Top Web Hosting Reviews
Top Web Hosting Provider of The Month:
Top Web Hosting
Visit Bluehost.com | Read Bluehost Review

>> Web Hosting Geeks // Web Hosting Articles // Ecommerce  


What is SSL (the little padlock)?








SSL ("Secured Socket Layer") is a protocol used to encrypt the communication between the user's browser and the web server. When SSL is active, a "little padlock" appears on the user's browser, usually in the status line at the bottom (at the top for Mac/Safari users.)

This assures the user that sensitive data (such as credit card numbers) can't be viewed by anyone "sniffing" the network connection (which is an increasing risk as more people use wireless networking).

Common web site owner questions about SSL:

How do I get the little padlock on my site?

To get the little padlock, your site must have an SSL Certificate from a Certificate Authority. Once an SSL Certificate has been purchased and installed, it provides three things:

  • The ability to show a page in "Secure Mode", which encrypts the traffic between the browser and the server, as indicated by the "little padlock" on the user's browser.
  • A guarantee by the issuing Certificate Authority that the domain name the certificate was issued for is indeed owned by the specific company or individual named in the certificate (visible if the user clicks on the little padlock).
  • An assurance that the domain name the certificate was issued for is the domain name the user's browser is now on.
  • Once obtained, the certificate must be installed on the web server by your web host. Since your web host also has to generate an initial cypher key to obtain the certificate, very often they will offer to handle the process of obtaining the certificate for you.

    My web host has a "shared certificate" that I can use. Should I?

    It's still fairly common for small sites to use a shared certificate from the host. In this circumstance, when a page needs to be shown in secured mode, the user is actually sent to a domain owned by the web host, and then back to the originating domain afterwards.

    A few years ago, when SSL Certificates were quite expensive (around $400 per year), this was real attractive for new sites just getting their feet wet in e-commerce. Today, with a number of perfectly functional SSL certificates available for under $100 (exclusive of installation, etc.), it is a lot less attractive. Since your user can look a the address line of his or her web browser and see that the site asking for the credit card number is not the site he or she thought they were on, the cost savings is probably not worth the risk of scaring off a sale.

    What's the difference between the expensive SSL Certificates and the inexpensive ones?

    Usually, mostly price. Some expensive certificates have specific functions, like securing a number of different subdomains simultaneously (a "wildcard" certificate), but the effective differences between basic single site certificates are very slight, despite the wide range of prices:

    The encryption mechanism used by all of them is the same, and most use the same key length (which is an indicator of the strength of the encryption) common to most browsers (128 bit).

    Some of them ("chained root" certificates) are slightly more of a pain for your web host to install than others ("single root" certificates), but this is pretty much invisible to the site owner.

    The amount of actual checking on the ownership of the domain varies wildly between vendors, with some (usually the more expensive) wanting significant documentation (like a D&B number), and others handling it with an automated phone call ("press #123 if you've just ordered a certificate").

    Some of them offer massive monetary guarantees as to their security (we'll pay you oodles of dollars if someone cracks this code), but since it's all the same encryption mechanism, if someone comes up with a crack, all e-commerce sites will be scrambling, and the odds of that vendor actually having enough cash to pay all of its customers their oodle is probably slim.

    The fact is that you are buying the certificate to insure the safety of the user's data, and to make the user confident that his or her data is secure. For the vast majority of users, simply having the little padlock show up is all they are looking for. There are exceptions (I have a client in the bank software business, and they feel that their customers (bank officers) are looking for a specific premier name on the SSL certificate, so are happy to continue using the expensive one), but most e-commerce customers do not pick their sellers based on who issued their SSL Certificates.

    My advice is to buy the cheaper one.

    I have an SSL certificate -- why shouldn't I serve all my pages in "Secured" mode?

    Because SSL has an overhead -- more data is sent with a page that is encrypted than a page that isn't. This translates to your site appearing to run slower, particularly for users who are on dial-up or other slow connections. Since this also increases the total amount of data transfered by your site, if your web host charges by transfer volume (or has an overage fee, as most do), this can increase the size of your monthly hosting bill.

    The server should go into secure mode when asking a user for financial or other sensitive data (which may well be "name, address and phone number", with today's risk of identity theft), and operate in normal mode otherwise.

    Updates to this article, and many other great articles and tutorials for small business web site owners can be found at Insanely Great Sites!


