Zen Cart Logo
Forums / General Questions / Activate SSL Certificate

Activate SSL Certificate

Views: 2,861

Results 1 to 20 of 37
13 Aug 2015, 9:36 PM
#1
stevenuk avatar

stevenuk

New Zenner

Join Date:
Aug 2015
Location:
United Kingdom East Coast
Posts:
55
Plugin Contributions:
0

Activate SSL Certificate

Hi

I have purchased a SSL Certificate to use on my store and I have been asked by the SSL Issue Company the following and not sure were to start to activate my certificate.

Thank you in advance

The following message below displayed, when I clicked on activate my SSL Certificate in the issuing store?

Important: Please use CSR code with 2048-bit private key to activate your SSL certificate. According to modern security standards using CSR codes with private key size less than 2048 bits is not allowed.

What is a CSR?
The Certificate Signing Request (CSR) is a small, encrypted text file containing information about your organization and the domain you wish to secure. A CSR is what you give to a Certification Authority, to generate your SSL certificate. It is an essential part of obtaining an SSL certificate.

Where can I find instructions on how to generate a CSR?

Thanks Guys.
Stephen

14 Aug 2015, 12:38 AM
#2
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: Activate SSL Certificate

Your hosting account management portal should have this...
You might ask your host

14 Aug 2015, 12:40 AM
#3
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Activate SSL Certificate

StevenUK:

Where can I find instructions on how to generate a CSR?

You create that in your cPanel.

SSL/TLS Manager

The SSL/TLS Manager will allow you to generate SSL certificates, certificate signing requests, and private keys. These are all parts of using SSL to secure your website. SSL allows you to secure pages on your site so that information such as logins, credit card numbers, etc are sent encrypted instead of plain text. It is important to secure your site’s login areas, shopping areas, and other pages where sensitive information could be sent over the web.

14 Aug 2015, 3:53 AM
#4
stevenuk avatar

stevenuk

New Zenner

Join Date:
Aug 2015
Location:
United Kingdom East Coast
Posts:
55
Plugin Contributions:
0

Re: Activate SSL Certificate

Thank you Guys I will try what you suggest. :smile:

16 Aug 2015, 10:13 PM
#5
stevenuk avatar

stevenuk

New Zenner

Join Date:
Aug 2015
Location:
United Kingdom East Coast
Posts:
55
Plugin Contributions:
0

Re: Activate SSL Certificate

Hi Guys

I've just found out that my new hosting company does not support SSL Certificates at this time (Whatever that means) :bangin: As a complete novice to all this does anyone know of a decent Host at reasonable cost, that does support this? I'm in the process of building my store, thankfully my store is not completely up and live, (i.e. just the main front index page) i'm thinking about building my store complete then transfer to another host is this a straightforward process?

Thanks everyone in advance

Steven.

16 Aug 2015, 10:39 PM
#6
frank18 avatar

frank18

Deceased

Join Date:
Nov 2007
Location:
Sunny Coast, Australia
Posts:
3,427
Plugin Contributions:
2

Re: Activate SSL Certificate

StevenUK:

Hi Guys

I've just found out that my new hosting company does not support SSL Certificates at this time (Whatever that means) :bangin: As a complete novice to all this does anyone know of a decent Host at reasonable cost, that does support this? I'm in the process of building my store, thankfully my store is not completely up and live, (i.e. just the main front index page) i'm thinking about building my store complete then transfer to another host is this a straightforward process?

Thanks everyone in advance

Steven.

Scroll to the top of this page and click the button "Services" - you should find a good ZC savvy host there.

16 Aug 2015, 10:48 PM
#7
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

StevenUK:

Hi Guys

I've just found out that my new hosting company does not support SSL Certificates at this time
:shocking: A "hosting company" that doesn't support SSL certificates? Who's your host - some neighbor's kid with a server in grandma's basement? Seriously, what kind of host doesn't support SSL certificates? That was acceptable back in the early 90s, but nowadays even the dead-simple sites use SSL since it can be purchased for like $5 per year...

As a complete novice to all this does anyone know of a decent Host at reasonable cost, that does support this?
This is not something that's usually allowed to be discussed here, but here are a few friendly suggestions: look for a UK based host, make sure they have 24/7 support and try to get an account with cPanel since it's probably the simplest for a novice. From my experience, I'd suggest staying faaaar away from HeartInternet and 1and1 when it comes to hosting. Hosting recommendations are not allowed here, but you're welcome to PM me and I'll send you links to 2 UK hosts that I quite like.

I'm in the process of building my store, thankfully my store is not completely up and live, (i.e. just the main front index page) i'm thinking about building my store complete then transfer to another host is this a straightforward process?
It's a fairly simple process when you're used to it, but A LOT of people struggle with it. Since you're still building your store, I believe it would probably be best to move to a new host and do any changes there. It might save you some headaches later on when the store is finished...

16 Aug 2015, 10:56 PM
#8
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

StevenUK:

As a complete novice to all this does anyone know of a decent Host at reasonable cost, that does support this?

Personally, I think a more important question is why do you think you need SSL?

Do you even know what it is and what it does? Do you know what it doesn't do?

If you can't answer these questions then you probably don't need it.

If your answer is 'it has something to do with security' (or something similarly vague) you probably don't need it.

