Find White Papers
Home
About Us
List Your Papers
    
> VeriSign Incorp. > Help Increase Site Visitor Trust in Your Site

Help Increase Site Visitor Trust in Your Site

White Paper Published By: VeriSign Incorp.

Provide site visitors visual cues that indicate your site is legitimate with Extended Validation (EV) SSL available from VeriSign.  Read this paper to learn how to increase site visitor confidence in your site. Learn more today!



Tags : 
verisign, phishing, extended validation, ev ssl, ssl, encryption, online safety, online security

VeriSign Incorp.
Published:  Jul 13, 2009
Type:  White Paper
Length:  8 pages

W H I T E PA P E R
Maximizing Site Visitor Trust Using
Extended Validation SSL W H I T E PA P E R
C O N T E N T S + The Erosion of SSL's Identity Promise 3
+ Introducing Identity Visitors Can Trust 4Internet Explorer 7: Green for Go 4
+ How Extended Validation Works 7
+ EV Upgrader Extends Protection to Windows XP Clients 8W H I T E PA P E R
Web business faces a crisis in con?dence. Trust in site security is declining, and inincreasing numbers consumers are scaling back their online transactions-or opting outentirely. According to Forrester Research on December 8, 2005, an astonishing 24percent of Internet users reported that they would not be shopping online that holidayseason because they did not feel safe. A full 61 percent reported that they had at leastreduced online purchases for the same reason. While this phenomenon has been maskedby the overall increase in online activities like banking, trading securities, and ?ling taxes,the fact remains that many online retail businesses are less effective than they could beand are leaving money on the table.Starting early in 2007, online companies will be able to de?nitively demonstrate theiridentity to customers-and customers will be able to con?rm this identity before trustingsites. This opportunity comes as a result of the greatest development in the Web's securebackbone in over 10 years. It is the introduction of a new kind of SSL Certi?cate, the?rst since the technology's origin more than a decade ago.These new certi?cates are called Extended Validation (EV) SSL Certi?cates, and theyrepresent more than a year's effort by the CA/Browser Forum, an industry consortium ofleading Web browser manufacturers and SSL certi?cation authorities (CAs) such asVeriSign. Starting late in 2006, members of the CA/Browser Forum have made these newcerti?cates available for the bene?t of Web businesses and site visitors alike. Thecerti?cates can facilitate online commerce in all its forms by increasing visitor con?dencein legitimate sites and greatly reducing the effectiveness of phishing attacks.
The Erosion of SSL's
Identity Promise
Ask your typical online shopper what the little lock icon on her Internet browser means,and she will tell you it means that transmissions are encrypted and therefore protectedfrom spying eyes. While that's technically correct, it's not all that the original pioneers ine-commerce intended it to signify.The original purpose of SSL Certi?cates was to validate the identity of a site when a userconnected to it. That's because although it is dif?cult to mimic physically the identity ofa business, it is quite easy to mimic one online. The industry understood this principle asearly as 1995 and therefore invented SSL Certi?cates. The creators intended thecerti?cate to vouch for site identity and therefore protect online shoppers from scams. Inthe beginning the identity promise of a standard SSL Certi?cate was enough. Today,however, it is not. The widespread use of the Web by laypeople with no special level ofcomputer education-combined with the low visibility of the lock icon on popularbrowsers-have made it possible for phishing to become the phenomenon we see today.Despite original intentions, traditional SSL Certi?cates aren't the solution. While someCAs do a very good job of authenticating identity, others do very little or employ easilyfooled practices. A site can even use a self-signed SSL Certi?cate with no identityauthentication whatsoever. In the second half of 2005 online users began to see large-scale phishing attacks that used low-authentication, "soft-target" SSL Certi?cates tofurther the illusion of legitimacy.
3W H I T E PA P E R
Introducing Identity Visitors
Can Trust
For SSL Certi?cates to reclaim their authority as a source of site identity information forvisitors, industry leaders needed to shore up two weaknesses in the existing system. First,the industry needed a new category of SSL Certi?cate that carries a high level of promiseregarding a site owner's identity. Then it needed a browser interface that makes it easy forusers to see that identity when it's known-and recognize when it isn't. These newcerti?cates are the EV SSL Certi?cates mentioned previously. Some users also refer tothem by their working name, which is High Assurance (HA) SSL Certi?cates. Thesediffer from generic "high-assurance certi?cates," which do not imply EV status... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search