Why are we charging extra for SSL?
streaming.nfm.id.au
streaming.nfm.id.au
* IPv4 addresses are NOT free by any means.
* Having an SSL certificate requires extra configuration on the server.
* Legitimate SSL certificates are not free (VeriSign, etc, if your site uses StartCom then you're doing it wrong)
That's just a few points.
You can use SNI but you probably have one website and one certificate for all customers anyway.
> if your site uses StartCom then you're doing it wrong
Why? (honest question)
I meant to say StartSSL, which is the free SSL certificate provider. As far as I'm aware, their free certificated come with no warranty of any kind (although I could be wrong). Depending on how large your business is, you would more than likely go with a trusted brand such as VariSign/GeoTrust/Thawte.
Although for small projects, they're more than fine if all you care about is quickly and cheaply securing transmissions.
Do customers really care about the name brand or "warranty" of the SSL certificate? What percentage of customers are even aware of who issued your certificate, and do those customers really have concerns about StartCom?
This sounds like the argument we heard from DynDNS salespeople last year, about how our customers expect us to be using "enterprise" vendors, rather than "consumer-grade" vendors like Amazon Web Services. Even our savviest customers have never asked us who our DNS provider was.
and lose all your IE on XP viwers and all your non-Honeycomb/ICS android viewers? All your 3.x iOS users? All your blackberry users?
Are there any large sites using SNI to handle SSL queries? I'd love to hear about their experiences.
http://www.getharvest.com/blog/2009/06/unlimited-clients-pro...
Sure, it costs a little bit of money. But it makes our users little safer when they log into our service. There aren't many levers you have a SaaS product that you can pull to really make user data secure once it leaves your servers.
As pwim said, if you can't recover the cost per user then your company must have some big problems. I always frown at a pricing page that says SSL is an add-on, it demonstrates that whomever is running things behind the curtain isn't really concerned about the safety of user data in their app.
Using SSL for all private data is an absolute must though.
tl;dr sites that need ssl usually can pay more for same service.
SLAs are buzzword nothings? Man, the naiveity is simply oozing out of this post.
All of those things relate to the security of the provider so you expect them as standard. SSL, as a customer facing feature, secures data when it's out on the wilds of the Internet or on the customer's network. It's a bit like charging extra to offer signed courier delivery instead of USPS.
Everything he listed relates to security at the provider, which you'd expect as standard. SSL merely secures the connection across the Web to the provider, but not within their system.
Is it just me or is anyone else tired of these blogs on Hacker News? It seems that anyone who has a website and some time can get their opinion to the top of the list.
I should try it.