|
SSL
The SSL (and TLS) protocol is the Web standard for encrypting
communications between users and SSL (secure sockets layer) e-commerce
sites. Data sent via an SSL connection is protected by encryption, a
mechanism that prevents eavesdropping and tampering with any transmitted
data. SSL provides businesses and consumers with the confidence that
private data sent to a Web site, such as credit card numbers, are kept
confidential. Web server certificates (also known as secure server
certificates or SSL certificates) are required to initialize an SSL
session. Customers know when they have an SSL session with a website
when their browser displays the little gold padlock and the address bar
begins with a https rather than http. SSL certificates can be used on
webservers for Internet security and mailservers such as imap, pop3 and
smtp for mail collection / sending security.
Why is security required for the Internet?
The Internet has been a revolution to commerce and the transfer of data
in general, which has developed new global business opportunities for
all, including major enterprises, small to medium sized businesses and
individuals alike. However e-commerce has inevitably attracted crime and
developed a new breed of online criminals ranging from fraudsters and
hackers to cyber terrorists. The growing concerns associated with
conducting e-commerce have now resulted in the fact that security is an
essential factor for online business success.
The market is now educated in the basics of online security and the
majority of online users now expect security to be integrated into any
online service they use and as a result they expect any details they
provide via the Internet to remain confidential and secure.
This white paper explains how SSL can be utilized as the core security
technology to protect customer's online transactions and informs users
that the security of the online business is being taken seriously. In
fact SSL provides proof of a digital identity and allows online
customers to visibly see that their digital transaction will be
confidential. These are essential factors in gaining customer confidence
and remove the concerns and risks associated with sending sensitive data
over the Internet.
SSL is essential to allow the true benefits of the Internet to be
realised.
When to use SSL?
SSL is not generally, nor should it be used for all pages on a website.
SSL is most commonly used for the sending and receiving of sensitive
information such as credit cards, membership ID's, or customer billing
information access. SSL need only be used on the "particular" page where
the secure activity is taking place. ALWAYS use SSL when asking for
credit card information. If visitors do not observe the https//
appearing on the form URL, and the "SSL Symbol", does not illuminate in
their browser, they won't be doing a whole lot of business with you. No
one wants his or her credit card information intercepted and stolen as
the result of a site not using SSL encryption!
|