Watch out for free SSL certificates!

Watch out for free SSL certificates!

25-02-2016 11:08:36

In December 2015, the site Let's Encrypt began offering a free SSL certificates using the Beta program. Right after that, when the service came into life it noted that in fact they don't give a full credibility.


On the page we can see the prefix HTTPS in the browser. This shows the establishing secure connection to the websites. The certificate ensures then that all transactions are confidential, which is safe for companies operating in e-commerce.


Is it worth to trust?


Businesses know that on trusted sites selling SSL Certificates will count an expense of $ 10 to $ 200. These prices are dependent on what type of protection gives a certificate and what it really involves. The costs can be further increased, because site owners are looking for the lowest available offer. However, there are also those who choose the free option is not always trusted.


Trend Micro has proved that free Certificates are also a tasty morsel for hackers. It is all about distributing malware servers through a gap on the site. Then they break into a site using the free Certificate and get access to the system without the user's knowledge. The process that perform hackers is called "Domain Shadowing" - a technique that allows them to create malicious subdomains on trusted sites. Hackers impersonate a real website and use it to serve ads with malicious software. The owners are not aware of the attack.


Business services should pay special attention to such attacks because of the risk of stealing user's data.

The case was further tested by Trend Micro - they have already sent an official request on the site, which provides the free Certificates.


To avoid such situations you should always use the services of trusted sellers. Data security is the most important thing. See on our site the full range of proven certificates from trustworthy vendors. 

Mensajes recientes

Google AdWords requires an SSL certificate?
03-07-2017 11:56:53

If you run a online business, you are sure to use Google AdWords. Perhaps this is one of the main traffic sources on your site, so the last message you want to see is "Your account has been suspended ...". And yet, you can expect it if your site is not SSL-secured.

Google AdWords requires an SSL certificate?
Comodo and DomenySSL are deprecating SGC
06-07-2016 13:23:42

Starting 1st of August 2016, Comodo and DomenySSL will no longer offer SGC variants of certificates. As your account has a valid SGC certificate which will be up for renewal in the future, the company has prepared a list of recommended alternatives.

Comodo and DomenySSL are deprecating SGC
Thawte pampers clients
04-07-2016 12:22:58

Thawte is only one of the few vendors outside of the United States. As the main competitor of American vendors quickly gained a 40 % share of the market SSL certificates.

Thawte pampers clients
más artículos