With the recent discovery of the Heartbleed bug, a major security flaw that was present in masses of websites including Google, Yahoo, Instagram and Netflix, internet security is something that, quite suddenly, is a lot closer to all of our hearts. If you have a website that stores any personal data or processes financial transactions, then its in your interest, and that of your customers, to know about SSL.
What is SSL?
SSL significa Secure Sockets Layer, e que basicamente permite a transmissão segura de dados sensíveis que podem incluir informações pessoais ou detalhes de cartão de crédito. Normalmente, quando tais dados são transferidos de um computador para o seu destino, ele vai passar por uma série de outros computadores antes que ele atinja o correto. Assim sendo, para assegurar a transmissão segura de dados, os detalhes são criptografadas e, em seguida, enviado para o servidor correto (em vez de servidor de um criminoso seria). Sem a criptografia, the data could be read and accessed by any of those computers that the data is passed through, meaning it could be accessible to identity thieves or hackers.
Even if you’ve never heard of SSL certificates before, it’s very likely that you’ve used them if you’ve ever purchase something online, managed your finances or logged into Facebook. To identify a website which possesses a valid SSL certificate, you can simply look at the address bar in the browser. Websites with an SSL certificate will usually have an address that begins with ‘https://’, and you should also be able to see a padlock icon.
Basic SSL vs. Extended Validation SSL certificates
There are different types of SSL certificates available which offer varying levels of protection. Some SSL certificates might just be suitable for keeping log in details for a website secure, whilst others may offer much more robust forms of protection.
One such enhanced type of SSL certificate is known as an extended validation SSL certificate(also known as EV SSL), which will turn the address bar green on the latest versions of any popular internet browser including Internet Explorer, Google Chrome or Firefox. An EV SSL also offers more robust protection against phishing attacks and is the type of certificate adopted by the majority of big commercial websites including Amazon and Ebay.
All websites which purchase SSL certificates need to go through a number of checks to verify the identity of the website and its owner. The more advanced level of SSL, the higher the number of checks. This means that when you see a website with an SSL certificate, you can be confident that the website is legitimate.
If your website has an SSL certificate, then it shows a commitment to your customers, showing that you care about their personal information and that you don’t want it to be easily accessible to those that might abuse it. As internet users become more savvy, it’s certain that they are less likely to use websites that don’t provide the security of an SSL certificate.
Claro, it really depends on what your website is for as to what type of SSL certificate you will require. If your website just sells one type of thing (for example memberships), then a low priced SSL certificate will probably be sufficient. Contudo, if you have an e-commerce site with lots of transactions, then something more renowned and robust may be required. Honestly though, para a maioria das pequenas empresas um certificado SSL padrão deve mais do que suficiente para as suas necessidades de segurança.
Por que alguns provedores de SSL mais caro do que outros?
A grande diferença de preço é tudo para baixo para o processo de verificação que as autoridades de certificado SSL comprometem-se a verificar se o seu site é o negócio real. Whilst global names like Verisignou Geotrust are well known, suas verificações são manual e lento, mas são certamente necessárias para as empresas como a Amazon ou Paypal. Contudo, estas verificações vir a um preço elevado, and would certainly be overkill for most small businesses.
Com aquilo em mente, I’ve tried to provide information on SSL certificates that would be suited to small businesses and entrepreneurs alike by meeting their security needs whilst keeping the cost down.
The cheapest SSL certificate provider
If you wish to pay a low price for your SSL certificate, then it is worth checking SSL certificate reseller websites such as ComodoSSLStore.com. Their lowest price certificates include a Comodo Domain Validation certificate for just $6.50 for one year.
For certificates to be this cheap, there must be a catch, certo? Truthfully, as long as you stick to well reputed resellers, this isn’t really the case. Unless you are after something very specialised, and you don’t have an issue with relying on reseller support rather than support directly from the certificate authority, then there is little reason not to use a reseller. SSL resellers buy SSL certificates in bulk which then enables them to pass on much lower prices to their customers. If you’re in any doubt however, it’s advisable to ask before purchasing if you have any particular requirements that you’re afraid won’t be met.
Com aquilo em mente, I’ve taken a look at three low priced SSL certificate providers and tried to give an honest assessment of the services they provide. Whilst the prices quoted are those given by the certificate authority, don’t forget to look for these certificates on a reseller website to get the best price possible.
RapidSSL are owned by Geotrust, who are one of the leading SSL certificate authorities. RapidSSL can provide certificates for $11.99 por ano, which includes a $10,000 fraud warranty which is perfect for any low volume e-commerce sites.
RapidSSL also offers e-mail support and also provides a 24/7 knowledge base and provides up to 256 bit encryption for one domain name. Perhaps the key thing here is that RapidSSL are literally a business that specialises in SSL, so they won’t attempt to sell you any additional extras that you may find with other services. You can pay extra to cover additional domain names, but this will cost you $199, which is quite pricey in comparison to their standard certificate.
GoDaddy are probably best known as a web hosting provider, Contudo, one of their many services includes providing SSL certificates. Like RapidSSL, GoDaddy provide a variety of different certificates, with prices starting from £48.99 per year. Contudo, like RapidSSL, the cheapest GoDaddy SSL certificates only cover one domain name and this doesn’t include any mobile variations of your site.
AlphaSSL’s cheapest package also starts from $49 (are you beginning to see a pattern here?). The big advantage that AlphaSSL has over GoDaddy and RapidSSL is that it will cover both the www and non www variations of your website (including mobile variations). Like RapidSSL, AlphaSSL is owned by well established SSL provider Verisign and its parent company is Symantec who actually established the SSL standard back in 1995. AlphaSSL’s cheapest SSL certificate only covers up to $1,000 worth of fraud however, which is lower than the warranties offered by RapidSSL and GoDaddy.
While we have only touched on a few SSL certificate providers here, there are potentially hundreds of different SSL certificates available on the market. This can be potentially confusing and difficult to navigate, but the general rule of thumb here is to use a trusted certificate authority and you can’t go wrong.
A higher price doesn’t necessarily mean a certificate is better, or any more secure for that matter, so be sure to select something that suits your business needs at the right price for you. Resellers are a good option if you’re on a budget, because you can secure a certificate from a highly trusted certificate authority but at a much lower price.
crédito de imagem: Adam Lerner