Cheers
RodG

16 Aug 2015, 11:19 PM
#9
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

Do you even know what it is and what it does? Do you know what it doesn't do?
Uhm... Does it even matter?

If you can't answer these questions then you probably don't need it.
I can't believe anyone would say that, and especially not someone as competent and knowledgeable as you...

It's an ecommerce site - I'd say using an SSL certificate is highly recommended and should be considered as mandatory. It doesn't help or protect you if you're hacked, but it still serves a purpose of not (easily) intercepting communication between 2 computers. I don't think I can make this any simpler. :smile:
With customers entering their personal info when creating accounts, I'd say we're talking about some really sensitive information and, well, if for no other reason, SSL should be in place to boost customer confidence.

Next, Google really does prefer sites using SSL certificates over those that don't use it. Put aside content quality and all other factors and compare 2 identical sites - one using SSL and the other not. Which one do you think would come up higher in SERPs? Hint here.

The total cost of en entry-level SSL certificate comes down to around $20 per year (lemme put it this way: 5 cents per day). If one doesn't want to "invest" (if we can even call that an investment) that into (as mentioned earlier) at least a confidence boost, then I'd rather not buy anything from that store...

16 Aug 2015, 11:41 PM
#10
stevenuk avatar

stevenuk

New Zenner

Join Date:
Aug 2015
Location:
United Kingdom East Coast
Posts:
55
Plugin Contributions:
0

Re: Activate SSL Certificate

Thank you everyone for your help it's much appreciated :smile:

16 Aug 2015, 11:44 PM
#11
stevenuk avatar

stevenuk

New Zenner

Join Date:
Aug 2015
Location:
United Kingdom East Coast
Posts:
55
Plugin Contributions:
0

Re: Activate SSL Certificate

RodG:

Personally, I think a more important question is why do you think you need SSL?

Do you even know what it is and what it does? Do you know what it doesn't do?

If you can't answer these questions then you probably don't need it.

If your answer is 'it has something to do with security' (or something similarly vague) you probably don't need it.

Cheers
RodG

In answer to your post I think an SSL certificate is a must to protect your customers

17 Aug 2015, 12:22 AM
#12
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

StevenUK:

In answer to your post I think an SSL certificate is a must to protect your customers

Protect them from what?

Where, when and how does it do this?

Fact SSL doesn't do what most people think it does. It is NOT some kind of 'magic bullet'.

Most people DON'T NEED IT. It has as many drawbacks as it has benefits.

Cheers
RodG

17 Aug 2015, 4:58 AM
#13
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

balihr:

Uhm... Does it even matter?

Yes, very much so.

balihr:

I can't believe anyone would say that, and especially not someone as competent and knowledgeable as you...

I also have an advanced diploma in network security, and I STILL say that.

Now ask yourself... What is it that I know that you don't, that makes me stand by my comments?

balihr:

It's an ecommerce site - I'd say using an SSL certificate is highly recommended and should be considered as mandatory.

But WHY?

balihr:

It doesn't help or protect you if you're hacked,

Correct.

balihr:

but it still serves a purpose of not (easily) intercepting communication between 2 computers. I don't think I can make this any simpler. :smile:

Also correct - including the 'Not easily' - And that is problem #1 - It gives a false sense of security.

It is also not exactly easy to intercept communication between 2 computers even WITHOUT SSL. So we now have two 'not easily' to do things - so exactly how much less easy is it? and to repeat your opening question, does it even matter?

balihr:

With customers entering their personal info when creating accounts, I'd say we're talking about some really sensitive information and,

Like their name, address and phone number? Most people have these listed in the phone book, and many have no problem making this info available on social media. Besides, who really gives a fluck if 'Joe Blow' from '123 somestreet' purchases a product from your store?

You're going to write some of these details on the parcel when you mail it anyway. How to you 'secure' this?

balihr:

well, if for no other reason, SSL should be in place to boost customer confidence.

I strongly disagree with this. MOST customers only become aware of SSL when there is a problem with the certificate or when the browser gives scary looking popups warning the some page elements are not secure.

Fact is MOST customers don't give this a second thought. The only people that are fanatical about SSL are the store owners, most of who don't have a freaking clue about SSL anyway (other than it 'is (somehow) good for security'.

In all the years I've been running online stores guess how many times people have reported that my/our site(s) aren't secure - Zero! That's how many.

In all the years I've been buying from online stores, guess how many there have been where I didn't proceed with the purchase because the store didn't have SSL. Yup, exactly ZERO.

balihr:

Next, Google really does prefer sites using SSL certificates over those that don't use it. Put aside content quality and all other factors and compare 2 identical sites - one using SSL and the other not. Which one do you think would come up higher in SERPs? Hint here.

I expressed my opinion of this about a year ago (when Google made this announcement). Alas, far too many people think that Google is the be all and end all of anything related to the Internet, so as much as I'm quite disgusted at Google making this move I will reluctantly acknowledge that this is one teeny reason where SSL may be of benefit to the average online merchant. I do say teeny though because even a year on it is still only a 'very lightweight signal' that pales into insignificance compared to high quality content. This has nothing to do with security - in spite of what Google say.

balihr:

The total cost of en entry-level SSL certificate comes down to around $20 per year (lemme put it this way: 5 cents per day). If one doesn't want to "invest" (if we can even call that an investment) that into (as mentioned earlier) at least a confidence boost, then I'd rather not buy anything from that store...

