SSL 'site seals' are even worse than you thought
certsimple.com
certsimple.com
We considered introducing a site seal because it's a common request but we've decided not to do it (at least for now) for reasons similar to many in this post.
It's hard to design a seal that accurately conveys the value added to a site's security by a CA, and the potential for abuse is high. A CA seal either means nothing or implies too much because having a cert from a trusted provider is just one part of what it means to be a secure website.
I want Let's Encrypt to do what it is supposed to: free automated certificates. Let third party tools (like Qualys SSL Labs) rate how good it is.
Most of HN already knows that, so more importantly:
- The reason the site seal uses JS (rather than a simple link) is that the link is actually to the CA's sales page, not the site report - there's no 'nofollow' so it's a massive search engine rank boost to the CA.
- There's a bunch of studies from non-security industry sources about how 'site seals' actually impact conversions. Some are positive, some are negative, but the biggest takeaway is that 'site seals' increasing conversations is by no means a foregone conclusion:
http://info.usertesting.com/OnDemandWebinarOptimizeYourWebFo...
http://www.widerfunnel.com/conversion-rate-optimization/do-m...
http://www.getelastic.com/best-practice-gone-bad-4-shocking-...
https://vwo.com/blog/website-credibility-and-conversion-kill...
http://www.quicksprout.com/2013/10/31/the-7-things-every-gre...
http://blog.optimizely.com/2013/12/08/ab-test-assumption-sec...
https://econsultancy.com/blog/5499-why-good-checkout-design-...
https://econsultancy.com/blog/7941-which-e-commerce-trustmar...
"Cost money, because they require the certificate authority to check who your are."