Zen Cart Logo
Forums / General Questions / Activate SSL Certificate

Activate SSL Certificate

Views: 2,861

Results 21 to 37 of 37
18 Aug 2015, 12:57 AM
#21
barco57 avatar

barco57

Totally Zenned

Join Date:
Apr 2006
Location:
West Salem, IL
Posts:
2,844
Plugin Contributions:
0

Activate SSL Certificate

Can reading threads where RodG debates others on some topic be considered something like an E-sport? Can we get a zencart.tv domain where we can stream these debates? They would be much more enjoyable with facial expressions, and hearing when sarcasm is applied...However I do think "stepping into the ring" with RodG is a bit like mud wrestling a pig, a complete waste of time and he (the pig) enjoys it too much...lol.

18 Aug 2015, 1:41 AM
#22
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

balihr:

Totally agreed. But then again, how long do you think the site will stay in business if the owner doesn't bow at Google and other search engines?

Rule#1 for Good Google Rankings (straight out of the webmasters handbook). DON'T create or develop a site for Google. Develop for people. IOW, no need to 'bow' to them at all. :-)

The sole reason Google keep changing and updating their algorithms is because people do develop specifically to 'please' (or bow) to the Almighty Google - They don't want that, they don't like that. The changes they make are usually to penalise people for this behaviour.

That doesn't mean a people should ignore their recommendations for what makes a good quality site though.

balihr:

Perception, experience, feel .. Doesn't matter what you call it

These are not all the same thing. I perceive that jumping off of a cliff with a parachute is a dangerous thing to do. I won't do it. Ever.
Many people have experienced jumping off of a cliff with a parachute.

Some of these people, after having the experience **feel **scared shotless, and will never do it again. Other will feel exhilarated and can't wait to do it again.

balihr:

I don't do analysis and statistics and don't have first-hand experience. I read about it from various sources, hoping the info is correct. But, if 20 sources say the same thing, and only one claims otherwise, I tend to go with the flow

Funny thing about people and the internet - There are always plenty of resources to prove and disprove any theory you can come up with. A current classic example is to vaccinate or not vaccinate. Much like where this thread has ended up, it is a topic of endless debate.

Here's a site that I feel could be of interest to you - mainly on account of the fact that it backs up the views of public perception and perceived security. http ://baymard <dot> com/blog/site-seal-trust.

Just as a FYI, I didn't just go out and look for this - it is a site I've had bookmarked for quite some time as a result of some other research I was doing several months ago.

The part that I found of most interest is/was this

Trust Seals vs. SSL Seals

As discussed earlier, it’s not the actual security of your page that matters the most to users as they have little to no technical understanding of TLS/SSL encryption or even how forms are submitted. Rather it is the perceived security that’s of importance to this vast majority of users. This is why we included both SSL seals (Norton, Thawte, Trustwave, Geotrust, Comodo) and trust seals (McAfee, BBB Accredited, TRUSTe) in the survey. What we wanted to test is which site seal makes the user feel the most secure, not which seal actually represents the strictest technical / security compliance.


What this research has found, and this text clearly demonstrates, as that SSL itself is really unimportant to most users, so on this basis, would you think it fair to assume that it would be quite possible and feasible to simply add one of these 'trust seals' to a site without SSL and people would actually place more trust in the site than one that has SSL but NO 'trust seal'?

I seriously/honestly think that this is a valid assumption - which in a way tends to prove my point that SSL itself is basically useless and pointless, at least from a security/trust perspective.

OR, do you think my assumption here is invalid - and that most people want SSL and a 'trust seal'?

Hhhhmm.. this has just got me thinking about the client I previously mentioned that seemed to have lost sales because SSL was enabled. I wonder what the effects will be if I placed a 'fake' Norton Trust seal on his site (still leaving SSL disabled). Yeah, I know that a 'genuine' trust seal usually contains a link to 'call home' for verification, but I'm sure that most users won't know that and will be easily fooled.

What do you reckon? :-)

Re: ad hominem comment
"What I meant was that online shoppers in the UK really do focus on stuff that most other people from all over the world never notice"

Yup, I know that is what you meant, but it is STILL an ad hominem comment (Or should I say a racist comment?). Either way, it adds nothing to the discussion or topic at hand - All it really means is that UK shoppers are probably more deluded than the rest of the world in that they are still under the illusion that there is some degree of privacy on the Internet. I reckon if what you say is true (and I really doubt that it is) then it is time you opened your eyes and take a look around.