I Disagree with this too. Firstly, what the flck is an 'entry-level SSL certificate'? How do these differ from a Certificate costing $100 or more? (Answer - There is NO DIFFERENCE, they all use the exact same encryption, assuming current standards of 2048 bit).
Secondly, the total cost of having an SSL enabled site these days is ZERO! Anyone that pays more than that is paying too much.

Thirdly, When SSL was first devised and developed as a security method (Which is what almost everyone thinks when it comes to SSL) there were actually TWO parts to the system. 1) Authentication. 2) Data Encryption. The most important of these is/was the authentication. It once gave people the confidence that the site they were visiting is/was indeed the site they thought they were visiting. This was made possible because there were only a small handful of companies that were able to issue SSL certificates, and before they did so, the businesses requesting/buying the certificates were required to supply documentation to prove they were who they say they were, and pass a few other checks (much like a 'police check').
Needless to say, this was a costly and time consuming process, but it did ensure that the businesses requesting the certificates were who they say they were, and that they were 'legitimate' businesses (and not some 'fly by night').

These days, anyone can get an SSL certificate for little or no cost, with no checks to ensure they are authorised to have and use the certificate, and not even the simplest of checks for authentication. In other words, what was once the most important aspect of SSL (Authentication) is now totally and completely worthless. It is dead simple for someone to obtain and use an SSL certificate for (say) 'paypal.xyz' (Which is a legitimate, but currently unregistered domain name BTW), make a duplicate copy of PayPal's login page, and use this site to capture the paypal login details of unsuspecting victims.
Now, tell me again, exactly what kind of security and confidence does this scenario instill? Think about this for a minute or two. The SSL cert is valid, the site itself appears valid - Yet it is a total scam, and it is going on all around us, right now.

SSL is now a flawed system and if it actually gives people 'confidence' then those people need to be educated, which is exactly what I'm trying to do here. SSL simply cannot be trusted.

SO.... where does that leave SSL? As you correctly implied, it offers an encrypted (not necessarily secured ) data transmission between two computers. Now, ask yourself, how many people will have access to this datastream anyway?
There will be you (the user at one end). Your ISP, then ?????, and at the far end, the hosting provider of the remote site.

Surely you can trust your own ISP, after all, they already have full access to your account, including all emails, so there isn't really much to be gained by encrypting your shopping habits against them.
Same deal at the other end - Surely the merchant can trust their own hosting provider -Heck, they have complete access to your website, the database, emails, and more, so there's no point in encrypting the datastream from them.

So this leaves the ????? - AKA, one or more of the hardware routers owned by various Telecoms companies between the two end points. These routers are housed in physically secure facilities and because they are a critical part of the network infrastructure only a very small handful (perhaps just 2 or 3 people) would be authorised to access them, and you can pretty much guarantee that every access and/or change made would be logged. Perhaps it is these few (highly paid, highly skilled) people that you are 'protecting' yourself from by encrypting the datastream? Why would they risk their jobs and careers to tap into this stream to 'sniff' for whatever it is the typical merchant is selling? They wouldn't.

OK, so now I/we have determined that the only people that can easily tap into the data streams are inherently trustworthy lets consider the people that we are actually trying to 'secure' ourselves against. Exactly who are these people, and why would they want to infiltrate your ISP or one of these Telecoms companies anyway? If they DO manage to do this, what makes your store (or your customer) so 'special'. It seem like a lot of effort to go to when the returns are what? The name, address and phone number of a few customers?

Seriously - Who are these people that you are trying to protect yourself against? If they can infiltrate your ISP or the Telecoms company then I reckon hacking into your store would be a walk in the park, and they'll end up with the exact same information, with a lot less effort and zero risk of of ever being identified. In short, the SSL encryption, like the SSL authentication is basically worthless

All it does is let online store owners 'think' that they are somehow doing something good to 'protect' their customers, even though there is no real threat to begin with.

This is why I occasionally pop the question to those asking about SSL as to why they want it. Most will say that it has something to do with security, others (such as yourself) will put forth various 'reasons' without really thinking it through, but so far, no one has actually come out and said the real reason they want it is because it makes them feel smug and secure and they'll disparage any store that doesn't meet their own mythical standards.

The only time SSL is actually needed, is where it is a requirement imposed by the various Credit Card companies and most of us don't fall into that category.

I make no apologies for this rant or any insinuations made.

SSL is flawed. It's as simple as that.

Cheers
RodG

17 Aug 2015, 1:57 PM
#14
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

I strongly disagree with this. MOST customers only become aware of SSL when there is a problem with the certificate or when the browser gives scary looking popups warning the some page elements are not secure.

Fact is MOST customers don't give this a second thought. The only people that are fanatical about SSL are the store owners, most of who don't have a freaking clue about SSL anyway (other than it 'is (somehow) good for security'.

And I strongly disagree with this. If you're basing this on personal experience with your own site, then I must ask how you compared? First of all, your site offers an incredibly unique product/service and there's no real competitor to what you're offering. There may be some, but nowhere near as good, stable, reliable and accurate as your product so your customers don't really have much choice but to use it with or without SSL.

