[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 397
  • Last Modified:

SSL Advise

Hello Experts

I am gathering all the requirements which I would need to make a simple my account section for the customers on the website at the moment.

Access to this section is only to preapproved list of business customers, who would already have a login to connect.

I will not take any payment or store any card details in here.

Can someone please advise, if I would need to purchase SSL and install on the website for MyAccount section?

Thanks
0
arthur112
Asked:
arthur112
3 Solutions
 
Paul MacDonaldDirector, Information SystemsCommented:
It depends on what you're using the "my account" section for.  Without an SSL certificate, all data going back and forth between the client and the server is unencrypted.  This means people can (possibly) intercept the data that's being transmitted.  If you don't care about that, you don't need an SSL certificate.
0
 
Daniel Van Der WerkenIndependent ConsultantCommented:
Any information that you think is confidential or should be private regarding your customers should not be sent via a non-SSL connection. Basically, anyone with a network sniffer like Wireshark or such can access any information sent to and from your site if it's not encrypted with an SSL connection.

If this information isn't stuff that's publicly available, you should use an SSL connection.
0
 
GaryCommented:
If you are only storing names and addresses (publicly available data) then it's up to you to decide whether you need to use SSL.
If you are storing things like credit cards, social security numbers etc (non public data) then these must be sent over SSL
0

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Tackle projects and never again get stuck behind a technical roadblock.
Join Now