What is SSL (the little padlock)?

SSL ("Secured Socket Layer") is a protocol used to encrypt the communication between the user's browser and the web server. When SSL is active, a "little padlock" appears on the user's browser, usually in the status line at the bottom (at the top for Mac/Safari users.)

This assures the user that sensitive data (such as credit card numbers) can't be viewed by anyone "sniffing" the network connection (which is an increasing risk as more people use wireless networking).

Common web site owner questions about SSL:

How do I get the little padlock on my site?

To get the little padlock, your site must have an SSL Certificate from a Certificate Authority. Once an SSL Certificate has been purchased and installed, it provides three things:

  • The ability to show a page in "Secure Mode", which encrypts the traffic between the browser and the server, as indicated by the "little padlock" on the user's browser.
  • A guarantee by the issuing Certificate Authority that the domain name the certificate was issued for is indeed owned by the specific company or individual named in the certificate (visible if the user clicks on the little padlock).
  • An assurance that the domain name the certificate was issued for is the domain name the user's browser is now on.
  • Once obtained, the certificate must be installed on the web server by your web host. Since your web host also has to generate an initial cypher key to obtain the certificate, very often they will offer to handle the process of obtaining the certificate for you.

    My web host has a "shared certificate" that I can use. Should I?

    It's still fairly common for small sites to use a shared certificate from the host. In this circumstance, when a page needs to be shown in secured mode, the user is actually sent to a domain owned by the web host, and then back to the originating domain afterwards.

    A few years ago, when SSL Certificates were quite expensive (around $400 per year), this was real attractive for new sites just getting their feet wet in e-commerce. Today, with a number of perfectly functional SSL certificates available for under $100 (exclusive of installation, etc.), it is a lot less attractive. Since your user can look a the address line of his or her web browser and see that the site asking for the credit card number is not the site he or she thought they were on, the cost savings is probably not worth the risk of scaring off a sale.

    What's the difference between the expensive SSL Certificates and the inexpensive ones?

    Usually, mostly price. Some expensive certificates have specific functions, like securing a number of different subdomains simultaneously (a "wildcard" certificate), but the effective differences between basic single site certificates are very slight, despite the wide range of prices:

    The encryption mechanism used by all of them is the same, and most use the same key length (which is an indicator of the strength of the encryption) common to most browsers (128 bit).

    Some of them ("chained root" certificates) are slightly more of a pain for your web host to install than others ("single root" certificates), but this is pretty much invisible to the site owner.

    The amount of actual checking on the ownership of the domain varies wildly between vendors, with some (usually the more expensive) wanting significant documentation (like a D&B number), and others handling it with an automated phone call ("press #123 if you've just ordered a certificate").

    Some of them offer massive monetary guarantees as to their security (we'll pay you oodles of dollars if someone cracks this code), but since it's all the same encryption mechanism, if someone comes up with a crack, all e-commerce sites will be scrambling, and the odds of that vendor actually having enough cash to pay all of its customers their oodle is probably slim.

    The fact is that you are buying the certificate to insure the safety of the user's data, and to make the user confident that his or her data is secure. For the vast majority of users, simply having the little padlock show up is all they are looking for. There are exceptions (I have a client in the bank software business, and they feel that their customers (bank officers) are looking for a specific premier name on the SSL certificate, so are happy to continue using the expensive one), but most e-commerce customers do not pick their sellers based on who issued their SSL Certificates.

    My advice is to buy the cheaper one.

    I have an SSL certificate -- why shouldn't I serve all my pages in "Secured" mode?

    Because SSL has an overhead -- more data is sent with a page that is encrypted than a page that isn't. This translates to your site appearing to run slower, particularly for users who are on dial-up or other slow connections. Since this also increases the total amount of data transfered by your site, if your web host charges by transfer volume (or has an overage fee, as most do), this can increase the size of your monthly hosting bill.

    The server should go into secure mode when asking a user for financial or other sensitive data (which may well be "name, address and phone number", with today's risk of identity theft), and operate in normal mode otherwise.

