SSL Certificate on a site, this could get long winded.
there are many levels of security when a cert is purchased, as an example from network solutions, you can get what is called EV (extended verification) which they vett your company, and you have to jump through several hoops to acquire that type of cert from NS.
From Godaddy:
Encrypts data transferred to and
from your site and protects against session hijacking attacks, including Firesheep.
Secure UNLIMITED servers.
Compare that to other Certification
Authorities that charge for licensing
on each server. (this is applicable when you have redundancy, and a scaled environment)
SSL Certificates not only confirm the identity of the Certificate holder’s website to the visitor’s browser
but also encrypt information sent and received by the holder’s website. Information contained in the
digital Certificate includes:
• The Certificate holder’s name (individual or company)*
• The Certificate’s serial number and expiration date
• A copy of the Certificate holder’s “public” cryptographic key
• The digital signature of the Certificate-issuing authority
Phishing and Pharming
Phishing and pharming continue to pose real threats to unsuspecting Internet users.
Phishing is a common scam that uses fake emails from legitimate companies to trick recipients into
revealing their account numbers, passwords – even credit card and social security numbers.
The scam starts when an account holder with a legitimate business receives an email that looks like an
authentic notice from the company where they do business. The email recipient is instructed to click
through to a website where they are asked to “verify” their personal information. Such emails often
threaten a loss of account access if the recipient doesn’t take action.
Once the recipients click through, they’re greeted by a knock-off website that only looks like the real
thing. Unless the victim looks carefully or checks for the https:// prefix, they’re likely to submit the
requested data, never knowing they’re handing their most private information to thieves.
More sophisticated than phishing, pharming is the process by which an Internet Service Provider’s (ISP)
domain name server (DNS) entries are hijacked. The idea is to redirect Internet traffic to a fake website
instead of the real thing. When a “pharmer” succeeds in such DNS “poisoning,” every computer using
that ISP for Internet access is directed to the wrong site when the user types in a URL (e.g.,
www.ebay.com).
* Premium SSL Certificates only. Standard SSL Certificates contai
its not just related to a store any more, and google is pushing that all environments run under SSL. its noteworthy to state also that, there are different levels of encryption 1024 being the entry level, and the EV you have to have 2048 or greater, i submit with 4096.
so the gist of an SSL is that to and fro are encrypted, and if you think about it, itscompletely logical that all sites should be secured.
I am also going to say something here, about what i keep reading the cert is not per se' installed on a site, the cert is for the domain name.
you can have a cert on shared hosting, you would need to acquire a dedicated IP, because you are securing your environment only, there is also the ability to install a shared cert, i have considered this, but then would need to adjust the pricing so that we are not footing the bill for the cert.
self-signed certs are garbage, the whole process of a purchased cert is that you get a CA certificate of authority from the issuer, they also insure these certs for up to $250K should you suffer loss due to issuance of a bad cert and negligence on the issuers behalf. though proving negligence could be difficult.
so we fall back into the you get what you pay for, so looking at GD's site, which is where i would and do purchase my certs, the price variance from one end of the spectrum to the other, seems to span greatly, i do not think its from one cert being more secure than the other, but the level of effort required as part of the issuance protocol.
i also have some issues in my head at the moment regarding dolphin and the youtube function, since those files are not hosted on the server with the cert, you may see this site has untrusted content.
ok there you have it as plain and layman as it gets, hope that helps everybody understand what how and when about SSL.
now, with this all being said, i have something i want to discuss as well, involving site security and vulnerability:
Give your customers confidence
Show your visitors your site is safe and reliable with Website Protection Site Scanner, the easy way to detect and correct security threats on your site.
Automated daily scans
Identify threats and vulnerabilities on your website before they can be exploited. A daily scan looks for more than 3,000 vulnerabilities that a hacker could exploit to inject malware, spyware or steal customer information through phishing attacks. If any issues are discovered, you are notified via email or you can simply log in to the online dashboard to view the latest results.
Identify website vulnerabilities
Site Scanner scans forms, login and password fields, internal and external links – places a hacker could get in to deface your website, steal information or infect your customers with malware.Learn more about common threats and how Site Scanner helps protect you.
View your scorecard
If a vulnerability is discovered, your easy-to-read scorecard ranks the threat severity as either "Critical", "Warning" or "Informational", so you can prioritize and respond accordingly. The online dashboard lets you drill down for detailed information, report your fixes, dispute issues, request help, add notes and manage email alert settings.
Fix the threat with expert help.
Website Protection Site Scanner provides detailed reports and history, offering explanations of the issues, the location of the vulnerability and suggested courses of action. Best of all, you get additional assistance from our trained security professionals via email or direct access through our security hotline number.
Site secured
When your website is cleared of vulnerabilities, includingmalware links, the Website Protection seal will show the date of the most recently passed scan so your visitors know your site is free of critical vulnerabilities. The site seal remains visible as long as any vulnerabilities that may have caused a failed scan are addressed within 72 hours.
Site Scanner$5.99/mo
- Trusted Site Seal
- Daily Malware Link Scan
- Daily Website Scan
- FREE Expert Support
- Google Safe Browsing "Blacklist" Check
Learn more
When a GIG is not enough --> Terabyte Dolphin Technical Support - Server Management and Support