{"id":4281,"date":"2020-05-13T13:04:57","date_gmt":"2020-05-13T11:04:57","guid":{"rendered":"https:\/\/ditech.media\/?p=4281"},"modified":"2020-05-19T10:52:08","modified_gmt":"2020-05-19T08:52:08","slug":"why-use-ssl-for-your-site","status":"publish","type":"post","link":"https:\/\/ditech.media\/news\/digital-defence\/why-use-ssl-for-your-site\/","title":{"rendered":"Why Use SSL For Your Site"},"content":{"rendered":"<p style=\"text-align: justify;\">Do you have a website and wondering if you should get SSL certificate for it or not? Do you want to know why you should use SSL certificate for your website? If the answer is YES, then this article is for you.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-4283\" src=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website1.png\" alt=\"\" width=\"572\" height=\"186\" srcset=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website1.png 877w, https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website1-300x97.png 300w, https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website1-768x250.png 768w\" sizes=\"(max-width: 572px) 100vw, 572px\" \/><\/p>\n<p style=\"text-align: justify;\">Since July 2018, Google has started flagging all unencrypted HTTP website as <strong>\u201cNot Secure\u201d<\/strong>. So how does this affect your site and its users?<br \/>\nWell, the answer is it will affect your website in different ways.<br \/>\nIf your website allows users to submit any personal information (e.g. name, email address, credit card numbers, etc.), then you should probably get an SSL certificate.<br \/>\nHowever, for me, regardless if you will ask your website users to submit any personal information or not, you should still get an SSL certificate.<br \/>\nWhy? Well, let\u2019s start with knowing what an SSL certificate is, why you need it, and how you can get one.<\/p>\n<h3>What is SSL certificate?<\/h3>\n<p style=\"text-align: justify;\">We know or should know that the website URL contains a protocol.<br \/>\nYeah I know that\u2019s a technical word but just look at your website URL and you will see either an HTTP (Hypertext Transfer Protocol) or HTTPS (Hypertext Transfer Protocol Secure) on it.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-4284\" src=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website2.jpg\" alt=\"\" width=\"499\" height=\"233\" srcset=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website2.jpg 731w, https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website2-300x140.jpg 300w\" sizes=\"(max-width: 499px) 100vw, 499px\" \/><\/p>\n<p style=\"text-align: justify;\">So what\u2019s the difference between HTTP and HTTPS?<br \/>\nSimply put, if you are seeing HTTP when visiting a website, that means the connection between your browser and the server of the website is not secure. It\u2019s not private.<br \/>\nIt\u2019s like you are talking to your friend about the crimes you\u2019ve done last night and lots of people around listening to your conversation. That\u2019s creepy right? Yeah I know it is.<br \/>\nSo you might want some sort of a privacy so anyone can\u2019t hear your conversation. You might want to go inside the room or go to a private place.<br \/>\nSame as visiting a website, if you will provide sensitive information to a website \u2013 paying using your credit card for example \u2013 you don\u2019t want your card details to be exposed to public. So you need it to be submitted to the website securely, through a private or secure connection called HTTPS.<\/p>\n<p style=\"text-align: justify;\">So maybe you are now convinced to use HTTPS over HTTP. Maybe you are now thinking to redirect your website users to the HTTPS version of your website to protect them.<br \/>\nBut wait, I think I never mentioned that you cannot just simply use the HTTPS. You need something that will enable it on the website server, and this something is call SSL certificate. Yeah! Finally, we are now talking about SSL certificate!<br \/>\nSo in a nutshell, SSL certificate is what enables or activates HTTPS protocol on the web server.<\/p>\n<h3><span style=\"font-weight: 500;\">Debunking a myth about SSL Certificate<\/span><\/h3>\n<p style=\"text-align: justify;\">As what I have mentioned, you need an SSL certificate to activate the HTTPS version of your site. But before we proceed, there\u2019s one thing that I want to clarify first.<br \/>\nMost website users think that SSL certificate will redirect their site to HTTPS automatically.<br \/>\nUnfortunately, that is not what SSL certificate is all about. Again, it activates the HTTPS version of your site, but it will not redirect your site to HTTPS. There might still be a chance that some users will access the non-secure version of your site \u2013 HTTP.<br \/>\nSo here\u2019s a comparison that might help you understand. However, if you already know about this, feel free to skip.<\/p>\n<h3>Website without SSL certificate<\/h3>\n<p style=\"text-align: justify;\">You can access the site via HTTP only.