You really wouldn't believe how 'hard' it was for me to write these comments - I tend to go out of my way to not put people or countries into nice little boxes in the way you have done. I feel as though I've just broken one of my own cardinal rules of debating. :-(

Cheers
RodG


18 Aug 2015, 1:53 AM
#23
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

barco57:

However I do think "stepping into the ring" with RodG is a bit like mud wrestling a pig, a complete waste of time and he (the pig) enjoys it too much...lol.

I've opted to not be offended by this.

I DO enjoy a good debate. Only problem is, too many people take things too personally and ignore the salient points.

Cheers
RodG

18 Aug 2015, 2:35 AM
#24
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

Ooops, I missed commenting on this:

balihr:

According to official AU stats, dialup users were only 1.2% of the total internet users

1.2% may not seem like much, but it still equates to almost 300,000 homes on dialup, and with 2.5people per home, that is 750,000 potential customers.

In the USA there are 3% still using dialup - that 9million homes - over 20 million potential customers.

Who's going to sneeze at a $1.00 sale to each of these customers?

There are benefits to catering to the lowest common denominator.

Cheers
RodG

18 Aug 2015, 7:16 AM
#25
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

barco57:

Can reading threads where RodG debates others on some topic be considered something like an E-sport? Can we get a zencart.tv domain where we can stream these debates? They would be much more enjoyable with facial expressions, and hearing when sarcasm is applied...However I do think "stepping into the ring" with RodG is a bit like mud wrestling a pig, a complete waste of time and he (the pig) enjoys it too much...lol.
Oh... I AM hoping you were trying to make a joke and hopefully say something funny, but the comparison blew it... At least I hope that was your intention...

Debates with RodG - well, everyone here knows you can't win a debate with him... :D But why think like that? I don't see these debates as a competition with a win/lose outcome. IMO, this is a win-win kind of thing where various people exchange information and/or knowledge and everyone can learn something from it...

Personally, I would very much enjoy meeting RodG in person and talk with him about quite a few topics. We agree on some matters and disagree on some - I'm sure it would make an interesting conversation... Or maybe I would just be a good listener, who knows, but point is - I'm sure I'd enjoy it...

18 Aug 2015, 10:40 AM
#26
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

Rule#1 for Good Google Rankings (straight out of the webmasters handbook). DON'T create or develop a site for Google. Develop for people. IOW, no need to 'bow' to them at all. :-)

The sole reason Google keep changing and updating their algorithms is because people do develop specifically to 'please' (or bow) to the Almighty Google - They don't want that, they don't like that. The changes they make are usually to penalise people for this behaviour.

That doesn't mean a people should ignore their recommendations for what makes a good quality site though.
Exactly my point - adding an SSL cert is just on their list of recommendations. It's nowhere near creating a site for Google... Don't stretch the topic and twist my words - we're discussing SSL certs here...

These are not all the same thing. I perceive that jumping off of a cliff with a parachute is a dangerous thing to do. I won't do it. Ever.
Many people have experienced jumping off of a cliff with a parachute.

Some of these people, after having the experience **feel **scared shotless, and will never do it again. Other will feel exhilarated and can't wait to do it again.
Comparing this to SSL - some people will feel better and safer, some people will feel indifferent. Do you think anyone will be scared as hell if they see an SSL cert in use? Don't compare bananas with carrots...

Funny thing about people and the internet - There are always plenty of resources to prove and disprove any theory you can come up with. A current classic example is to vaccinate or not vaccinate. Much like where this thread has ended up, it is a topic of endless debate.
Exactly. Not sure about AU, but here in Croatia there's less than 1% of people against it (it was on TV like a month ago...). As I had mentioned earlier - I decide to go with the flow and you'll find me amongst the remaining 99% of population. Now, to make it perfectly clear, I'm not saying that just because the majority is doing it, it automatically means it's correct. I'm just saying I choose to go with the flow and I choose to accept the recommendations given by the majority.

Here's a site that I feel could be of interest to you - mainly on account of the fact that it backs up the views of public perception and perceived security. http ://baymard <dot> com/blog/site-seal-trust.

Just as a FYI, I didn't just go out and look for this - it is a site I've had bookmarked for quite some time as a result of some other research I was doing several months ago.