Now stop for a minute and try to think as an average online shopper. Or as a small merchant trying to run an online business.

With everyday sites that have lots of competition, every tiny bit matters. If I had to choose between two sites with identical prices, where only one of them is using SSL, I'd opt for the one using SSL thinking something like "ok, these guys do care about my privacy...". It's absolutely irrelevant whether it will REALLY matter or not, it's just the feeling. False or not, the majority of people like to "feel safe and protected".

As the saying goes - both the rich and the poor get sad and cry, but I'd rather cry in a Rolls Royce than on the back of a donkey...

I expressed my opinion of this about a year ago (when Google made this announcement). Alas, far too many people think that Google is the be all and end all of anything related to the Internet, so as much as I'm quite disgusted at Google making this move I will reluctantly acknowledge that this is one teeny reason where SSL may be of benefit to the average online merchant. I do say teeny though because even a year on it is still only a 'very lightweight signal' that pales into insignificance compared to high quality content. This has nothing to do with security - in spite of what Google say.
A teeny meeny tiny signal. Yes. Just like local server location. And people will rather be hosted with some host in their country that has a 10 Mbps port limit, than opt for an offshore host with a 500 Mbps port speed... But, fact remains - it's a factor. I'd rather have (some imaginary score) 55/100 with Google, than 52/100. That tiny difference can make a major difference for a small merchant like me...

I Disagree with this too. Firstly, what the flck is an 'entry-level SSL certificate'? ...cut the tech stuff...
All it does is let online store owners 'think' that they are somehow doing something good to 'protect' their customers, even though there is no real threat to begin with.
From a tech standpoint, you're absolutely right and I never argued THAT. What I do argue is the fact that most online shoppers do NOT come with an advanced diploma in network security and they have no clue about what SSL is, nor how it works. They just "know" it's something to protect them and to make their purchase safe. They feel better shopping there. (Same reason why for example fashion stores in malls have those perfumes to scent up the entire shop - they just need you to feel better while you're there so you spend spend spend.) I put "know" in quotation marks for a reason. They "learned" about it after reading some 10-lines text in their local newspaper, or their friend posted a link on Facebook or maybe they just heard about it somewhere and now it sounds familiar. For a merchant, that's absolutely irrelevant, as long as it helps to convert a visitor into a customer. In most cases it's not a deciding factor, but it can help...

This is why I occasionally pop the question to those asking about SSL as to why they want it. Most will say that it has something to do with security, others (such as yourself) will put forth various 'reasons' without really thinking it through, but so far, no one has actually come out and said the real reason they want it is because it makes them feel smug and secure and they'll disparage any store that doesn't meet their own mythical standards.
Ask me why I want it... Simple - just to improve User Experience (UX). Same reason why I want a responsive site - my old site did work on mobile devices and all the info was there and you could read it if you wanted to, but UX matters and I want/need/must-have a responsive site to please visitors browsing it with just about any mobile device...

The only time SSL is actually needed, is where it is a requirement imposed by the various Credit Card companies and most of us don't fall into that category.
Needed... Why are you so focused on that word? How about wanted? In my case, I simply wanted to improve User Experience on my site (and guess what, it's not even ecommerce). It costs me $10 per year. I spend more money on coffee in a week... Why would you challenge me spending that money on something that can potentially only help my business? Are there many (or any) downsides to using an SSL certificate? What do I lose if I have it?

And, I've been saving this for last... 2 years ago one of my clients was asking me about his high cart abandonment rate (he's in a very competitive industry). I suggested installing an SSL certificate (opted for one with a dynamic seal) and we placed a noticeable "secure connection" line right below the header that was showing up on https pages... No other UX changes were made to the site. Approx 2 months later he reported a 12% reduced abandonment rate (based on HIS stats, not mine). At that time he was doing around GBP 50-70k per month. A 12% difference was very much welcome... As usual, it all came down to making an impression and "convincing" the visitor to continue through checkout...
Perhaps AU isn't THAT obsessed with SSL, but UK sure was and still is.

At the end of the day, I think the main question is - can having an SSL cert help a website owner OR is it a bad idea to have it? I'd opt for the first, and considering the "investment" involved, I dare say it's a must-have... But, you're welcome to claim otherwise...

17 Aug 2015, 7:54 PM
#15
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

Hi Balihr,

In the course of just a single message exchange you've gone from this:

balihr:

I can't believe anyone would say that, and especially not someone as competent and knowledgeable as you...

It's an ecommerce site - I'd say using an SSL certificate is highly recommended and should be considered as mandatory.


With customers entering their personal info when creating accounts, I'd say we're talking about some really sensitive information


Ask me why I want it... Simple - just to improve User Experience (UX).

To this:

balihr:

At the end of the day, I think the main question is - can having an SSL cert help a website owner OR is it a bad idea to have it? I'd opt for the first

I'll consider this as a lesson learned.

No longer are you recommending that "it should be considered as mandatory".
No longer are you considering security/sensitivity as being a significant reason for SSL.

You have 'reduced' the entire 'debate' down to a matter 'User Experience' and 'can it help'.

I have to disagree about the 'user experience' because that doesn't change unless there is a problem with the SSL implementation, which actually gives a bad user experience - something we don't want.

