{"id":3433,"date":"2018-11-04T09:00:10","date_gmt":"2018-11-04T15:00:10","guid":{"rendered":"https:\/\/www.tinythunder.com\/?p=3433"},"modified":"2018-11-04T09:00:10","modified_gmt":"2018-11-04T15:00:10","slug":"encryption-ssl","status":"publish","type":"post","link":"https:\/\/tinythunder.com\/blog\/encryption-ssl\/","title":{"rendered":"What Is Website Encryption (SSL) and Why You Need It"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Website encryption changed a lot in 2018, so I\u2019ve updated this post with the current state of website encryption and SSL certificates.<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">First, a quick explanation. We\u2019re talking about the lock icon that\u2019s displayed next to the URL in your address bar (see note at the end of this article about how this is changing).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/tinythunder.com\/wp-content\/uploads\/2021\/07\/ssl-icon-1200x724-1-1024x618.png\" alt=\"\" class=\"wp-image-8925\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The padlock (and the use of \u201c<strong>https<\/strong>\u201d instead of simply \u201chttp\u201d) announces the presence of a Secure Sockets Layer (SSL), which encrypts the connection between your browser (Firefox, Safari, Chrome, Internet Explorer) and the website you\u2019re visiting.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cSSL allows sensitive information such as credit card numbers, social security numbers, and login credentials to be transmitted securely. Normally, data sent between browsers and web servers is sent in plain text\u2014leaving you vulnerable to eavesdropping. If an attacker is able to intercept all data being sent between a browser and a web server they can see and use that information.\u201d&nbsp;<a href=\"https:\/\/www.digicert.com\/ssl.htm\" target=\"_blank\" rel=\"noreferrer noopener\">via DigiCert.<\/a><\/p><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">To set this up, you would purchase an SSL certificate for your website URL and install it on your server. SSL certificates contain a pair of keys (public and private) used to establish a secure connection between the viewer and the website. If you\u2019d like a rough analogy for how this works,&nbsp;<a href=\"https:\/\/www.tinythunder.com\/website-encryption\/#\">click here.<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Do You Need SSL? Yes.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Several years ago, when I originally wrote this post, I recommended purchasing SSL for the following reasons:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>if you collect personal information through forms<\/li><li>if you collect credit card information\/sell products<\/li><li>if customers log in to your website<\/li><li>if you have restricted content<\/li><li>if you wanted a potential SEO boost<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Part of the reason for this criteria was because the average certificate cost an additional +$99 per year for hosting costs. It was a good practice to have it, but for a small business with nothing more than service options and contact forms it didn\u2019t seem necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However,&nbsp;<a href=\"https:\/\/support.google.com\/webmasters\/answer\/6073543?hl=en\" target=\"_blank\" rel=\"noreferrer noopener\">in February 2018, Google announced<\/a>&nbsp;that it would begin marking all HTTP sites as \u201cnot secure\u201d in Chrome beginning in July 2018. Since&nbsp;<a href=\"https:\/\/www.statista.com\/statistics\/268299\/most-popular-internet-browsers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chrome is currently the most popular Internet browser<\/a>, this is a big deal. It\u2019s not like your site suddenly became less secure, it just looks that way, particularly to someone who might not understand the nuance of browser security warnings.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">We include SSL certificates free of charge with every website we build.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No longer a nice option; SSL is now a must have for every small business on the web. This is also a great example of the power an industry behemoth has \u2013 if Google even announces they\u2019re thinking about a change, everyone stops and listens. In this case, it\u2019s a good thing, because it\u2019s making the web more secure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important Note About the SSL Icon:<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/blog.chromium.org\/2018\/05\/evolving-chromes-security-indicators.html\" target=\"_blank\" rel=\"noreferrer noopener\">Google is changing the style of the padlock icon.<\/a>&nbsp;\u201cUsers should expect that the web is safe by default, and they\u2019ll be warned when there\u2019s an issue. Since we\u2019ll soon&nbsp;<a href=\"https:\/\/security.googleblog.com\/2018\/02\/a-secure-web-is-here-to-stay.html\">start marking<\/a>&nbsp;all HTTP pages as \u201cnot secure\u201d, we\u2019ll step towards removing Chrome\u2019s positive security indicators so that the default unmarked state is secure.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This means that instead of looking for a padlock, you won\u2019t even have to think about a secure connection unless you get the red \u201cnot secure\u201d notice (in Chrome). This is beginning October 2018.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">I hope this article was informative, practical, and gives you a decent idea of how SSL certificates work and why they\u2019re now a must for every business. Keep in mind that while this is a best practice, it doesn\u2019t mean that&nbsp;<em>every<\/em>&nbsp;website will abide by it. Always check for SSL when submitting credit card or personal information online. Thanks for reading and feel free to ask questions in the comments below.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">If we built\/maintain your website, you already have SSL. If you\u2019d like us to send you an estimate to build a new WordPress site (or redesign an existing website),&nbsp;<a href=\"https:\/\/www.tinythunder.com\/discovery-call\">schedule a discovery call.<\/a><\/h4>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Website encryption changed a lot in 2018, so I\u2019ve updated this post with the current state of website encryption and SSL certificates.<\/p>\n","protected":false},"author":4,"featured_media":9179,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[81,83],"tags":[89,80,96],"class_list":["post-3433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","category-websites","tag-best-practices","tag-security","tag-websites"],"meta_box":[],"_links":{"self":[{"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/posts\/3433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/comments?post=3433"}],"version-history":[{"count":0,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/posts\/3433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/media\/9179"}],"wp:attachment":[{"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/media?parent=3433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/categories?post=3433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tinythunder.com\/wp-json\/wp\/v2\/tags?post=3433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}