The part that I found of most interest is/was this

Trust Seals vs. SSL Seals

As discussed earlier, it’s not the actual security of your page that matters the most to users as they have little to no technical understanding of TLS/SSL encryption or even how forms are submitted. Rather it is the perceived security that’s of importance to this vast majority of users. This is why we included both SSL seals (Norton, Thawte, Trustwave, Geotrust, Comodo) and trust seals (McAfee, BBB Accredited, TRUSTe) in the survey. What we wanted to test is which site seal makes the user feel the most secure, not which seal actually represents the strictest technical / security compliance.


What this research has found, and this text clearly demonstrates, as that SSL itself is really unimportant to most users, so on this basis, would you think it fair to assume that it would be quite possible and feasible to simply add one of these 'trust seals' to a site without SSL and people would actually place more trust in the site than one that has SSL but NO 'trust seal'?

I seriously/honestly think that this is a valid assumption - which in a way tends to prove my point that SSL itself is basically useless and pointless, at least from a security/trust perspective.
I'm not sure if I understood this correctly, but are you saying that you'd put a FAKE seal and cheat people about the site being secured? If so, then I don't think a scam-like method needs any discussion. And if you're talking about those trust seals - well, if it helps generate one more sale, then it's worth it. Some people like to see it and some are indifferent. I haven't heard anyone complaining against it saying they abandoned their cart just because the trust seal was there...

Hhhhmm.. this has just got me thinking about the client I previously mentioned that seemed to have lost sales because SSL was enabled. I wonder what the effects will be if I placed a 'fake' Norton Trust seal on his site (still leaving SSL disabled). Yeah, I know that a 'genuine' trust seal usually contains a link to 'call home' for verification, but I'm sure that most users won't know that and will be easily fooled.

What do you reckon? :-)
Although I know you're trying to be sarcastic here, I'm still going to reply. A FAKE seal might backfire and cause you to lose a sale with people who notice it's fake. Keyword is might. Some will never notice it's fake, some will be indifferent. But, unlike a real working seal, some might leave because it's there and it's fake... Nobody will leave just because you have a valid seal or cert, that I'm sure of.

Re: [COLOR=#333333]ad hominem comment
"What I meant was that online shoppers in the UK really do focus on stuff that most other people from all over the world never notice"

Yup, I know that is what you meant, but it is STILL an ad hominem comment (Or should I say a racist comment?). Either way, it adds nothing to the discussion or topic at hand - All it really means is that UK shoppers are probably more deluded than the rest of the world in that they are still under the illusion that there is some degree of privacy on the Internet. I reckon if what you say is true (and I really doubt that it is) then it is time you opened your eyes and take a look around.
Please look up the definition of racism. This *might *be described as stereotyping, but it sure wasn't racist.

However, there's also one more thing you should keep in mind here - different markets have different requirements. Take cars for example... Bring a car with a 1.2 liters engine to Europe and it's OK. Take the same car to the US and they'll laugh at you and say it's for a 9 year old... Same thing here - UK shoppers have different expectations and different online behavior than some other nations. This is not even stereotyping, this is what I see every day and I'd call it common sense... Although we ARE globalized, not all nations move forward at the same pace.

It's absolutely irrelevant whether they are right or not, it's what they expect and it's up to the merchant to humour them or not. Just like it's the shoppers decision to purchase or leave. And, I'm pretty sure every merchant would prefer to have a customer instead of a visitor...

Imagine a survey saying US consumers prefer to go shopping in the afternoon, and UK shoppers prefer it in the early morning. If I told you to do a happy hour in the morning if you're from US, or in the afternoon if you're from UK, I hope you wouldn't call me racist for that as well... Because, if you would, then I suggest writing a long anti-racism letter to Ford and General Motors and ask that Eastern Europe gets the exact same cars as the dealers in California... I'm sure they would sell at least one V8 family estate car every decade there... :wink:

18 Aug 2015, 10:58 AM
#27
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

RodG:

1.2% may not seem like much, but it still equates to almost 300,000 homes on dialup, and with 2.5people per home, that is 750,000 potential customers.

In the USA there are 3% still using dialup - that 9million homes - over 20 million potential customers.