With no SSL, or a valid SSL install, the 'user experience' remains the same. The user 'perception' is a different matter, but that argument could go on forever.

As for the 'can it help' - This comes down to two things - 1) The user perception - as in do they really take any notice if a given site is using SSL or not. (see comment above)) and 2) Can it affect the sites' Google rankings - Perhaps, but if so, this is only due to changes they made just on a year ago, and it is such a 'lightweight' ranking factor, this, much like the eternal 'Friendly URL' debates can also go on forever with no resolve. IOW, 12 months ago, this wasn't even a factor to be considered.

As for your 'final' comment - "is it a bad idea to have it"? My response to this is Generally speaking, no it isn't. It is only bad when there is a problem with its implementation that causes scary looking warnings from the web browsers that not all the page content is secure. This kind of warnings scare far more people away from a site than a site with no SSL at all ever would.

This brings me back to my apparent dislike of SSL, in that for most people (especially store owners) it is considered essential for 'security' as though it were some kind of 'magic bullet' - This, as I have always stated, gives a false sense of security, and as a Network Security consultant (seriously, I consult to quite a few large organisations & businesses) there is nothing less secure than a false sense of being secure - it generally means that real security measures and issues get ignored and/or overlooked. SSL is just one of many layers of security albeit a rather insignificant one when looking at the big picture.
Those without the 'education' that I, and most other security consultants provide, usually consider SSL as being perhaps the most significant layer of security rather than the least significant.

You may now argue that I haven't changed your opinion on this is any way, shape or form, but your 1st round of comments, and your current comments indicate otherwise. :-) My 'work' is done.

My only hope now is that others reading this thread have a better understanding of what SSL actual is/does, and what it isn't and doesn't do.

It is not, and was not my intent to single you (or any other individual out) for this 'lesson'.

Cheers
RodG


17 Aug 2015, 9:36 PM
#16
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

Hi again balihr

This second response is because I don't think the comments/response are directly relevant to what SSL is/isn't so and I don't wish to cloud that aspect of the discussion.

balihr:

And I strongly disagree with this. If you're basing this on personal experience with your own site,

Heck no. My own site is so insignificant and miniscule that it would be useless for observations in regards to customer behaviour.

balihr:

then I must ask how you compared?

Mostly from a LOT of research, backup up by a number of 'experiments' and 'trials' on some of our clients sites and stores (with their permission). I/We currently host and/or maintain almost 100 sites, 90% of them using eCommerce.

balihr:

First of all, your site offers an incredibly unique product/service and there's no real competitor to what you're offering.

Agreed - especially if you are referring to the ozpost or shop.vcseb.com site and have only looked at it in the last few days as there are now only seven 'products' in that particular store.
The other few hundred products (mostly phone covers) have been relocated to our 'new' store at market.vcsweb.com

Even this store isn't of much use for customer behaviour observations though - The products are years old, and we'd be pushing to get one sale a month. In it's heyday we were making 20-30 sales per day. The only reason we even keep a live store (with physical products) these days is for development purposes.

balihr:

Now stop for a minute and try to think as an average online shopper. Or as a small merchant trying to run an online business.

With everyday sites that have lots of competition, every tiny bit matters. If I had to choose between two sites with identical prices, where only one of them is using SSL, I'd opt for the one using SSL thinking something like "ok, these guys do care about my privacy...". It's absolutely irrelevant whether it will REALLY matter or not, it's just the feeling. False or not, the majority of people like to "feel safe and protected".

I don't dispute your argument or your logic, in fact I fully agree with it - BUT research and testing indicate that this is NOT what its like in the real world. People may say and think these things, but at the end of the day they either don't look or don't care. This is one of the reasons why so many everyday people fall victim of scams and scammers.

balihr:

And people will rather be hosted with some host in their country that has a 10 Mbps port limit, than opt for an offshore host with a 500 Mbps port speed...

Yup, so true. Many people are idiots. They let their perceptions get in the way of facts.

balihr:

But, fact remains - it's a factor. I'd rather have (some imaginary score) 55/100 with Google, than 52/100. That tiny difference can make a major difference for a small merchant like me...

I understand and agree with what you are saying - but I must add that only a fool will develop and run an online store that depends on Google for its survival. I've seen (and experienced) too many horror stories about businesses closing down as a direct result of their dependence on Google and its ever changing ranking factors.

balihr:

They just "know" it's something to protect them and to make their purchase safe. They feel better shopping there.

You asked how I compared (human behaviour). It is now my turn to ask you the same question. What evidence do you have to support this claim?
Logic and common sense will dictate that this is a true and valid claim. Research and experimentation indicates otherwise.

balihr:

Needed... Why are you so focused on that word?

Because almost every online merchant is under the impression that SSL is needed. SOME of them will even go as far to say it "*should be considered as mandatory". <grin> *

balihr:

How about wanted?

I'd still ask them the same question as to why they want it. Yes, it is entirely up to them, and none of my business really - but if/when they say they want it 'for security' I feel obligated to inform them of the facts. That IS my business (literally).

balihr:

In my case, I simply wanted to improve User Experience on my site (and guess what, it's not even ecommerce). It costs me $10 per year.

