SSL Still Mostly Misunderstood
darkreading.com
darkreading.com
And you guessed it... no SSL certificate.
Shocks me that either nobody has complained to them or they haven't listened.
I also think there needs to be a push to separate the encryption and remote server verification parts of SSL/TLS. I'd love to encrypt all communication with the sites I run, but am completely uninterested in coughing up cash for an SSL cert.
I've configured https servers (with a cert from Verisign and self-signed) and thought that communication to-and-from those servers was encrypted, and thus secure. Now I'm wondering what I've misunderstood.
I set the browser to notify when transitioning from https to http. Then I try to force a site to give me an https connection before I start entering sensitive data. If the browser pops a protocol transition warning, I back out.
It also annoys me when an https delivered page in turn pulls in http content. This breaks the security of the entire rendered page. Having the user check for the https protocol in the address bar is not sufficient.
It seems to me that the basic concepts involved are not that difficult (leaving out the math). Don't start communicating until you know the "channel" is secure and the other endpoint is verified. Verification is accomplished through a chain of trust. Pages are composed of multiple pieces. If any piece/participant in the channel comes from an unsecured or unverified source, you must treat the channel as compromised.
But no browser presents them in a clear and meaningful fashion, with enough context to describe plainly to the average user what is going on.