balihr:
Uhm... Does it even matter?
Yes, very much so.
balihr:
I can't believe anyone would say that, and especially not someone as competent and knowledgeable as you...
I also have an advanced diploma in network security, and I STILL say that.
Now ask yourself... What is it that I know that you don't, that makes me stand by my comments?
balihr:
It's an ecommerce site - I'd say using an SSL certificate is highly recommended and should be considered as mandatory.
But WHY?
balihr:
It doesn't help or protect you if you're hacked,
Correct.
balihr:
but it still serves a purpose of not (easily) intercepting communication between 2 computers. I don't think I can make this any simpler. :smile:
Also correct - including the 'Not easily' - And that is problem #1 - It gives a false sense of security.
It is also not exactly easy to intercept communication between 2 computers even WITHOUT SSL. So we now have two 'not easily' to do things - so exactly how much less easy is it? and to repeat your opening question, does it even matter?
balihr:
With customers entering their personal info when creating accounts, I'd say we're talking about some really sensitive information and,
Like their name, address and phone number? Most people have these listed in the phone book, and many have no problem making this info available on social media. Besides, who really gives a fluck if 'Joe Blow' from '123 somestreet' purchases a product from your store?
You're going to write some of these details on the parcel when you mail it anyway. How to you 'secure' this?
balihr:
well, if for no other reason, SSL should be in place to boost customer confidence.
I strongly disagree with this. MOST customers only become aware of SSL when there is a problem with the certificate or when the browser gives scary looking popups warning the some page elements are not secure.
Fact is MOST customers don't give this a second thought. The only people that are fanatical about SSL are the store owners, most of who don't have a freaking clue about SSL anyway (other than it 'is (somehow) good for security'.
In all the years I've been running online stores guess how many times people have reported that my/our site(s) aren't secure - Zero! That's how many.
In all the years I've been buying from online stores, guess how many there have been where I didn't proceed with the purchase because the store didn't have SSL. Yup, exactly ZERO.
balihr:
Next, Google really does prefer sites using SSL certificates over those that don't use it. Put aside content quality and all other factors and compare 2 identical sites - one using SSL and the other not. Which one do you think would come up higher in SERPs? Hint here.
I expressed my opinion of this about a year ago (when Google made this announcement). Alas, far too many people think that Google is the be all and end all of anything related to the Internet, so as much as I'm quite disgusted at Google making this move I will reluctantly acknowledge that this is one teeny reason where SSL may be of benefit to the average online merchant. I do say teeny though because even a year on it is still only a 'very lightweight signal' that pales into insignificance compared to high quality content. This has nothing to do with security - in spite of what Google say.
balihr:
The total cost of en entry-level SSL certificate comes down to around $20 per year (lemme put it this way: 5 cents per day). If one doesn't want to "invest" (if we can even call that an investment) that into (as mentioned earlier) at least a confidence boost, then I'd rather not buy anything from that store...
I Disagree with this too. Firstly, what the flck is an 'entry-level SSL certificate'? How do these differ from a Certificate costing $100 or more? (Answer - There is NO DIFFERENCE, they all use the exact same encryption, assuming current standards of 2048 bit).
Secondly, the total cost of having an SSL enabled site these days is ZERO! Anyone that pays more than that is paying too much.
Thirdly, When SSL was first devised and developed as a security method (Which is what almost everyone thinks when it comes to SSL) there were actually TWO parts to the system. 1) Authentication. 2) Data Encryption. The most important of these is/was the authentication. It once gave people the confidence that the site they were visiting is/was indeed the site they thought they were visiting. This was made possible because there were only a small handful of companies that were able to issue SSL certificates, and before they did so, the businesses requesting/buying the certificates were required to supply documentation to prove they were who they say they were, and pass a few other checks (much like a 'police check').
Needless to say, this was a costly and time consuming process, but it did ensure that the businesses requesting the certificates were who they say they were, and that they were 'legitimate' businesses (and not some 'fly by night').
These days, anyone can get an SSL certificate for little or no cost, with no checks to ensure they are authorised to have and use the certificate, and not even the simplest of checks for authentication. In other words, what was once the most important aspect of SSL (Authentication) is now totally and completely worthless. It is dead simple for someone to obtain and use an SSL certificate for (say) 'paypal.xyz' (Which is a legitimate, but currently unregistered domain name BTW), make a duplicate copy of PayPal's login page, and use this site to capture the paypal login details of unsuspecting victims.
Now, tell me again, exactly what kind of security and confidence does this scenario instill? Think about this for a minute or two. The SSL cert is valid, the site itself appears valid - Yet it is a total scam, and it is going on all around us, right now.
SSL is now a flawed system and if it actually gives people 'confidence' then those people need to be educated, which is exactly what I'm trying to do here. SSL simply cannot be trusted.
SO.... where does that leave SSL? As you correctly implied, it offers an encrypted (not necessarily secured ) data transmission between two computers. Now, ask yourself, how many people will have access to this datastream anyway?
There will be you (the user at one end). Your ISP, then ?????, and at the far end, the hosting provider of the remote site.
Surely you can trust your own ISP, after all, they already have full access to your account, including all emails, so there isn't really much to be gained by encrypting your shopping habits against them.
Same deal at the other end - Surely the merchant can trust their own hosting provider -Heck, they have complete access to your website, the database, emails, and more, so there's no point in encrypting the datastream from them.
So this leaves the ????? - AKA, one or more of the hardware routers owned by various Telecoms companies between the two end points. These routers are housed in physically secure facilities and because they are a critical part of the network infrastructure only a very small handful (perhaps just 2 or 3 people) would be authorised to access them, and you can pretty much guarantee that every access and/or change made would be logged. Perhaps it is these few (highly paid, highly skilled) people that you are 'protecting' yourself from by encrypting the datastream? Why would they risk their jobs and careers to tap into this stream to 'sniff' for whatever it is the typical merchant is selling? They wouldn't.
OK, so now I/we have determined that the only people that can easily tap into the data streams are inherently trustworthy lets consider the people that we are actually trying to 'secure' ourselves against. Exactly who are these people, and why would they want to infiltrate your ISP or one of these Telecoms companies anyway? If they DO manage to do this, what makes your store (or your customer) so 'special'. It seem like a lot of effort to go to when the returns are what? The name, address and phone number of a few customers?
Seriously - Who are these people that you are trying to protect yourself against? If they can infiltrate your ISP or the Telecoms company then I reckon hacking into your store would be a walk in the park, and they'll end up with the exact same information, with a lot less effort and zero risk of of ever being identified. In short, the SSL encryption, like the SSL authentication is basically worthless
All it does is let online store owners 'think' that they are somehow doing something good to 'protect' their customers, even though there is no real threat to begin with.
This is why I occasionally pop the question to those asking about SSL as to why they want it. Most will say that it has something to do with security, others (such as yourself) will put forth various 'reasons' without really thinking it through, but so far, no one has actually come out and said the real reason they want it is because it makes them feel smug and secure and they'll disparage any store that doesn't meet their own mythical standards.
The only time SSL is actually needed, is where it is a requirement imposed by the various Credit Card companies and most of us don't fall into that category.
I make no apologies for this rant or any insinuations made.
SSL is flawed. It's as simple as that.
Cheers
RodG