HTTPS and SSL, explained without the jargon
This is one of those topics that looks small until it costs you something. Here is HTTPS and SSL without the vocabulary that usually surrounds it.
The cheapest security work is the boring kind done on a schedule. Write the reasoning down alongside the decision, because the reasoning is what changes first.
The short version
Browsers now actively warn on unencrypted pages. This is the sort of thing that compounds, quietly, in both directions. It is the sort of thing that looks like polish right up until it costs you an enquiry.
Why people complicate it
Most of the confusion comes from tooling rather than from the idea itself. The teams that handle this well are rarely the ones with the biggest budgets.
Certificates can and should renew automatically. In practice this is a scheduling problem more than a technical one. It is the sort of thing that looks like polish right up until it costs you an enquiry.
A reasonable first step
Mixed content quietly breaks the padlock. This is the sort of thing that compounds, quietly, in both directions. Budget a little time for it every quarter and it never becomes a project of its own.
In practice
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about HTTPS and SSL before you move on:
- Someone can say what the current setup is without going to look
- Mixed content quietly breaks the padlock — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.