<br \/>\nIf you will access the site via HTTPS, the browser will show you a security warning like the screenshot below:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-4282\" src=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website3.jpg\" alt=\"\" width=\"536\" height=\"271\" srcset=\"https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website3.jpg 702w, https:\/\/ditech.media\/wp-content\/uploads\/2020\/05\/website3-300x152.jpg 300w\" sizes=\"(max-width: 536px) 100vw, 536px\" \/><\/p>\n<p style=\"text-align: justify;\">This is also one of the reason why you should get an SSL certificate for your website, because some browsers or devices will redirect a website to HTTPS version automatically.<br \/>\nSo if your website doesn\u2019t have an SSL certificate, your website visitors will encounter the above warning. Enough to scare them away.<\/p>\n<h3>Website with SSL certificate<\/h3>\n<p style=\"text-align: justify;\">Well, you don\u2019t have to worry about the security warning if you have an SSL certificate installed to your website server. This is because the HTTPS version of your site is already enabled.<br \/>\nBut let us go back to the purpose of SSL. We want it installed to the website to protect users, right? So we might want all users to redirect to the HTTPS version of the site to protect them.<br \/>\nBut then again, this has nothing to do with the SSL certificate, if you want all users to be redirected to the HTTPS version of your site, you need to configure a force redirection to it. There are different ways on how to do it, but we will not talk about it here.<\/p>\n<h3>How to get an SSL certificate?<\/h3>\n<p style=\"text-align: justify;\">Most web hosting companies if not all, offer SSL certificate. So if you want to buy one, it is recommended to buy it from where your website is hosted. This is the most efficient way, because your web host can easily provide you the requirements that you need to buy and install the certificate.<\/p>\n<p style=\"text-align: justify;\">Before buying your SSL certificate, you need to know the following:<\/p>\n<ul>\n<li>Types of SSL certificate<\/li>\n<li>Requirements for SSL certificate<\/li>\n<\/ul>\n<h3>Types of SSL certificates and their requirements<\/h3>\n<p style=\"text-align: justify;\">There are different types of SSL certificates. While they are the same in terms of encryption \u2013 256 bit \u2013 their differences can be determined by the level of the authentication.<\/p>\n<h3>Domain Validation (DV) SSL certificates<\/h3>\n<p style=\"text-align: justify;\">DV certificate is the quickest, easiest and most cost-effective SSL certificate you can get. You can even get this SSL certificate for free. This type of certificate only requires proof of ownership of the domain name that you want to secure.<\/p>\n<p style=\"text-align: justify;\">Though DV is the most cost-effective SSL certificate, it is not ideal for commercial websites. The Certifying Authority will not examine the legitimacy of the organization who will request for a DV certificate. Thus, its trust level is low, and is not recommended for commercial websites.<\/p>\n<p>Requirement:<\/p>\n<ul>\n<li>Domain ownership validation<\/li>\n<\/ul>\n<h3>Organization Validation (OV) SSL certificates<\/h3>\n<p style=\"text-align: justify;\">OV certificate is way better than DV, because it has a higher trust level. It has a step higher authentication than DV.<\/p>\n<p style=\"text-align: justify;\">To receive an OV certificate, the organization must prove that it owns the domain name, and prove that the business it operates is registered legally. Thus, this type of certificate is ideal for commercial websites.<\/p>\n<p>Requirements:<\/p>\n<ul>\n<li>Domain ownership validation<\/li>\n<li>Proof that you are operating a legitimate business<\/li>\n<\/ul>\n<h3>Extended Validation (EV) SSL certificates<\/h3>\n<p style=\"text-align: justify;\">EV certificate provides the highest level of trust and highly recommended for business websites. This is because it will display the name of the organization when you click the padlock on the address bar. This is the most recognized indicator of a secure and trusted website.<\/p>\n<p>Requirements:<\/p>\n<ul>\n<li>Domain ownership validation<\/li>\n<li>Proof that your business is legitimate including its physical address<\/li>\n<\/ul>\n<p>Alright. I think you are now ready to secure your site. Good luck!<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Do you have a website and wondering if you should get SSL certificate for it or not? Do you want to know why you should use SSL certificate for your website? If the answer is YES, then this article is for you. Since July 2018, Google has started flagging all unencrypted HTTP website as \u201cNot &hellip;<\/p>\n","protected":false},"author":3227,"featured_media":4300,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[162,157],"tags":[],"_links":{"self":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/4281"}],"collection":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/users\/3227"}],"replies":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/comments?post=4281"}],"version-history":[{"count":0,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/posts\/4281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media\/4300"}],"wp:attachment":[{"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/media?parent=4281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/categories?post=4281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ditech.media\/wp-json\/wp\/v2\/tags?post=4281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}