin Contributions:
0

Re: Which SSL certificate should I get?

Great discussion. Not sure who is right or wrong and I'm not going to judge you guys.

When we started in Canada about 3 years ago with zencart 1.3.8a we were using only paypal and no ssl on our website. we sold many orders but not as expected. After we took credit card and SSL order increases to 300% by first week and peoples were loving to pay using credit card and we were surprised that people hates paypal or don;t trust paypal! Some customer even commented we cannot trust paypal by giving our bank access and authorize to take money any time and that is so risky!

Still we were not satisfied and then we took EV SSL and still the same. Then we took BBB accredited business review and revenue increased suddenly. But still people call us even when we are popular on Canada now and ask us are we legit? how long it may take to ship? is the product genuine? why the prices are low? From where it will be ship? too many silly questions we sometimes received for a 20 dollar product!

And there are some peoples who purchase every month over 10,000 and surprisingly never called us except few emails!

So based on our experiences we know that reviews are very important for majority online shoppers. If they know that site is very good and so many happy shoppers they feel comfortable about that store automatically and love to give it a try. and there are still many peoples who will never buy online at any cost instead they will call us and order by phone, no matter what you tell them. lol

So for any serious ecommerce starter I would advise as below.

  • First decide your niche very carefully or you will be sooner frustrated. Make sure you know your business and target before creating online presence.
  • yes of course if it is necessary or no but make sure you get (SSL, BBB review and some other online reviews about your websites), some customer will buy if they see this. So according to CCPO why you would want to miss a sale because of those things.
  • Secure your server and application with professional programmers. As Rod said >>> this is the most important part!
  • Be prepare to professionally market your website and there is cost involved. Do not just think Gooogle will give you buyers...Hell no...Google, Bing and Yahoo even will drop you if they see you are doing good with a high targeted keywords to motivate you for opt in to their adword programs. This is the ugly truth of these search engines today! Believe it or not as we have proof with many sites now. They study you more than you do study them. They want your money and that is as simple as sounds!
  • Try to compete with something new instead popular products.

There are many more...but have to go now...ask me if someone interested to know more....take care for now.