Re: ssl certificate/shopping cart

by "Karin Ransdell" <kransdell(at)squishedmosquito.com>

 Date:  Tue, 8 Jul 2003 00:37:24 -0500
 To:  <hwg-business(at)hwg.org>
 References:  hotmail EPONA virtualtech
  todo: View Thread, Original

----- Original Message -----
From: "Michael Schultz" <mike(at)virtualtech.com>
To: "Karin Ransdell" <kransdell(at)squishedmosquito.com>
Cc: "Write Words" <webwriting(at)hotmail.com>; <hwg-business(at)hwg.org>
Sent: Monday, July 07, 2003 5:59 PM
Subject: Re: ssl certificate/shopping cart


> My two cents, split into sections...
>
> Karin Ransdell wrote:
>
> >We use the Comodo certificates and they are very helpful, should you need
> >tech support.  Since the entire "certifying authority" fiasco is a
racket, I
> >see no reason to pay one penny more just so that https:// doesn't throw
an
> >error in someone's browsers.
> >
> I see one big reason... lost sales.

You misunderstood the qualifier of "one penny more" and that's partly my
fault.  It was directly tied to Comodo as the CA.  They charge different
amounts for different "levels", the difference between 'levels' having
nothing to do with how secure the connection is.  Why pay $200 when $100
will do the same job?

> >Generating certificates is a technical matter,
> >not an authoritative matter.  Any system admin worth his paycheck should
be
> >able to generate a fully secure, functioning certificate ('self-signed')
> >that would work just as well as one you must pay a third party for.
> >
> Agreed... except for the above error.
>
> >
> >What you are paying for is a 'seal of approval' that these cerfitying
> >authorities are recognized by the browser makers.  They do not guarentee
or
> >even for the most part verify the information you provide, so what makes
> >them so trustworthy?  The fact that they did what it took to be accepted
by
> >the browser makers (read: got on the Microsoft 'approved' list) is what
you
> >are buying.  Sound like legal extortion to anybody else?
> >
> Maybe, but "welcome to the real world".  Online sales is not the place
> to be standing up for your principles.  Save that for the
> *nix/Mac/Windows battles found at your local flame board.  If my clients
> found out that I went a different route because I wanted to "stick it to
> the big monopolies" I would be applying for a job flipping burgers in
> very short order.

I still hold that the entire "Company X" is a Certifying Authority, but
"Company A" is not amounts to a racket.  The nuances are moot.  Is Company X
the only company *capable* of generating secure certificates?  So why does
Company A have to buy in with the browser manufacturer for acceptance?
Gee.. could it have anything to do with $$$?

> >Also, with regard to Comodo's placing a transation amount levels on their
> >certificates, the certificate is the same, has the same technical effect,
so
> >don't bother to pay more.
> >
> No idea about this, but IMHO it is a moot point.  See above.  For $99 a
> year you can get a GeoTrust cert which will work with all major
> browsers.  If you can't afford that, you can't afford to be in business.

Again, this was directly related to Comodo, the CA in question.  They have a
cert for $39.  So why pay $349?  Why pay $199?  Why $99?  That was my point.
I'm sure someone will explain why, but since the point of the SSL is to
encrypt the connection while not throwing an error stating that the
certificate encrypting the connection doesn't have the browser's holy water
on it <pause> why pay top dollar if the end result is the same?

> Sorry for the rant... been that kind of day.

How well I understand.  Have a nice tomorrow.

KRansdell

HTML: hwg-business mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.