Three myths about HTTPS and SSL
We end up explaining this on discovery calls often enough that it deserved writing down. A few things about HTTPS and SSL that get repeated more often than they get checked.
Security is a maintenance habit rather than a purchase, which is why it drifts. Budget a little time for it every quarter and it never becomes a project of its own.
“It only matters for big sites”
Browsers now actively warn on unencrypted pages. That sounds obvious written down. It is still the thing most often skipped. It is the sort of thing that looks like polish right up until it costs you an enquiry.
“We can deal with it after launch”
Sometimes true, usually expensive. Small and consistent beats large and occasional here.
“Our platform handles it”
Mixed content quietly breaks the padlock. The reasoning matters more than the rule, because the rule has exceptions. If it only works because one person remembers to do something, it does not work yet.
The short version
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about HTTPS and SSL before you move on:
- Someone can say what the current setup is without going to look
- Certificates can and should renew automatically — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.