A very bad comparison, again... If you're going to "optimize" your site based on those 750,000 potential customers, you'll have to put the bar very very low. 750,000 really does sound intimidating, but let's take a look at the other side. You're dropping the bar and affecting the shopping experience for the remaining 98.8%. Using your math, that means you're lowering standards for 61,750,000 potential customers. If only 2% of them leave your site because of bad shopping experience (because you decided to be very friendly with the previously mentioned group), you're losing 1,235,000 potential customers.
Using large numbers to play the psychology card doesn't work here...

18 Aug 2015, 11:34 AM
#28
barco57 avatar

barco57

Totally Zenned

Join Date:
Apr 2006
Location:
West Salem, IL
Posts:
2,844
Plugin Contributions:
0

Re: Activate SSL Certificate

well, I was shooting for funny...it sounded funnier in my head...I will slowly back out of the room now

18 Aug 2015, 12:12 PM
#29
balihr avatar

balihr

Totally Zenned

Join Date:
Oct 2008
Location:
Croatia
Posts:
1,788
Plugin Contributions:
22

Re: Activate SSL Certificate

As this discussion went above what most people will find reasonable (and I truly admire anyone who really reads all that was posted here), I'm just gonna put a few lines as my closing statements and will not be discussing this any further.

The following are MY personal standpoints and/or recommendations. It might be wrong, it might be bad for someone, it might ruin your business, it might get an airplane engine fall right on your head... Again, the following is MY opinion - I suggest you do your own research and make your own decision. Don't ever go pointing your finger at me based on this...

  • using SSL on any ecommerce site IS recommended and can be considered as a must
  • the total cost involved in getting an SSL certificate is negligible and shouldn't even be referred to as a cost
  • using SSL will NOT protect you, your customers or your site - having an SSL certificate installed doesn't mean your site is now bulletproof and you need not worry about other security aspects. SSL is just one of many security related "things".
  • using SSL should be considered as a customer confidence boost, not a hacker-proof tool (just like a lock doesn't stop a thief)
  • using SSL will NOT affect your site's speed and performance if you're with a decent host. If you're hosted on a bad server, SSL will probably degrade your site's performance, but it will not make a major difference since everything else will be bad as well...
  • assuming your site was properly coded, SSL doesn't generate security warnings (which is usually simple to fix if it happens) and it can only help your business. If you're that one pine tree in an oak woods, simply disable SSL, forget about it and move on with your life (chances are minimal, but still...).
  • having a valid SSL certificate DOES help with rankings, although it's just a lightweight signal. On the other hand, a 100 grams bar is also lightweight - try holding 1,000 of those bars... Put 100 lightweight signals on your site and you'll surely see some results.
  • if you don't use SSL, some visitors might leave your site just because of that. Not necessarily, but might. If you do use SSL, nobody will leave your site just because of that.

There will always be people who will speak against it and/or say it's worthless, but currently it seems that the majority thinks it's a good idea to have SSL. At least based on my research. Again, I might be wrong. Use your head and your common sense to decide what's best for you.

If ANY other member here has anything to say on this matter, I'm sure we'd all love to hear it.

18 Aug 2015, 4:13 PM
#30
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: Activate SSL Certificate

And don't forget the "coffee shop", where encryption via TLS actually does help (when used for transport of all proof of identity including tokens). Other safeguards should be used as well (TLS is not a magic bullet), but akin to locking the door of your house, it will help at least help deter the avarage person.

Neither locks or encryption will outright stop someone with the time or expertise needed (or at all if the windows are left open, key under a rock, etc). But locks and encryption can help reduce the occurance of "crimes of opportunity".

Do I recommend TLS? Yes, along with many other security best practises and further education. Does everyone listen or take the information to heart? Probably not.

Heck, people here still violate the law (news media actually educate about it every year) and leave their cars running in the winter (doors unlocked and the keys in the ignition). Because cars can be easily stolen without the keys, does that mean I should not recommend people stop leaving their cars running with the doors unlocked and the keys in the ignition?

19 Aug 2015, 12:36 AM
#31
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

lhungil:

And don't forget the "coffee shop", where encryption via TLS actually does help (when used for transport of all proof of identity including tokens). Other safeguards should be used as well (TLS is not a magic bullet), but akin to locking the door of your house, it will help at least help deter the avarage person.

