3 ms·
In my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party. The only re
by jakobe 13y ago
In my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party.
The only reason why I want to support https is so that customers can confirm who they are downloading from. Ideally, I'd like an EV certificate, but I can't afford that. So I chose a business validation cert. A domain only certificate wouldn't really confirm anything.
(Also, some of my troubles would have been the same with a domain-only cert. The emails with missing links were those for domain validation, and I had to paste the CSR in the management area that was offline...)
- aleksandrm 13y agoSome if not all payment processing websites, like Stripe, still require that you use SSL to prevent MITM attacks.
- micahflee 13y agoIf you offer software to download HTTPS is a must. Otherwise any active attacker, from a kid at a coffee shop to the NSA at the ISPs, can make it so when people download your software they're also downloading your software with malware attached. Software downloads are one of the most important things to protect, and it saddens me that some websites still exist that offer software downloads that don't use HTTPS.
- ars_technician 13y agoSorry, but you are still wasting your money on a business validation certificate. A domain validation certificate is the only thing that a browser actually validates and ensures the security between you and the website. The rest is just sprinkles on top to make people feel better and to charge website owners extra money.
- mattlutze 13y ago>> so that customers can confirm who they are downloading from This would seem that he was in fact looking to provide "some sprinkles [to] make his customers feel better." Perhaps not a waste of money, then, if it provided what he was looking for?
- asdasf 13y agoThe sprinkles are for people buying certs, not the customers of the people buying certs. End users don't even know he got a different cert, or what that means.
- aioprisan 13y agoYou're really just wasting your time with a "business validated" certificate. The browser doesn't treat it any differently and consumers like my parents would not know the difference or know what to look for. It's all (brilliant) marketing, nothing else. You're equally secure with a PositiveSSL cert from namecheap.com for $8 (or free with a domain registration)..
- majelix 13y ago> You're really just wasting your time with a "business validated" certificate. The browser doesn't treat it any differently If your vendor doesn't do a decent job verifying who you are (and this may or may not mean EV), then browsers won't treat the certificate any differently when it's entirely replaced by someone else either.
- asdasf 13y agoIt doesn't matter how good a job your vendor does, if there is a vendor that does a bad job, then the attacker can get a cert from them. The presence of a single bad cert authority renders all certificates useless.