I still don't see how it improves the user experience. It may change the perception that people have about the site, but the actual experience is exactly the same both with and without SSL (Unless poorly implemented, which gives a BAD experience).

balihr:

Why would you challenge me spending that money on something that can potentially only help my business?

I'm not challenging you on what you choose to do (or not do) to potential help your business. That is of no concern to me.

If I AM challenging you in any way, it is that you are telling other merchants that "*using an SSL certificate is highly recommended and should be considered as mandatory".

*I could be asking why you are challenging me when I say that I don't recommend SSL (for most merchants) and that their is no valid reason why it should be mandatory.

balihr:

Are there many (or any) downsides to using an SSL certificate? What do I lose if I have it?

I'm glad you asked. Yes, there are downsides to it.

  1. There is the cost factor - OK, this is quite insignificant these days, but that wasn't always the case, but nonethless there is a cost - and paraphrasing your own words 'every little bit counts'

  2. There is the 'overhead' of encrypting and decrypting the data. This takes time and memory. Again, neither of these are as significant as they once were (especially on the server side of things), but there are still many people using a dialup connection and the additional data caused by encryption can/does have a noticeable affect on page loading times.
    Not all customers have gigabytes of memory in their systems, and this can be quickly 'eaten up' by the decryption process (to the extent of some data being temporarily written to disk. Again, this causes performance issues.

  3. Not all web browsers support encryption. OK, there are very few of these still being used, but they do still exist, so SSL prevents these people from accessing the site.

  4. When poorly implemented, typically caused by not all content being served over HTTPS, the browser alerts scare people away from completing a purchase, and causes them to shop elsewhere - This never happens on a site without SSL.

... So there you go. at least 4 downsides that you almost certainly hadn't even considered (until now). If you had, you wouldn't have asked the question.

balihr:

And, I've been saving this for last... 2 years ago one of my clients was asking me about his high cart abandonment rate (he's in a very competitive industry). I suggested installing an SSL certificate (opted for one with a dynamic seal) and we placed a noticeable "secure connection" line right below the header that was showing up on https pages... No other UX changes were made to the site. Approx 2 months later he reported a 12% reduced abandonment rate (based on HIS stats, not mine). At that time he was doing around GBP 50-70k per month. A 12% difference was very much welcome... As usual, it all came down to making an impression and "convincing" the visitor to continue through checkout...

Aha. The good old anecdotal 'evidence'. I have one of those too. One of the most successful sites that I host/maintain (7 years old) is pulling in an average of $10,000 sales per month. Until a little over 12months ago, this site had never used SSL - and then some 'expert' got to them and convinced them that they'd do even better if they had SSL, so after given them my 'lesson' they still insisted it was something they needed - I gave it to them - In the 3 months that followed, their sales dropped to under $8000p/m - worst figures in 3 years. As no other changes had been made I requested they 'humour' me in disabling the SSL. Result - Their sales increased back to pre SSL days. Four months after this I/we decided to run another experiment and re-enabled the SSL (figuring it may have just been a coincidence) - Well fck me dead - once agian their sales actually dropped. We let this go on 2 two months before disabling the SSL again, which again saw an increase in sales.
I wanted to tun this little 'experiment' again last month (thinking that it may be related to the season), but the client denied my request - as far as he was concerned, and based solely on the sales figures with and with SSL, he'd already lost over $5k in sales with the SSL enabled. He was unwilling to allow further experiments (understandable so), as such, they no longer have it enabled (for the store front). I did convince them that enabling it for the Admin functions was a wise idea though).

It is also worth mentioning that the second busiest store that I host/maintain (average $200k per year) doesn't use SSL either.
As for the other 80 or so eCommerce sites under my control their sales are so low (in comparison) that I'm not seeing any significant difference between those with SSL and those without.

balihr:

Perhaps AU isn't THAT obsessed with SSL, but UK sure was and still is.

I shall consider this to be an ad hominem comment.

Anyway, at the end of the day, I actually agree with almost every comment you've made. The "problem" is that the facts tend to indicate that we are both wrong.

I don't know about you, but I find this quite unsettling.

Cheers
RodG

17 Aug 2015, 11:06 PM
#17
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

In the course of just a single message exchange you've gone from this:

To this:

I'll consider this as a lesson learned.

No longer are you recommending that "it should be considered as mandatory".
[COLOR=#333333]No longer are you considering security/sensitivity as being a significant reason for SSL.
Oh, c'mon, don't twist my words... I never, not once, said that SSL is required for security purposes. Have I? You even cut off the second half of my statement where I said "if for no other reason, then to boost customer confidence". Which is basically UX.

Considered as mandatory? Yes. For security reasons? Heck no, I didn't say that.

You have 'reduced' the entire 'debate' down to a matter 'User Experience' and 'can it help'.
Yes, I have. Based on your comments, it's easy to conclude that you advise against it because it makes no difference for security. Put security aside - does it (or can it) help overall? Because, most merchants will happily take that one extra step if it can help.

I have to disagree about the 'user experience' because that doesn't change unless there is a problem with the SSL implementation, which actually gives a bad user experience - something we don't want.
Unless there is a problem... Yeah, well, poor coding can cause tons of other problems as well.