    MORE RESOURCES:

    Chase Paymentech and Kount Join Forces to Combat Fraud for eCommerce Merchants
    MarketWatch (press release)
    DALLAS & BOISE, Idaho, Mar 15, 2010 (BUSINESS WIRE) -- Chase Paymentech, a leading merchant acquirer and payment processor, and Kount, a Boise, Idaho-based ...

    and more »


    Google mixes cloud computing with ecommerce
    EDL Consulting
    Google's improved offerings to businesses come just before Microsoft is set to launch a cloud-based version of Microsoft Office, according to the E-Commerce ...

    and more »


    Ecommerce growth in US leads to global demands
    EDL Consulting
    The Information Technology & Innovation Foundation recently reported that ecommerce grew by more than 400 percent in the United States from 2000 to 2009. ...



    Ecommerce Marketing Tips: Writing Better Copy
    ECommerce-Guide
    Writing good product copy is an essential part of a successful ecommerce shop. But if writing's not your thing, check out one of the many ...



    MoBeePay(TM) Officially Announces a Revolutionary Mobile eCommerce App.
    PR Newswire (press release)
    CHICAGO, March 15 /PRNewswire/ -- The MoBeePay iPhone application (other versions coming soon) allows buyers and sellers to connect and transact business in ...

    and more »


    Ecommerce Journal

    New iPads just for $100
    Ecommerce Journal
    Tell us what topics you want to be covered in the Ecommerce Journal? You can use BBCode tags in the text. URLs will automatically be converted to links. ...

    and more »


    Latest Ecommerce Podcast Features Interview With Mike Feiman of PoolDawg
    PR-USA.net (press release)
    SLI Systems, provider of on-demand, intelligent search services for Internet and e-commerce sites, announced today that the latest Ecommerce Podcast ...



    Challenging eCommerce landscape for UK retail
    Quest Search and Selection
    UK retailers will be warned later this month that they face major challenges due to the ever-changing eCommerce landscape. With eCommerce consumer habits ...

    and more »


    Magento and PayPal Expand Relationship to Drive e-Commerce Innovation
    MarketWatch (press release)
    Magento is one of the fastest-growing global e-commerce solutions. Its open source product gives merchants complete flexibility and control over the user ...
    Magento Integrates PayPal into Ecommerce Selling SolutionAuctionbytes

    all 26 news articles »


    AKAM To Benefit From Multiple Growth Drivers
    Benzinga
    “While we believe the company will benefit from multiple growth drivers (HD, ecommerce and cloud computing) and the worst of the media pricing declines are ...
    Kaufman Bros. Assumes Coverage on Akamai Technologies (AKAM) with a HoldStreetInsider.com (subscription)
    Market Report -- Short Stories (AKAM)MSN Money
    Maxim Group Downgrades Akamai (AKAM) to HoldStreetInsider.com (subscription)

    all 5 news articles »

    Google News





     
     
     

    © 2004 - 2008 "Web Hosting Geeks" | Web Hosting Reviews | Customer Reviews | RealMetrics Reviews | Hosting Articles | Directory | Partners | Contacts
    Over 7000 articles: web hosting, web development, domain names, ecommerce, web design, site promotion, ppc advertising, seo, site promotion and many others.
    Web hosting reviews, ratings and awards are not based on any incentives or commissions. Names and trademarks are the properties of their respective owners.
    A direct link to Web Hosting Geeks (http://webhostinggeeks.com) must be provided in order to use any of the above information. Contact us for more info.

    Partners: Hosts by speed, Cheap Website Hosting, Free Website Hosting, Cheap Web Hosting, Top 10 Web Hosts, Top 10 Web Hosting Deals, Best Website Hosting, Free Web Hosting, Free Web Hosting, Dedicated Server Hosting, Adult Web Hosting, Web Hosting Discussions, Dedicated Server Reviews, Best Web Hosting, Web Hosting Discounts, HostProfessor.com, rsuog, halyava, PHP Website Hosting Services, Web Hosting Reviews, Hosting Uptime, Best Web Hosting Reviews, Cheap Webhosting, Web Hosting, Flash Templates, CMS Templates, Web Hosting Reviews, Website Hosting Reviews, Web Hosting Providers, Best Web Hosting, Top Web Hosting, RSUOG Web Hosting