SSL证书比较

发布于 2024-12-18 01:14:48 字数 1459 浏览 2 评论 0原文

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

临走之时 2024-12-25 01:14:48

标准 ssl 证书在加密方面与高级证书一样安全。使用相同的算法/密钥。保费只是花费更多,因为据推测,证书颁发机构花费了额外的几微秒假装他们已经验证了您的身份。这主要只是一种营销策略,目的是从客户那里收取额外的费用,而几乎没有实际的安全收益。

大多数网络用户不了解 SSL,甚至不知道如何寻找锁定图标。他们会在他们认为对他们有利的任何地方输入他们的个人信息。建立网站的可信度比仅仅说“嘿,我们有 SSL”要困难得多。

standard ssl certs are JUST as secure, cryptographically, as the premium ones. The same algorithms/keys are used. The premiums just cost more because, supposedly, the certificate authority has spent a few extra microseconds pretending that they've verified your identity. It's mostly just a marketing ploy to suck extra $$$ out of clients for very little actual gain in security.

Most web users have no idea about SSL, or even to know about looking for the lock icon. They'll enter their personal information anywhere they think it'll benefit them somehow. Establishing a site's trustworthiness is far harder than just saying "hey, we've got SSL".

合久必婚 2024-12-25 01:14:48

正如其他人所述,扩展验证 (EV) 证书在结构上与标准域验证 (DV) 证书类似。区别不在于保护浏览器和站点之间的管道,而在于证书颁发者在授予证书的过程中所做的努力程度。

证书就像护照。说证书相同就像说来自两个不同国家的两本护照具有相同的安全特征。这意味着它们具有相同的防止被伪造的保护。然而,它并没有告诉任何关于证书/护照是否颁发给正确的人的信息。这就是域验证证书和扩展验证证书之间的区别。

例如,我不知道实际使用的标准,但“域已验证”就是这个意思。嘿,我们通过包含此域的电子邮件地址与您联系,并且您来自该公司,因此这是您付费购买的证书。通过域验证。

相比之下,扩展验证意味着证书颁发者可能会联系拥有请求证书的域的公司的法律部门,以验证请求者是否有权获取该域的证书。这样他们就可以验证,仅仅因为您在公司工作,您就无法获得颁发给您的公司域名的证书。

那么,正如其他人所说,这是否意味着您的用户会知道其中的差异,并对他们提供给您关注的信息感到足够偏执?你可能不知道。 如果他们应该提供财务信息,我会主动索要额外的 $$$。如果不是,那可能就没那么重要了。

As stated by others, the Extended Validation (EV) certificate is structurally similar to standard Domain Validation (DV) certificate. The difference is not about securing the pipe between the browser and the site, but rather the level of diligence done by the Certificate Issuer in the process of granting a certificate.

Certificates are like passports. Saying that the certificates are the same is like saying two passports from two different countries have the same security features. It means they have the same protection against being forged. It doesn't however tell anything about whether the certificate/passport was issued to the right person. That's the difference between Domain and Extended validation certificates.

For example, I don't know the actual criteria used, but 'Domain Validated' means just that. Hey, we contacted you at an e-mail address with this domain and you're from that company, so here's the certificate that you paid for. Validated by domain.

By comparison, the extended validation would mean that maybe the certificate issuer contacted the legal department of the company that owns the domain requesting the certificate to verify that the requester is authorized to get a certificate for that domain. That way they can verify that just because you work at the company, you're not going to be able to get a certificate with the company's domain issued to you.

So, as others have stated, does that mean your users will know the difference and be paranoid enough about the information they're giving you to care? You may not know. If they're supposed to give financial information, I'd spring for the extra $$$. If not, it probably doesn't matter as much.

贩梦商人 2024-12-25 01:14:48

我认为当你问这个问题时,你基本上是一语中的:

这足以说服用户想要以保密方式输入吗
信息??

但实际上,问题应该是:

这足以说服我的用户......

当我开始回复时,Marc B刚刚发布了他的内容 - 我同意他所说的大部分内容 - 我认为这最终是一个营销问题,只有你知道/ 您的企业可以回答。

如果您是 eBay,并且地址栏中缺少锁定图标可能会拒绝 0.01% 的客户 - 这可能非常值得这个价格。

如果您刚刚起步,并试图保持较低的开支 - 可能包括那些愚蠢的“由 GoDaddy SSL 保护”或他们在您网站上拥有的任何图标/徽标之一是一个很好的妥协。

GoDaddy 图标

I think you mostly hit the nail on the head when you asked:

is that enough to persuade users to want to enter in confidential
information??

But, really, the question should be:

is that enough to persuade MY users ...

As I started my reply, Marc B just posted his - and I agree with most of what he said - I think this is ultimately a marketing question that only you / your business can answer.

If you're eBay, and the lack of a lock icon in the address bar may turn away 0.01% of your customers - it's probably well worth the price.

If you're just starting out, and trying to keep expenses low - probably including one of those silly "Secured by GoDaddy SSL" or whatever icons / logos they have on your site is a good compromise.

GoDaddy Icons

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文