Neither locks or encryption will outright stop someone with the time or expertise needed (or at all if the windows are left open, key under a rock, etc). But locks and encryption can help reduce the occurance of "crimes of opportunity".

Do I recommend TLS? Yes, along with many other security best practises and further education. Does everyone listen or take the information to heart? Probably not.

Heck, people here still violate the law (news media actually educate about it every year) and leave their cars running in the winter (doors unlocked and the keys in the ignition). Because cars can be easily stolen without the keys, does that mean I should not recommend people stop leaving their cars running with the doors unlocked and the keys in the ignition?

I've been waiting for someone to mention the coffee shop / library scenario <smiles>.

This is another case of public perception rather reality. The SSL gives the user a false sense of security (and this has been my main point of argument all along).

Fact is, when I've wanted to be 'naughty' <cough, cough> in such places the packet sniffing method (which is what SSL/TLS protects against) is actually one of last methods I'd use (especially if I'm only interested in capturing login/password/CC details).

Key loggers are much simpler to install (both hardware and software types), and there is no need to capture megabytes of streaming traffic and sifting though it to obtain the 50 or so characters of wanted information.

Just saying'

Cheers
RodG

19 Aug 2015, 1:39 AM
#32
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

balihr:

As this discussion went above what most people will find reasonable (and I truly admire anyone who really reads all that was posted here), I'm just gonna put a few lines as my closing statements and will not be discussing this any further.

Sounds good to me. I was actually thinking of writing up a similar summary, but being lazy, I'll use yours instead (and some of my comments may come as a surprise).

balihr:

The following are MY personal standpoints and/or recommendations. It might be wrong, it might be bad for someone, it might ruin your business, it might get an airplane engine fall right on your head... Again, the following is MY opinion - I suggest you do your own research and make your own decision. Don't ever go pointing your finger at me based on this...

LOL.

balihr:

  • using SSL on any ecommerce site IS recommended and can be considered as a must

Agreed. (I would however like those that insist on using it be aware of what it does and more importantly what it doesn't do though)

balihr:

  • the total cost involved in getting an SSL certificate is negligible and shouldn't even be referred to as a cost

Agreed.

balihr:

  • using SSL will NOT protect you, your customers or your site - having an SSL certificate installed doesn't mean your site is now bulletproof and you need not worry about other security aspects. SSL is just one of many security related "things".

Agreed.

balihr:

  • using SSL should be considered as a customer confidence boost, not a hacker-proof tool (just like a lock doesn't stop a thief)

Agreed.

balihr:

  • using SSL will NOT affect your site's speed and performance if you're with a decent host. If you're hosted on a bad server, SSL will probably degrade your site's performance, but it will not make a major difference since everything else will be bad as well...

Agreed.

balihr:

  • assuming your site was properly coded, SSL doesn't generate security warnings (which is usually simple to fix if it happens)

Agreed.

balihr:

and it can only help your business.

Agreed (With a very small reservation related to the client's experience previously discussed where SSL appeared to have cost him sales. My gut feeling here is that there is/was still something more to this than I've been able to identify though. I (like most others would have expected an increase in sales with SSL enabled). Nonetheless, the sales figures do/did show otherwise, so I feel justified in maintaining this small reservation).

balihr:

  • having a valid SSL certificate DOES help with rankings, although it's just a lightweight signal.

I'm not yet convinced of this benefit. I've not seen or read any concrete evidence to support the claim.

I feel it is worth keeping in mind that so far it is only Google that has indicated that this is/will be used as a ranking factor (as far as I know), and that for many years Google (and other search engines) didn't/wouldn't even index HTTPS pages.
I've not investigated, but I suspect that many Search engines still won't index them on the assumption that they are encrypted for good reason - namely, they can/will contain confidential information.
This is also why I was quite horrified when Google not only started indexing them several years ago, but are now encouraging 'SSL everywhere'. HTTPS used to be a signalling factor to 'not index', as such, I still don't think this is a good move on Google's part.

As I have been (rightly) told me though - times have changed and I/we need to adapt to these changes regardless of whether we agree with them or not.

The question now is, have/will all the other search engines also followed Google down this path - because if they don't we run a risk of being entirely Google dependent. It is for this reason I'm not yet prepared to use 'SSL everywhere', and will only use it in the places where needed - eg. Login and account creation pages.