As for the 'can it help' - This comes down to two things - 1) The user perception - as in do they really take any notice if a given site is using SSL or not. (see comment above)) and 2) Can it affect the sites' Google rankings - Perhaps, but if so, this is only due to changes they made just on a year ago, and it is such a 'lightweight' ranking factor, this, much like the eternal 'Friendly URL' debates can also go on forever with no resolve. IOW, 12 months ago, this wasn't even a factor to be considered.
12 months ago my kid was spending his time at the playground. Now he goes to school. Things change. Forget about "12 months ago it was like that..." - it's the worst argument one can pull up. It's like talking with the old people who go like "oh, it was not like this when I was young, during World War 2...". Fact remains - it's a factor TODAY and I live today and for tomorrow, not for 12 months ago. I couldn't care less what it was back then, or in 2005 or in the 80s...

As for your 'final' comment - "is it a bad idea to have it"? My response to this is Generally speaking, no it isn't. It is only bad when there is a problem with its implementation that causes scary looking warnings from the web browsers that not all the page content is secure. This kind of warnings scare far more people away from a site than a site with no SSL at all ever would.
Just like poor coding. Or bad server. Or loading unoptimized images (we've all seen and are still seeing a product_listing page with 20-30 products each loading a 3000x4000 px thumbnail...). Waiting 30-40 seconds to load a page will also scare people away. We're not discussing poor coding here, we should be assuming the site was built properly and there are no coding errors. I mean, it's like saying "yeah, a Mercedes is a really great car, but if I take the front left wheel off and go drive it, I don't quite enjoy the experience..."

This brings me back to my apparent dislike of SSL, in that for most people (especially store owners) it is considered essential for 'security' as though it were some kind of 'magic bullet' - This, as I have always stated, gives a false sense of security, and as a Network Security consultant (seriously, I consult to quite a few large organisations & businesses) there is nothing less secure than a false sense of being secure - it generally means that real security measures and issues get ignored and/or overlooked. SSL is just one of many layers of security albeit a rather insignificant one when looking at the big picture.
Those without the 'education' that I, and most other security consultants provide, usually consider SSL as being perhaps the most significant layer of security rather than the least significant.
You can dislike it or hate it, but that still doesn't justify talking people out of it when there's potential benefit. You could've put it all down in a single line of text (instead of asking the why question) - something like "just keep in mind having an SSL certificate has absolutely nothing with your site's security or safety, it's more of an aesthetic purpose... just sayin..." :wink:

You may now argue that I haven't changed your opinion on this is any way, shape or form, but your 1st round of comments, and your current comments indicate otherwise. :-) My 'work' is done.
Although I still claim my first round of comments weren't focused on SSL for security, but for the general idea and UX, OK, so be it...

17 Aug 2015, 11:17 PM
#18
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

balihr:

Considered as mandatory? Yes. For security reasons? Heck no, I didn't say that.

So why DO you consider it mandatory?

17 Aug 2015, 11:26 PM
#19
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

balihr

I entered this thread with the following reply to the OP

Personally, I think a more important question is why do you think you need SSL?

Do you even know what it is and what it does? Do you know what it doesn't do?

If you can't answer these questions then you probably don't need it.

If your answer is 'it has something to do with security' (or something similarly vague) you probably don't need it.

You responded with


I can't believe anyone would say that, and especially not someone as competent and knowledgeable as you...

It's an ecommerce site - I'd say using an SSL certificate is highly recommended and should be considered as mandatory. It doesn't help or protect you if you're hacked, but it still serves a purpose of not (easily) intercepting communication between 2 computers. I don't think I can make this any simpler.
------------------------------------------------------

You NOW state

"Oh, c'mon, don't twist my words... I never, not once, said that SSL is required for security purposes. Have I?"

Forgive me for getting it wrong - I thought it was a fair assumption that your original words were related to nothing BUT security purposes.

I don't think I can make this any simpler.

EOT.

18 Aug 2015, 12:22 AM
#20
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

I understand and agree with what you are saying - but I must add that only a fool will develop and run an online store that depends on Google for its survival. I've seen (and experienced) too many horror stories about businesses closing down as a direct result of their dependence on Google and its ever changing ranking factors.
Totally agreed. But then again, how long do you think the site will stay in business if the owner doesn't bow at Google and other search engines? (since I usually deal with non tech-savy people, I tend to say Google although I'm referring to all search engines) Yes, they ARE changing ranking factors ALL THE TIME - does that mean one should say "f**k Google, I ain't doin any changes they are asking for". It's like saying SEO is stupid because they keep asking for new stuff and come up with new factors... You don't fight the beast, it's a war you'll never win. If you decide you don't care about Google and you will not conform to their requirements, it's OK. I mean, Don Quijote made a similar decision and he was very happy in his life... :wink:

You asked how I compared (human behaviour). It is now my turn to ask you the same question. What evidence do you have to support this claim?
Logic and common sense will dictate that this is a true and valid claim. Research and experimentation indicates otherwise.
I don't do analysis and statistics and don't have first-hand experience. I read about it from various sources, hoping the info is correct. But, if 20 sources say the same thing, and only one claims otherwise, I tend to go with the flow...
There's a joke about a guy driving on the highway and listening to the radio. Suddenly, the speaker interrupts the program with an important announcement warning drivers on that highway about a crazy guy driving in the wrong direction. And that guy looks at the radio and says "you idiot, it's not just one driver, it's hundreds..."
Anyway... Here (don't forget to scroll down to the second answer as well). Here.