    Updates to this article, and many other great articles and tutorials for small business web site owners can be found at Insanely Great Sites!

    In The News:


    pen paper and inkwell


    cat break through


    E-Gold

    E-gold is a digital currency, used extensively on the Internet... Read More

    How Measuring Key Performance Indicators Can Improve E-Commerce Strategy - Part One

    The problem with most e-commerce marketing strategy today is that... Read More

    Are You Making These E-Commerce Excuses? (part 1)

    A year ago, I had big plans to re-vamp my... Read More

    Saving Money On Your E-commerce Site

    After building and transferring many e-commerce sites it still amazes... Read More

    Web Users Crave Familiarity

    The sad truth is, general Web users would love it... Read More

    Stakeholder Analysis and Stakeholder Management

    What is a Stakeholder?Try "define: Stakeholder" in Google and you... Read More

    Do Your Online Brokerage Business With Zero Down

    If you have little or no capital but you want... Read More

    Select a Niche Market for Ecommerce

    Choosing a carefully pinpointed niche market should be one of... Read More

    Top 5 Dot Com Myths Debunked

    Most people who get into business know what's involved. They... Read More

    Shopping Cart Abandonment ? Discover 5 Things you can do to Lower Cart Abandonment

    A common frustration among merchants who sell online via a... Read More

    Why This Is The Perfect Time To Start Charging For Website Subscriptions

    If you're a writer, researcher, subject matter expert, enthusiastic hobbyist,... Read More

    Developing a Winning e-Commerce Strategy

    One bright spot on the economic horizons around the world... Read More

    How to Get Free Internet Merchant Accounts

    This article will show small businesses how to get free... Read More

    Writing Web Pages: Get To The Meat Faster

    Much of my consulting work comprises writing 'Outside Opinion' reports... Read More

    Ten Reasons Why Online Surveys Are The Future of Marketing

    Customers are tough cookies. They're extremely media aware and increasingly... Read More

    7 Must Have Scripts to Look for When Shopping for E-commerce Hosting

    When shopping for e-commerce hosting there are a lot of... Read More

    The Census and the E-Commerce Wave

    Understanding business and product sales can sometimes put me in... Read More

    Intranet Project Names - Some Ideas

    "What's in a name? That which we call a rose... Read More

    Online Consumers ? What Are They Complaining About?

    For many businesses, e-commerce represents a tremendous method for generating... Read More

    How to Generate Cash from Your Web Site

    The Internet has changed the way people do business today.... Read More

    Does Your Shopping Cart Have a Squeaky Wheel?

    Have you ever gone grocery shopping just before a holiday?... Read More

    E-marketplaces from Sellers Perspective

    What is an E-marketplace anyway?E-marketplace is a business to business... Read More

    Dont Get Ripped Off Getting A Merchant Account

    Far too many people get ripped off when setting up... Read More

    Ecommerce Comes from Customer Satisfaction

    Online shopping is convenient, but many companies whose web sites... Read More

    How To Eliminate Credit Card Refunds From Digital Thieves

    Can you encounter the number of times where a Credit... Read More

    Web advertising e-Marketing Places!

    Overview:What is web advertising?Internet Advertising is popularly known as web... Read More

    eCommerce, How Much Does It cost?

    Making profits with your existing website design or creating a... Read More

    Content Ever be Profitable?

    THE CURRENT WORRIES1. Content SuppliersThe Ethos of Free ContentContent Suppliers... Read More

    7 Suggestions for an i-Mom Friendly Web Site (e-commerce news and statistics)

    The Internet began as a male dominated medium, but those... Read More

    Getting Started in ECommerce ? Part Two

    In Part One we talked a little bit about what... Read More

    Shopping Carts For The Faint Of Heart

    The chief criteria for judging an ecommerce shopping cart are... Read More

    Turn Your Rusty Junk Into eBay Gold

    Often times people to stop to realize the income potential... Read More

    Using Credit Cards Securely Online

    Nowadays, shopping online is a very common thing. Making your... Read More