e-Path:
Hello all,
May I please add to this.
Sure, but only if I can too. :)
e-Path:
It is very rare these days for any ecommerce site not to have an SSL certificate
I actually disagree with this assertion. According to
http://www.netcraft.com/internet-data-mining/ssl-survey/
As of May 2013 less than 50% of the sites polled were using SSL.
e-Path:
In many cases if you don't have an SSL certificate on your ecommerce site you are not permitted to engage in ecommerce activity at all.
Not true. This only applies to sites handing CC related data (PCI-DSS, or Payment Card Industry Data Security Standard)
I'd state that very few eCommerce sites are subject to the PCI requirements on account of the fact that they don't directly handle Credit Card data, but rather, leave this to 3rd part processors such as PayPal and ePath(?), and it is those sites that are subject to the PCI-DSS requirements.
e-Path:
We believe "websmith's" issue is due to his site not having an SSL certificate.
I can't argue this. It's been a while since I looked at the ePath code, but as I recall, ePath are/were handling security in a somewhat unusual manner in that the CC data is collected on the eCommerce site and forwarded to the ePath servers (in which case SSL is a definite legal requirement), rather than the more common method of redirecting the customer to the payment gateway site and entering the data there (meaning that the store itself has no record of any CC related data).
e-Path:
Please allow me to briefly explain ... When data is travelling from a secure site (https) by the POST method to an insecure site (http) some browsers may throw a warning. It is important to understand this is not e-Path causing this, this is the workings of the browser to provide a warning to the user when it sees data about to move from a secure location to an insecure location via POST. When this happens the customer is likely to get spooked and close down their browser thereby not going back to your Zen Cart, thereby Zen Cart does not record the order.
An SSL certificate for your Zen Cart and the issue is eliminated.
On the other hand, sites without SSL enabled will never cause a browser warning either. No SSL = No spooked customers. Ever.
e-Path:
With an SSL certificate you are providing a secure connection when your customers enter their personal information, such as address, email, phone, name etc. This is a positive thing that instils confidence.
That's the 'party line'. In practice, with few exceptions, most people don't take any notice as to whether a site uses SSL or not - That is until the SSL itself start popping up scary warnings that something is amiss.
Almost everyone says they do take note of this, but in reality they don't. With no SSL there are no scary warnings and customers proceed to checkout without a second thought.
Even with SSL and the scary warnings, most people tend to just ignore the warnings anyway and click through to complete the purchase.
e-Path:
You also ensure the customer will not experience any annoying browser warnings popping up that may stop the customer from going back to your Zen Cart - assuming you have correctly configured your site to use SSL of course.
Again, if a site doesn't have SSL in the 1st place there will be no 'annoying warnings' that would spook them in the 1st place.
Which store will you be inclined to shop at - A Non SSL site with no scary warnings, or an SSL enable site with a popup stating that not all elements are secure and that you should proceed with caution?
As a general rule, I feel safer with the store not giving me a scary message.
e-Path:
I believe Websmith is the only customer of ours who does not have an SSL certificate on his site and who is, subsequently, experiencing the issue of his Zen Cart intermittently not recording the order.
I believe you are probably right (but only because I don't have enough information to dispute it) :)
e-Path:
We have been in communication with "websmith" for some time now over this issue and fully understand and appreciate his frustration. We have been very keen to help him, so much so that about three weeks back we offered to pay for and supply an SSL certificate for his own Zen Cart website courtesy of e-Path so this issue could be resolved.
Now, payment gateways don't normally go around supplying free SSL certificates for their customers but in this case "websmith" seems a particularly polite and patient gentleman who obviously truly believes we are causing this issue of his Zen Cart not recording orders at odd times.
With an SSL certificate on the Zen Cart website there is nothing but a smooth process from ordering, making a payment authorisation then to Zen Cart's "thank you" page. Nothing impedes the process.
Thank you
Peter Thwaites
I applaud you for doing to what I'd consider an 'extreme measure' to help solve the issue and pacify a single customer, and I'd be really interested as to whether this does actually solve the problem or not (I have no reason to think it won't), but I do think that SSL on the clients site should be optional in this scenario because there is no technical reason why the end customer would need to enter their CC details on the eCommerce site only to have it forwarded to the gateway for final processing. It is much more secure to have this data entered at the Gateway directly.
Just my 2 cents worth
Cheers
RodG (adv dip network security - and someone that believes SSL generally does more harm than good).
ps. Of all the sites that I maintain, the two with the biggest sales (in excess of $250,000 p/a) don't use SSL, and to the best of my knowledge they haven't lost a single customer as a result. In fact during a 3 month period where one of these sites did use SSL their sales actually dropped quite significantly. I've no real explanation why, and it may have just been a coincidence, but we plan to activate it again soon to see if there is a correlation or not.