{"id":1947,"date":"2016-05-23T04:00:25","date_gmt":"2016-05-23T08:00:25","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=1947"},"modified":"2023-04-10T18:14:09","modified_gmt":"2023-04-10T22:14:09","slug":"what-is-lets-encrypt-what-should-we-make-of-it","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-lets-encrypt-what-should-we-make-of-it\/","title":{"rendered":"What Is Let\u2019s Encrypt? What Should We Make of It?"},"content":{"rendered":"<h2>A new Certificate Authority, Let&#8217;s Encrypt, is here and will soon begin offering free DV SSL Certificates.<\/h2>\n<p>Let\u2019s Encrypt is a new non-profit Certificate Authority (CA) sponsored and founded by industry advocates; such as, the Electronic Frontier Foundation (EFF), Mozilla, and the Internet Security Research Group (ISRG). Let\u2019s Encrypt will be launching very soon and will be offering free SSL certificates.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1948\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/10\/letsencrypt.jpg\" alt=\"letsencrypt\" width=\"416\" height=\"234\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/10\/letsencrypt.jpg 416w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2015\/10\/letsencrypt-300x169.jpg 300w\" sizes=\"auto, (max-width: 416px) 100vw, 416px\" \/><\/p>\n<p>Of course we are strong supporters of universal encryption and hope that Let\u2019s Encrypt will lower barriers for websites that can\u2019t afford existing SSL options. However, we do not think Let\u2019s Encrypt should be a viable option for commercial use of any kind, you should continue to buy from established Certificate Authorities (CAs) such as Symantec, <a class=\"wpil_keyword_link \" href=\"https:\/\/www.thesslstore.com\/comodo\/comodo-ssl-certificates.aspx\" title=\"Comodo\" data-wpil-keyword-link=\"linked\">Comodo<\/a>, GeoTrust, RapidSSL and Thawte. Especially since the pricing for basic encryption\/Domain Validated (DV) certificates are available for extremely low and affordable rates and still carry a strong brand name recognized by most web users. Also, Let\u2019s Encrypt will not be able to provide a few major types of SSL certificate solutions, like Extended Validation (EV) or multi-domain certificates and we definitely don\u2019t think that a free certificate solves a user\u2019s most pressing problem when browsing on the web: Authentication.<\/p>\n<h2>Let\u2019s Encrypt Will Have Major Limitations<\/h2>\n<p>Unfortunately, Let\u2019s Encrypt will have some <strong>very notable limitations<\/strong> due to their limited funding and infrastructure. Because they will only be offering free certificates, they will only be able to provide automated, basic encryption only\/Domain Validated (DV) SSL certificates with no other frills that typically come with SSL certificates.<\/p>\n<p>These limited certificates only confirm the ownership of your domain, and don\u2019t involve any vetting of your business information (which typically takes a validation expert\u2019s time and effort to manually verify) or any additional features found in basic certificates, like a site seal or a warranty. In general, businesses that want to offer their potential customers an additional layer of safety &amp; security like activating all SSL indicators in browser or from promoting authentication should opt for OV or EV certificates from trusted 3rd party security companies\/commercial CAs such as Symantec and Comodo.<\/p>\n<p>EV certificates (like the one we use on our website) are the only kind that activate the <strong><a href=\"https:\/\/www.thesslstore.com\/extended-validation-ssl-certificates.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">Green Address Bar<\/a><\/strong>, the most prominent SSL indicator in the world, which proudly displays your business name and location next to your URL in web browsers in green. Green means go in all languages and for all ages!<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<p>Many of the largest companies in the world use EV SSL certificates because they are better equipped to communicate trust and security to the general website visitors. Twitter, Apple, and PayPal, for example, all use EV SSL to ensure users have absolutely no doubt they are on the official and intended website. Banks almost exclusively use EV SSL because <strong>EV certificates are less vulnerable<\/strong> to unauthorized issuance and phishing attacks. The green bar cannot be duplicated by a hacker at all.<\/p>\n<p>Also, Let\u2019s Encrypt won\u2019t have support for Wildcard SSL certificates at launch. Wildcard certificates allow you to protect subdomains of your choice, indicated by the use of an \u201c*\u201d (giving you the option to extend SSL security to the location of the asterisk, such as \u201c*.domain.com\u201d or \u201c*.employeeportal.domain.com\u201d). These certificates are incredibly versatile and an efficient option for management reasons. For some websites, they can actually be the only option if they need to have immediate SSL security on new subdomains.<\/p>\n<p>We believe these are <strong>major limitations<\/strong> which will exclude a notable number of users and use-cases from even trying out the certificate.