Re: ssl certificate/shopping cart

by "Karin Ransdell" <kransdell(at)squishedmosquito.com>

 Date:  Tue, 8 Jul 2003 00:59:27 -0500
 To:  <hwg-business(at)hwg.org>
 References: 
  todo: View Thread, Original

----- Original Message -----
From: "John Foliot - bytown internet" <foliot(at)bytowninternet.com>
To: "Michael Schultz" <mike(at)virtualtech.com>; "Karin Ransdell"
<kransdell(at)squishedmosquito.com>
Cc: "Write Words" <webwriting(at)hotmail.com>; <hwg-business(at)hwg.org>
Sent: Monday, July 07, 2003 6:38 PM
Subject: RE: ssl certificate/shopping cart


> 2 more cents
>
> Karin, while it's true that any sys-admin worth his (her) title can
generate
> a self signed cert in about 5 minutes, your allegation that there is no
> inherent trust assigned to the major cert issuers requires more than just
> your say as proof.  As a former employee of Entrust (who also issued
digital
> certs) I know for a fact that proof of right was required before a cert
was
> issued, and they took those issues seriously.  Access to the CA used to
> issue the digital certificates was strictly controlled to the point of
> paranoia, with retinal imaging scans required to access the lock room to
the
> remote *terminal* that was linked to the CA computer.

That's all well and fine and good, but is another one of those
self-defeating "so whats" because of exactly what you write next, which is a
*perfect* explanation of why I have the attitude that I do.

Your comment is 100% dead on.  Thank you for saying it...

> The real issue, if you really want to know, is not whether the connection
is
> being encrypted via SSL (and who issued the cert), but rather, what
happens
> to your sensitive data at the other end?... in other words, what security
> precautions have the vendor taken once they have received your encrypted
> credit card number and have that information?

>>>>> ding ding ding <<<<<< we have a winner.. go to the bonus round!  Yes.
Let's say someone has a certificate from a 'recognized' CA.  All they really
had to do was pay for it and provide some information (verified, tested by
blood, whatever, as it's about to become completely moot in this example).
Technically, the connection is secure.  (The same security a sys admin can
provide, minus the CA blessing.)  But, as in your good example, the
sensitive data sits on an unprotected hard drive, or an insecure database,
or a printout on someone's desk, even.....
Or here's an even better one.  XYZ Hosting has a blanket certificate that
they provide for their hosting clients.  The SSL connection is technically
and "administratively" good.  But hosting customer "Freddy Flybynight" sells
widgets on his ecommerce website.  The CA has absolutely no idea who Freddy
is.  They've got nothing from him.  The hosting company gets his payment,
but they don't require anything more than a valid credit card number.

Does the average customer care that the certificate isn't in Freddy's name?
How would they even know?  Unless they get an error from their browser, do
they even view the certificate to see who owns it and who issued it?  Do
they care if Freddy (or whoever bought it) paid $300, $100, or even $10 for
it?

Again.... why pay $xxxxxx.00 when $xxx.00 will do the same job?

> Shop around, there are a number of reputable certificate sellers who take
> their "end" of the legally binding agreement seriously, be it Verisign,
> Entrust, Baltimore, Thawte or others.  As is pointed out, if your client
is
> balking at $100.00 for a digital cert, I would be very concerned about how
> and what they do to/with the data once they receive it.  The strongest
door
> lock in the world won't help if you just leave you cash lying on the
floor.

Maybe that particular client should use XYZ Hosting and a blanket cert ;)
Yes, balking is bad, but paying more than one must is not very prudent,
either.

KRansdell

HTML: hwg-business mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.