01 May 2009

SSL Certificates and Padlock Misuse

I recently discussed organisation names on SSL certificates. The padlock has become an overused visual indicator to indicate use of SSL certificates or broader protection measures.

Padlock icons have never been the exclusive browser indicator of a site using a valid, trusted SSL (more correctly now called Transport Layer Security [TLS], SSL's successor) certificate, and the position in the browser has varied considerably.

Here are a couple of mis-uses of the padlock symbol—neither are related to SSL certificates. They simply add to confusion about what is a secure website.

Partial web page screen capture showing a padlock icon with the words 'If your browser is not showing the secure padlock on your screen click on this padlock' Partial web page screen capture showing a padlock icon with the words 'This padlock is shown when we are collecting information about you. Please see our privacy policy for details of how we may use this information'

How do we expect users to understand what "secure server", "security certificate" and "security" mean in the web world? Maybe we should ensure our designers understand first.

Perhaps encourage them to read trusted resources like Learn About Secure Web Pages from Get Safe Online.

Then we can avoid pages like this:

Partial web page screen capture showing a gigantic padlock photograph taking up 70% of the web page and linking to a non-SSL web site

which links to a restricted access area, but not on a secure server!

Posted on: 01 May 2009 at 08:24 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
SSL Certificates and Padlock Misuse
http://www.clerkendweller.com/2009/5/1/SSL-Certificates-and-Padlock-Misuse
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/5/1/SSL-Certificates-and-Padlock-Misuse
Requested by 38.107.179.224 on Tuesday, 7 February 2012 at 21:23 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2012 clerkendweller.com