Are SSL Benefits Worth the Hassle?

Currently using SSL Godaddy at http://www.spothero.com

Another iphone says, "Unable to verify server id"

Two people I know cannot access it from their blackberry, and server identification problems continue to appear even in browsers on computers.

Are SSL benefits for this problem? What could be the disadvantage of completely getting rid of an HTTPS connection?

+4
source share
4 answers

For a certificate to be considered valid for the network, it must:

  • Validity will not expire.
  • Not issued after current date
  • Issued to view domain
  • Issued for server authentication
  • Certificate Chain Must Be Trusted

The problem that you probably see is related to the last requirement, your certificates are issued from the Go Daddy Certificate Authority (CA), and therefore the "system" accessing your site must know and trust this certificate.

Windows and other operating systems come with a full download of trusted CA certificates, so users of these systems will be able to access your site without any warnings (unless they trust CA). The Blackberry / iphone operating system probably does not have trusted CA Daddy CA certificates, so the user will have to add this manually (which most users do not know how to do)

This explains the problems you see regarding the โ€œtroublesโ€ issue, which largely depends on what Spothero will do when he lives. If this requires users to send confidential / confidential information, then yes, it must have the HTTPs component when this data is sent / displayed. If Spothero will never use confidential other information, you really do not need SSL.

So, getting back to the cause of your problem, if you decide that you really need SSL (to give your users peace of mind), consider using a better-known certificate authority, such as Verisign or Thwaites.

+4
source

Actually a well understood (if not widely practiced) way to deal with this issue.

Recall that the mathematical definition of risk

R = P x N

where R is the risk, P is the probability of a bad event, and H is the danger, that is, the cost of this bad thing if it happens.

Evaluate how bad the information can cost you, in currency. Find out the likelihood that someone will try it (anything from guessing wild autumn to thorough analysis) and succeed, and you can calculate R.

Is R less cost to solve SSL problem? If so, it is not worth the effort.

Now, at the same time, the complaint you received means that the certificate that you use for your SSL is not signed by a known trusted source, for example Verisign. If GoDaddy sold you SLL and cert, then this is a technical support problem for them. Otherwise, you need to buy a verified certificate.

+4
source

SSL is important if you send sensitive data, such as usernames and passwords.

I see that your authority to verify a certificate is GoDaddy itself, which may not be as popular. A better option would be to switch to Verisign or Thawte's.

0
source

When using tools such as FireSheep extensively, it is extremely important to use SSL if you have ever used public Wi-Fi networks. It is extremely easy to track and personalize users by copying session cookies.

0
source

Source: https://habr.com/ru/post/1334024/


All Articles