Skip to content

SSL Explained: The Importance of Secured Socket Layers

Secure connection icon vector illustration isolated on white background, flat style secured ssl shield symbols

A Secured Socket Layer, or SSL, is the usual way that a website creates a secure connection with a web browser. Whenever a web surfer visits a secure site that uses SSL technology, it creates an encrypted link between their browser session and the webserver. SSL is the industry standard for secure web communication and is used to protect millions of online transactions each day.

What Does Encryption Mean?

Encryption simply means that the information that is going back and forth between an individual’s computer and the website is scrambled so that no one else can understand it. A formula on each side is used to scramble the information before sending it and unscramble it upon receipt. If a hacker happens to intercept the personal information en route, it would be worthless to them.

What is an SSL Certificate?

The web server must have an SSL certificate before it can create an SSL connection. When someone activates SSL protocols on their web server, they are asked to answer questions that will establish their identity. The questions ask for information about both the website and the company. After the SSL certificate is requested, the web server creates two cryptographic keys, one is a Private Key and the other is a Public Key. These keys are used along with the encryption formula to create a secure link between the web server and browser sessions.

Public Keys vs. Private Keys

As the name implies, the Public Key is not kept secret. It is placed into the Certificate Signing Request (CSR) which is a data file that contains the website’s details. The CSR is submitted to the SSL Digital Certificate group for validation as part of the SSL certificate application process. Once the details are validated, the SSL certificate is officially issued, and the website is allowed to use SSL. Next, the webserver confirms that the SSL certificate matches the Private Key. This makes sure that the SSL certificate is only used by the website that originally requested it. At this point, the webserver is able to create safely encrypted links, or communication paths, between its website and a customer’s browser.

What’s in an SSL Certificate?

Most SSL certificates include the domain name (web address), company name, company address, the certificate’s expiration date, and information about the certification authority who issued the certificate. Individuals are not usually allowed to possess an SSL certificate. In virtually all cases, SSL certificates are only issued to companies.

How Does SSL Work with My Browser?

The typical web user isn’t required to understand the complex process behind the SSL protocol. A key indicator is processed by the web browser to indicate that it is protected by an SSL-encrypted session, and the browser will show a small lock icon in the lower, right-hand corner of the screen. If the lock is clicked, it will display the SSL certificate and all the details.

Behind the scenes, the browser retrieves the SSL certificate whenever it connects to a secure site. The browser checks to make sure that the certificate has not expired, whether or not the issuing authority is one that the browser trusts, and that the certificate is being used by the same website to which it was issued. If either safety check fails, the browser will let the user know that the site is not secured by SSL through a warning message. The user has the choice of trusting the site or leaving.

HTTP Secure

Hypertext Transfer Protocol Secure, or HTTPS, combines standard HTTP with SSL for secure identification and encrypted communication of web servers. This standard is frequently used for online payments and other transactions that involve sensitive information. One way to instantly know if a site is using the HTTPS standard is to look at the address at the top of the page. If the address starts with “https” instead of the typical “HTTP”, the site is using HTTPS security measures. It’s important to keep in mind that only a portion of the website may be using HTTPS, while the vast majority might be using simple HTTP. The idea behind HTTPS is to create a secure channel over a mostly unsecured network. For example, while it is critical that online banking uses HTTPS to secure a customer’s account information, they would not need to go to that extreme to protect pages that simply tell the public how to apply for a new loan or credit card.

Related Articles

Related Articles

All
  • All
  • Easy Prey Podcast
  • General Tech Topics, News & Emerging Trends
  • Home Computing to Boost Online Performance & Security
  • IP Addresses
  • Networking Basics: Learn How Networks Work
  • Online Privacy Topics to Stay Safe in a Risky World
  • Online Safety
  • Uncategorized
Amazon Scams

Amazon Scams Come in All Shapes and Sizes. Are You Prepared?

Tell Amazon ASAP if you’re a victim of a delivery scam. Amazon takes fraud and scams quite...

[Read More]
Ron Zayas talks about data privacy and security.

How Companies are Collecting, Tracking, and Selling Your Personal Information

The modern world comes with many technological and digital conveniences. But unfortunately, many of them come with…

[Read More]
A young woman sits in a cozy room, literally and metaphorically encircled by a vibrant, 360-degree holographic bubble of personalized social media, videos, and apps.

What Is a Filter Bubble? How Algorithms Shape What You See Online

When you and your friend in another city search for the exact same thing on Google, you…

[Read More]
A woman sitting at a desk and using a computer to research sustainable building materials with the help of an AI assistant.

AI Is Changing Privacy Laws–Here’s What You Need to Know

AI is everywhere. Even if you’re not logging into ChatGPT every day, everything you do on the…

[Read More]
Adjusting your browser security settings can help you stay safer online.

Browser Security Settings Make a Difference to Online Safety

If you’re getting online, you’re using a browser. Whether you’re a Firefox fan, a Chrome devotee, or…

[Read More]
Diagram comparing public and private IP addresses: local devices use private IPs via a router, which connects to the internet through a single public IP from an ISP.

Public IP vs. Private IP Address: What’s the Difference and Why It Matters

Have you ever looked up your IP address on a tool like WhatIsMyIPAddress.com’s tool and noticed what…

[Read More]