"You are losing sales. People look for the lock icon on the address bar."
Also, he can get SSL on his site for FREE in < 5 minutes using Cloudflare.
11–20 of 33 posts
"You are losing sales. People look for the lock icon on the address bar."
Also, he can get SSL on his site for FREE in < 5 minutes using Cloudflare.
Read section 4 specifically.
I would not bother with a technical explanation of any of this stuff. He doesn't care, and bluntly it's not particularly easy to point to major compromises in which the lack of SSL played a key role. Most of the time, data is siphoned out of "PCI-compliant" shops that do use SSL, and they get it through database compromises and/or compromised POS terminals. MITM doesn't seem to be worth the effort, if only because the other stuff is so easy and yields so much data.
Nor would I bother talking about PCI. Most of their requirements are silly and do little or nothing to prevent exposure of PII or fraud. What matters to him is the agreement with his processor, not some 4000-page document that wants to tell you how to take a piss.
Eyes on the money. No processor, no business, no money. Keep it simple. If that doesn't do it, you've done your part and should walk away. It's not your problem.
The second thing, the fact it's http and not https suggests he's collecting and storing this information, which is almost certainly a violation of his credit card agreement with his bank. Credit card information is not supposed to be stored, he passes that off through a secure connection with his processing service, who will only do that through a secure connection, and he gets a transaction ID and authorization and that's all he references from that point on.
So this is less about SSL/TLS as it is, he's doing it all wrong. And it's depressing that he's in business, only made possible by the ignorance of his customers who actually agree to give him all of this information, and on an insecure connection no less.
Scaring them with the bad stuff might not be effective, people don't react well to being told they're doing everything wrong. Perhaps showing them an easier solution that reduces their admin hassles & could potentially increase their sales is a better way to approach this.
Unless he is a government, insurance, credit card, bank, real estate organization he should not be asking for a SSN online or storing it unless they are for his employees or the transactions being conducted requires notification to the IRS or the transaction is subject to the customer identification program rules. Either way PII like this should be securely stored offline. For Credit Card information it has to all be…
>I am trying to explain to him why this is bad, but he doesn't really care. "You are losing sales. People look for the lock icon on the address bar." Also, he can get SSL on his site for FREE in < 5 minutes using Cloudflare.
>I am trying to explain to him why this is bad, but he doesn't really care. "You are losing sales. People look for the lock icon on the address bar." Also, he can get SSL on his site for FREE in < 5 minutes using Cloudflare.
Also, for a totally non-technical person, it will take – and be billed as – more than 5 minutes of someone else's time to get even that free half-measure into effect.