The real cost of ignoring HTTPS and SSL
It comes up on almost every project, usually later than it should. Nobody bills you for neglecting HTTPS and SSL. The cost shows up somewhere else.
The cheapest security work is the boring kind done on a schedule. The version that survives contact with a real deadline is the simple one.
Where the cost lands
- Time spent on work that should not have been necessary
- Enquiries that quietly never arrive
- Browsers now actively warn on unencrypted pages
- Rework, once the problem is finally visible
Certificates can and should renew automatically. In practice this is a scheduling problem more than a technical one. If it only works because one person remembers to do something, it does not work yet.
What to do next
Mixed content quietly breaks the padlock. Where this goes wrong is almost never a lack of knowledge. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
In practice
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about HTTPS and SSL before you move on:
- Someone can say what the current setup is without going to look
- Browsers now actively warn on unencrypted pages — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Worth checking on your own setup before it becomes someone else's problem to fix.