Online security cerificates
Sunday, July 29th, 2007[rolygate]
Struck a problem with the site certicate logos - the ‘Secured by…’ etc logos that show who audits the security at the shopping cart end of the site. The problem is this: if you are an independent operator who sets up your own store, on any old server, you can get a certificate to show that the route out to your merchant partner’s credit card processing facility is secure (assuming it is, since it will be audited first - at least by those whose certificates are actually worth having).
However, if you are located within an entire secure ecommerce facility, with grade one security starting at the door so to speak, you can’t have a certificate. Even though the building, the servers, the entire set-up are all 1000% more secure than where a site owner just has a secure connection to his card agent.
This is because the certificates are issued to the site hosts, not the individual site owners (all 500 or 1,000 of them), so they cannot display the appropriate logos.
It doesn’t matter that the entire operation is much more secure than a go-it-aloner’s. The only way around this, as far as I can see at the moment, is for individual site owners to purchase their own (additional and completely unnecessary) certificates. You can be in a postnuke bunker facility with more security than Fort Knox, have multiple top-grade certificates from Verisign etc (as we do) and still have no right to display the logo on the front page.
This is something of a dichotomy, or a dilemma, or another one of those di- thingies. If you know of answer, please tell me, because I have to find a solution. And of course Lord Price is occupied elsewhere, feeding the pheasants or something, and in any case cares not a jot for anything remotely connected to technical affairs.
subscribe: RSS feed