This is one aspect of this thread that I wouldn't mind discussing a little further, especially with someone that has a more indepth understanding/knowledge about what the other SE's are doing or planning.

balihr:

On the other hand, a 100 grams bar is also lightweight - try holding 1,000 of those bars... Put 100 lightweight signals on your site and you'll surely see some results.

I can't argue with that. :-)

balihr:

  • if you don't use SSL, some visitors might leave your site just because of that. Not necessarily, but might.

Agreed.

balihr:

If you do use SSL, nobody will leave your site just because of that.

Agreed - with the caveat that the SSL implementation is without errors (and I seem to see a lot that do have errors of one sort or another). :-(

balihr:

There will always be people who will speak against it and/or say it's worthless,

No. That's only me <grin>. My reasons for doing so are quite honorable though. :-)

balihr:

but currently it seems that the majority thinks it's a good idea to have SSL.

Also me. :-)

balihr:

At least based on my research. Again, I might be wrong.

No, not wrong. Mostly right. Please don't go telling people it should be mandatory though 'cos that's where I will say you are wrong <smiles>

balihr:

Use your head and your common sense to decide what's best for you.

Good advice with only one serious flaw. Common sense is no where near as common as you think it is (or should be).
Common sense dictates that one should never take anything at face value - If something seems too good to be true it usually is.
example: SSL is generally seen as a magic bullet or significant aspect of 'security', when the truth is, it is neither, as hopefully this discussion has shown. :-)

Cheers
RodG

19 Aug 2015, 1:49 AM
#33
rodg avatar

rodg

Deceased

Join Date:
Jan 2007
Location:
Australia
Posts:
6,263
Plugin Contributions:
4

Re: Activate SSL Certificate

Just a couple of quick/short comments:

balihr:

*RodG: Hhhhmm.. this has just got me thinking about the client I previously mentioned that seemed to have lost sales because SSL was enabled. I wonder what the effects will be if I placed a 'fake' Norton Trust seal on his site (still leaving SSL disabled). Yeah, I know that a 'genuine' trust seal usually contains a link to 'call home' for verification, but I'm sure that most users won't know that and will be easily fooled.

What do you reckon? :-)
*--------------------------------------------------------------------------------------------

Although I know you're trying to be sarcastic here, I'm still going to reply. A FAKE seal might backfire and cause you to lose a sale with people who notice it's fake.

Actually, I was being quite serious. You are right though, it might backfire. I doubt that the client would be willing to let me try/experiment anyway.

balihr:

This *might be described as stereotyping, but it sure wasn't racist.
*

My apologies. Stereotyping was the word I was looking for. I couldn't think of it at the time though.

balihr:

Using large numbers to play the psychology card doesn't work here...

Do I get points for trying? :-)

Cheers
RodG

19 Aug 2015, 2:15 AM
#34
lhungil avatar

lhungil

Totally Zenned

Join Date:
Feb 2012
Location:
mostly harmless
Posts:
1,818
Plugin Contributions:
4

Re: Activate SSL Certificate

RodG:

I've been waiting for someone to mention the coffee shop / library scenario <smiles>. ...
Happy to oblidge.

Of course keyloggers only work if you have hardware access (or have exploited software on a device). Not a huge concern for me personally (I may be considered overly paranoid / protective of my devices - including USB / Lightning ports and other external devices!)... And there are a few other tricks out there sneezes

But yes, key loggers (or just grabbing unencrypted identity cookies) have been proven (along with social engineering) to work well against the populace. Not to mention how dangerous wireless keyboards / mice / other HID devices can be... Especially those with no encryption or weak encryption... or regularly used (providing one with a large sample of similiar data to make cracking easier / faster).

But a perfect example of why TLS alone is not enough. And about assumptions / misconceptions. Kinda like the "I have a VPN, so I am safe"... Still alot that can be leaked (especially when connecting but before the tunnel is established).

And of course if one has access to the physical networking hardware a man in the middle can still be performed against TLS (and other traffic - or software exloits). Yes there are ways to reduce risk, but not eliminate.

Just saying'

(ever notice how when we are all mostly - or completely - on the same page, it still sometimes looks like we are arguing?)

