Reliability is arguably the single most important criterion for any e-commerce project. The SSL protocol helps reduce risk and provide an adequate level of protection for the information a user submits. Let us look at how it works, what types of certificates exist and why no online store can do without one today.
Why almost nobody thinks about a secure connection
While debates rage about how secure messengers are and how far governments intrude into private life, most people never pay attention to whether a website uses a secure connection. And even those who notice rarely realise how important it is.
In January and February 2016 alone, hackers in Ukraine made 7 attempts to break into government websites. In 2015 there were recorded attempts to interfere with the operation of several energy companies — a number of regional power utility servers were taken offline at the time. New reports of DDoS attacks appear in the press on a regular basis. Not so long ago even the website of the world-famous British broadcaster BBC was hit by cyberattacks.
How many Ukrainian media websites do you think are protected reliably enough? The answer is striking: as of the beginning of 2016, out of 145 resources reviewed by the Digital Security School, only 14.5% of online publications used dedicated protection services.
Half a billion transfers and a fair question
Between 1 January 2015 and 1 January 2016, Ukrainians made over half a billion transfers to the accounts of online stores. And these figures cover domestic resources only: foreign ones accounted for just about 9 million payments.
For reference: what SSL is
SSL is a cryptographic protocol that provides secure communication. Using asymmetric cryptography, it establishes a secure channel whose main advantage is independence from the application protocol: SSL can negotiate the encryption algorithm and the session key.
- Request. You open a site with an installed SSL certificate, and the browser asks the server to identify itself.
- Response. The server sends a copy of its SSL certificate.
- Verification. The browser confirms that the certificate is genuine.
- Encryption. Only after that does SSL begin encrypting all the data coming from the client.
That is exactly why the familiar "http" turns into "https", where the s stands for secure, that is, protection.

What types of certificates exist
An SSL certificate can cover either a single host or a domain together with its subdomains. There are different types of certificates, depending on how much information they confirm: from the authenticity of the domain name to the authenticity of the company itself.
For a single host
The certificate protects one specific host — the simplest option for a small resource.
For a domain with subdomains
A single certificate covers the main domain and its subdomains at once.
Domain validation
The minimum level of verification: the certificate confirms that the domain name is genuine.
Extended validation (EV)
The highest level: it confirms the authenticity of the company that owns the site.
Indeed, SSL certificates with EV (extended validation) enjoy greater trust, because obtaining one takes a great deal of effort and an astonishing amount of legal paperwork. As a rule, they serve as a kind of guarantee that the company is serious and takes its relationship with customers responsibly.
How to tell whether a site uses a secure connection
That said, most users do notice the browser's hints that a page is encrypted. The address bar highlighted in green, for example.

Unfortunately, few people on the Ukrainian internet market know about EV SSL certification (and that is exactly what gets highlighted) — just as few know about the need for encryption in general.
Why an online store needs an SSL certificate
Above all, it lets you protect your business and, most importantly, build a relationship of trust with the customer. Any information users send through the site — whether a name, a phone number or a bank card number — leaves in encrypted form.
- Confidential data exchange between the client and the server.
- Fewer potential risks for a business in e-commerce.
- A relationship of trust with the customer.
An SSL certificate is direct proof that a site is secure and clearly set up for the long run.
We build resources for e-commerce and strongly recommend SSL certificates to all of our clients. Today they are essential for every e-commerce project without exception.The ANIART developers
Conclusion
With the threat of data theft growing sharper by the day, domestic companies would do well to adopt this excellent technology. It does cost a certain amount, yet, as practice shows, it not only guarantees the safety of both the business and the customer but also helps increase sales.
And we would encourage Ukrainian internet users to be more attentive: instead of fearing transactions, make the right choice of online stores you can trust.
