Research, Technology

How to find out if a site is safe and what is an SSL site certificate

We are talking more and more about data protection andthat they should not go to anyone but us, and maybe someone with whom we want to share them. Often this is the site on which we register. We don't mind giving him our data, but if we simply transfer it over the ”http” protocol, it is relatively easy for third parties to access it and use it for their own purposes. And it's good if it's just about advertising. Therefore, I propose to talk about what an ssl certificate is for a site, how it can make our life easier and more secure. And at the same time, we will consider examples of such certificates, estimate a set of data that can leak to the side, and understand which sites it is better not to use so as not to risk confidentiality.

It is very easy to intercept your data without a security certificate.

Content

  • 1 What data can be stolen on the Internet
  • 2 Which sites are dangerous
  • 3 What is an SSL certificate
  • 4 What types of SSL certificates are there
  • 5 Is a website certificate so important?

What data can be stolen on the Internet

To begin with, let's figure out what kind of data can be stolen on the Internet. Among them can be anything that you send to the server. But in general, attackers are most interested in the following:

  • Usernames and passwords
  • First name, last name, year of birth
  • The address
  • Email
  • Phone number
  • Payment data (card number and other similar information)

It seems that the most important is the paymentinformation. But the username and password are also important. After all, if you use the same bundle on all sites, it is enough to get it and then substitute it through the bot in all registration forms. And so it is possible block devices and steal money, and do something else.

How does the Internet and social networks affect the brain?

What sites are dangerous

First of all, those resources that do not have ssl are dangerouswebsite certificate. If it is not there, the browser will warn you about it. Of course, visiting it does not mean that your data will be stolen, but it means that they didn’t think about protection here or simply saved on it.

We all use the Internet. But it must be done safely!

Search engines often struggle with such sites andthey try to exclude them from the search results or give them not in the first lines of the search result. Therefore, if you have a website and it has problems with traffic, keep this in mind - issuing a certificate will increase the number of visitors.

What is an SSL certificate

An SSL certificate is the digital signature of your website.. When it is, a padlock appears in the address bar and visitors understand that the data they transmit is safe. Otherwise, as I said above, they can be intercepted.

Initially SSL was a cryptographic protocolwhich has served its purpose for a long time.But over time, it became outdated and had to come up with something new. This is how the TSL protocol was born, but the previous name has already taken root and the new product was still called the site's SSL certificate.

The SSL certificate contains the following information:

  • the domain name for which the certificate itself is issued
  • certificate validity period
  • the legal entity that owns the certificate and its location
  • information about the SSL certificate provider

Any domain owner can create an SSL certificate. There are versions for both individuals and legal entities. But not all of its options are available to both.

In order to make a certificate, you need:

  • create a unique key for the site
  • send a request to issue a certificate to a certification authority
  • wait for the issuance of a certificate signed by a certification authority certificate
  • add a certificate to a site or server
  • After that, browsers and operating systems willknow that the site can be trusted. A special icon will appear in the address bar, users will be safer, and search engines will place the site in search results more often.

    Just remember that https is better than just http

    What types of SSL certificates are there

    In general, if it’s quite simple, then SSL certificatescan be divided into four main types. It will be beginner, intermediate and advanced levels. And the fourth will be a certificate for application developers. They differ depending on the information that is encrypted in them, and on the needs of the resource.

    The simplest type of certificate is called Domain Validation (DV). This is the only certificate that canget an individual. But legal ones can also use it if the site is not very serious (financial, government, and so on). In fact, this is just a check of the right to control a domain. It works over the https protocol and is suitable for sites that only need to encrypt the personal data required during registration. Such a certificate is issued per day according to a simplified program.

    What will the Internet of the future look like? We give examples.

    The middle certificate implies standard verification and is called Organization Validation (OV). Its presence confirms that the domain belongs tospecific organization and it has the right to manage it. When registering for verification, materials from open sources are used. So the certification center is convinced of the good faith of the company and that it can be trusted with its data. Even ways to get in touch are checked - in particular, a phone number. It usually takes 3 days to issue a certificate, but sometimes it takes a little longer.

    The most serious certificate, which is used in financial institutions, the public sector and in other similar places, is called Extended Validation (EV). The review is carried out with the utmost care andnot only the domain ownership of a particular organization is taken into account, but also its actual existence, as well as the legitimacy of its activities. Employees of the certification center conduct an extended legal and financial due diligence, taking into account all the nuances. Such a certificate is issued the longest - usually from five days.

    A separate type of certificate for developers.

    The last type of certificate is Code Signing - a certificate for developers so that they can sign their applications with it, confirming their authenticity and the integrity of their content. The release takes up to three days.

    Usually all certificates are issued for onedomain, but there are also those that are multi-domain. They are less common and more expensive than regular ones, but they have their advantages. If you want to make a certificate for your site, you can do it in a certification authority.

    How important is a website certificate?

    As you can see, the certificate not just important, but very important. It ensures user safety andthe information they transmit, on the one hand, and on the other, allows the site to receive more registrations or provide more services. For example, you can boost sales or drive more organic traffic through higher search engine rankings.

    Now you know that if you are the owner of the site, then you it is worth getting an SSL certificate, and if you are a Web user, then keep an eye on its presence, and only if it is, you can feel safe.