Because almost every online merchant is under the impression that SSL is needed. SOME of them will even go as far to say it "*should be considered as mandatory". <grin> *
Yes, some will say that. And some might even go further and say AJAX is a good thing and helps UX (although it didn't exist 10 years ago :P) so adding AJAX features should also be considered mandatory. And, if I'm gonna go wild and off the hook, I might even say that ANYTHING that can help a merchant get extra sales should be considered mandatory...

I'd still ask them the same question as to why they want it. Yes, it is entirely up to them, and none of my business really - but if/when they say they want it 'for security' I feel obligated to inform them of the facts. That IS my business (literally).
Again, something you could've easily handled in a singe-line statement, with a link or two to external sites backing your claims for those who want to learn more. And then go into debates and explanations IF someone asks for it. Or if another catfish (like myself) bites.

I still don't see how it improves the user experience. It may change the perception that people have about the site, but the actual experience is exactly the same both with and without SSL (Unless poorly implemented, which gives a BAD experience).
Perception, experience, feel... Doesn't matter what you call it. There are numerous marketing studies about what kind of scent makes you spend more in a store, what light color will get you to spend more, there are even studies on what size the ceramic floor tiles should be in supermarkets to get you to spend more... Same goes for SSL - if it helps generate a sale, then yes, it should be considered mandatory.

If I AM challenging you in any way, it is that you are telling other merchants that "[I]using an SSL certificate is highly recommended and should be considered as mandatory".
See above.

I'm glad you asked. Yes, there are downsides to it.

  1. There is the cost factor - OK, this is quite insignificant these days, but that wasn't always the case, but nonethless there is a cost - and paraphrasing your own words 'every little bit counts'
    These days? Don't go back in the past. 20-30 years ago cell phones were reserved for the wealthiest and those who really need it. Now every kid has one.
    What cost factor?! $20-ish per year? I spend $2-$3 every bloody day on coffee alone. I spend 5 times more money per year on toilet paper (yes, to wipe my a**). You're considering this as cost? Seriously?
  1. There is the 'overhead' of encrypting and decrypting the data. This takes time and memory. Again, neither of these are as significant as they once were (especially on the server side of things),
    Please step into 2015. Don't talk about how things WERE, forget about that as it's starting to get ridiculous. Yeah, I remember computer with 4 MB of RAM. Yes, I remember being a hotshot with my Pentium 100 MHz. And, yes, Edison was also a hotshot when he turned on his lightbulb and blew out his candles...

but there are still [COLOR="#FF0000"]many people using a dialup connection and the additional data caused by encryption can/does have a noticeable affect on page loading times.
Seriously? That's like saying there's still a lot of people using IE6 so you're not going to modernize your site...
According to official AU stats, dialup users were only 1.2% of the total internet users. UK started terminating dialup some time ago. You can NOT go adapting (or downgrading) your site because of a few individuals who are very likely never to even visit your site...

Not all customers have gigabytes of memory in their systems, and this can be quickly 'eaten up' by the decryption process (to the extent of some data being temporarily written to disk. Again, this causes performance issues.
Then you should feel obligated to instruct them to change host instead of giving them a lesson about SSL. I still get shocked when I see hosts offering packages with 500 MB disk space... Yes, I'm pretty sure there will be performance issues with hosts having 10,000 accounts on an Atom server... Go for a decent host and you'll never notice performance issues caused by SSL.

  1. Not all web browsers support encryption. OK, there are very few of these still being used, but they do still exist, so SSL prevents these people from accessing the site.
    Uhm... Which browsers would that be? And how many people REALLY use it? What's the percentage of visitors coming to your site using browsers that don't support SSL? I just checked my awstats and Google Analytics and haven't found a single one...
  1. When poorly implemented, typically caused by not all content being served over HTTPS, the browser alerts scare people away from completing a purchase, and causes them to shop elsewhere - This never happens on a site without SSL.
    Yes, when poorly implemented. A space shuttle will/might crash if a single screw is "poorly implemented". But that's a whole different story, we're not talking about poor coding.

... So there you go. at least 4 downsides that you almost certainly hadn't even considered (until now). If you had, you wouldn't have asked the question.
The #1 I did consider and even mentioned, but I find it to be SO insignificant that it's not worth pointing out as a downside. As for the other 3... Those are not even worth mentioning...

I shall consider this to be an ad hominem comment.
I had to look up the meaning - "responding to arguments by attacking a person's character, rather than to the content of their arguments"
Absolutely NOT. I apologize if it sounded like that. What I meant was that online shoppers in the UK really do focus on stuff that most other people from all over the world never notice. Mobile shopping (mobile optimized templates and stuff like that) was considered a must-have 3-4 years ago. The rest of the world found it important like a year ago. UK shoppers DO notice other minor stuff, including SSL. Aussies are probably not that obsessed with it and will shop with or without it just the same. And I bet 99% of people here in Croatia don't even know SSL exists...

I don't know about you, but I find this quite unsettling.
Naaah, personally, I don't care. I plan on winning the lottery in a year or two and will die a rich man not caring about these things... :D