<\/p>\n<h2>Years of Experience Taught us That Users Need More than a Free Certificate<\/h2>\n<p>We have worked with hundreds of thousands of customers and if our experience has taught us anything, it\u2019s that SSL can be confusing, and many people need help. Knowing what type of certificate you need and how you will get it successfully working on your network are the most common and most serious questions our customers and partners have. Anyone who works with SSL knows it\u2019s about much more than just making a purchase. These complex security solutions need hand holding, therefore are not a type of product that can just be sold and never spoken of again. People need help with validation, installation, site seals, Always on SSL implementation, random industry updates &amp; compliance, etc. even if it is just with a basic DV certificate.<\/p>\n<p>Every customer of ours gets 24 x 7 access to our customer support to help with any part of the SSL process. For example, when the <a href=\"https:\/\/www.thesslstore.com\/blog\/how-to-protect-yourself-from-the-heartbleed-opnesslbug\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Heartbleed bug<\/strong><\/a> was discovered, our team of SSL experts was answering questions non-stop from website owners and administrators worried about what to do next. When the industry announced the SHA-2 migration, we had thousands of calls from confused users who did not know if they would be affected.<\/p>\n<p>Due to the nature of Let\u2019s Encrypt, they won\u2019t have staff on hand to help you get your first SSL certificate installed, or have a 24 x 7 hotline the next time a critical bug is discovered. Community support will be available, but we don\u2019t think this will be the best option for professionals and business owners who need to quickly get their site configured and working, and move on to the job they really care about which involves making money. If an issue with the magnitude of Heartbleed occurred and your business was relying on a free certificate issued by Let\u2019s Encrypt and you need help navigating the process to resolve the issue, you might be in some serious trouble all in an attempt to save $20-$50 at the onset\u2026it\u2019s just not worth the risk.<\/p>\n<p><strong>We have found that what our customer\u2019s need most isn\u2019t a free certificate, but help and guidance on how to ensure their SSL configuration is working properly and is adequately secure.<\/strong> Most businesses view time as the most precious commodity, so they are more than willing to pay for a security product that is backed with 24\/7 support and quick solutions, rather than simply getting a free product that requires countless hours of manual intervention. Web security in nothing to cut corners on in this day and age, it needs to be left to industry experts and security companies with specialized &amp; optimized security protocols, processes &amp; procedures.<\/p>\n<p>We also strongly believe in the reputation of the existing CAs. Numerous studies have shown that globally recognized CAs like Symantec, Comodo, GeoTrust, and Thawte reassure millions of people using the web every day. Case studies have shown that using a \u201cSite Seal\u201d (an interactive badge showing your website\u2019s use of SSL and choice of CA) from a trusted CA can improve customer trust and conversion rates, especially the Norton\u00ae Secure Seal, which comes with all Symantec branded certificates and it the most-recognized trust mark on the web.<\/p>\n<p>Let\u2019s Encrypt\u2019s one-size-fits-all approach isn\u2019t perfect. A personal blog has different needs than a corporate homepage. At <strong><a href=\"https:\/\/www.thesslstore.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">The SSL Store&#x2122;<\/a><\/strong>, we believe there is a perfect solution for everyone: personal attention and attentive support behind globally recognized brands.<\/p>\n<p>As SSL encryption becomes more prevalent, websites and online businesses looking to stand out will need to do more. We hope that the green padlock, an indicator that SSL is being used on a website, will become ubiquitous across the web.<\/p>\n<p>Those looking to differentiate themselves should look to do more and get an EV certificate which activates the more prominent Green Address Bar, proudly displaying your companies legally registered name and country. The rigors of the EV process doesn\u2019t just get you a fancy display in your browser \u2013 it also makes replicating your certificate extremely harder (a hacker may just more likely target a site with let\u2019s say a free basic certificate?), which can keep your website and reputation safer.<\/p>\n<p>Whether you have never used SSL before, or are an existing customer with us, please give us a call to learn more about how you can use SSL to not just encrypt and secure your website\u2019s communications, but also improve your brand\u2019s reputation and increase customer loyalty.<\/p>\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>A new Certificate Authority, Let&#8217;s Encrypt, is here and will soon begin offering free DV SSL Certificates. Let\u2019s Encrypt is a new non-profit Certificate Authority (CA) sponsored and founded by&#8230;<\/p>\n","protected":false},"author":2,"featured_media":2848,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[],"class_list":["post-1947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","post-without-tags"],"views":25547,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/05\/Girl_Editing_Code_Photo-1.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/1947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=1947"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/1947\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/2848"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=1947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=1947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=1947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}