19 Aug 2015, 3:04 AM
#35
lruskauff avatar

lruskauff

Totally Zenned

Join Date:
Sep 2008
Location:
WA
Posts:
559
Plugin Contributions:
0

Re: Activate SSL Certificate

barco57:

Can reading threads where RodG debates others on some topic be considered something like an E-sport? Can we get a zencart.tv domain where we can stream these debates? They would be much more enjoyable with facial expressions, and hearing when sarcasm is applied...However I do think "stepping into the ring" with RodG is a bit like mud wrestling a pig, a complete waste of time and he (the pig) enjoys it too much...lol.

For what it's worth, I thought this very funny. And Balihr is holding his own.

And I must enjoy the debate 'cause I'm one of those still lurking (until now). I'd like them to take the discussion to a new area though, maybe a learning area, because by now I forgot who the original OP was and what the question was (but I'm sure it deals with SSL).

9 Oct 2018, 12:49 AM
#36
ideasgirl avatar

ideasgirl

Totally Zenned

Join Date:
Aug 2005
Location:
Trujillo Alto, Puerto Rico
Posts:
1,437
Plugin Contributions:
3

Re: Activate SSL Certificate

Would it be possible to bring this topic to the present? Not much about the need/want of the SSL but to have it enabled site wide. :lookaroun

9 Oct 2018, 2:26 AM
#37
dbltoe avatar

dbltoe

Totally Zenned

Join Date:
Jan 2004
Location:
N of San Antonio TX
Posts:
9,792
Plugin Contributions:
14

Re: Activate SSL Certificate

As found elsewhere in the forum. Settings in includes/configure.php:```

<?php/** * @package Configuration Settings * @copyright Copyright 2003-2016 Zen Cart Development Team * @copyright Portions Copyright 2003 osCommerce * @license http://www.zen-cart.com/license/2_0.txt GNU Public License V2.0 * File Built by Zen Cart Installer on Mon Jan 01 2018 06:36:11 */ /*************** NOTE: This file is VERY similar to, but DIFFERENT from the "admin" version of configure.php. ***********/ /*************** The 2 files should be kept separate and not used to overwrite each other. ***********/ /** * Enter the domain for your store * HTTP_SERVER is your Main webserver: eg-http://www.yourdomain.com * HTTPS_SERVER is your Secure/SSL webserver: eg-https://www.yourdomain.com */ define('HTTP_SERVER', 'https://YOURSITE.com'); define('HTTPS_SERVER', 'https://YOURSITE.com'); /** * If you want to tell Zen Cart to use your HTTPS URL on sensitive pages like login and checkout, set this to 'true'. Otherwise 'false'. (Keep the quotes) */ define('ENABLE_SSL', 'true'); ```Settings for the YOURADMIN/includes/configure.php:``` <?php/** * @package Configuration Settings * @copyright Copyright 2003-2016 Zen Cart Development Team * @copyright Portions Copyright 2003 osCommerce * @license http://www.zen-cart.com/license/2_0.txt GNU Public License V2.0 * File Built by Zen Cart Installer on Mon Jan 01 2018 06:36:11 */ /*************** NOTE: This file is VERY similar to, but DIFFERENT from the "store" version of configure.php. ***********/ /*************** The 2 files should be kept separate and not used to overwrite each other. ***********/ /** * Enter the domain for your Admin URL. If you have SSL, enter the correct https address in the HTTP_SERVER setting, instead of just an http address. */ define('HTTP_SERVER', 'https://YOURSITE.com'); /** * Note about HTTPS_SERVER: * There is no longer an HTTPS_SERVER setting for the Admin. Instead, put your SSL URL in the HTTP_SERVER setting above. */ /** * Note about DIR_WS_ADMIN * The DIR_WS_ADMIN value is now auto-detected. * In the rare case where it cannot be detected properly, you can add your own DIR_WS_ADMIN definition below. */ /** * Enter the domain for your storefront URL. * Enter a separate SSL URL in HTTPS_CATALOG_SERVER if your store supports SSL. */ define('HTTP_CATALOG_SERVER', 'https://YOURSITE.com'); define('HTTPS_CATALOG_SERVER', 'https://YOURSITE.com'); /** * Do you use SSL for your customers login/checkout on the storefront? If so, enter 'true'. Else 'false'. */ define('ENABLE_SSL_CATALOG', 'true'); ```With an SSL properly installed, using these settings will set your entire site to be secure at all times. The next step is to make sure you have not embedded links in your site that point to http://. If you find them, change them to // instead. The browser will automatically open the link in the highest possible security.