• MyOxy
  • Offices & Services
  • Alumni
  • Newsroom
  • Calendars

Occidental College

Our StoryAdmission & AidAcademicsLife at OxyLos AngelesOxy VoicesGivingGo Tigers!

Information Resources

  • Information Resources
  • Blog
  • SSL is supposed to solve two problems but most people only care about one of them

SSL is supposed to solve two problems but most people only care about one of them

November 15, 2011

One of my esteemed colleagues and a member of the Oxy Web Team, wrote a post about how to get rid of a particularly annoying pop-up alert present in Internet Explorer 8 (and older versions). But what she neglected to do was spin an incredibly boring and technical tale about what that error message is all about.

The same error as it appears in Internet Explorer 9

Surely, you're dying to hear more.In the beginning, there was the web. Later on, some folks decided the web needed to be secure. They developed something called SSL which was designed to solve two problems:

  1. Encrypt traffic between a web browser and a web server so that sensitive information could be passed securely.
  2. Give the web browser a way to determine if the web server is actually owned and operated by the organization it purported to be owned by.

Problem #1 is generally seen as the more important of the two problems, largely due to the fact that most folks already understand how wiretapping works and the risks that come with it. Problem #2 has no real analogue in the physical world that most people can relate to. When you go to an Apple store and buy an iPhone, there's no doubt that you are in a building owned by Apple and selling genuine Apple products (for the sake of this analogy, pretend China doesn't exist for a moment). On the web, though, you could be at a site that looks like it was made by Apple and appears to be selling Apple products but might actually be run by some kid in Slovenia for all you know. So SSL also includes a mechanism that allows you to validate the owner of a site. Think of it as the opposite of how cashiers ask for your ID when you buy stuff using a credit card - instead, you're also asking the cashier for their ID to prove they're Apple Store employees and not some random dude wearing a polo shirt and skimming credit card numbers. The problem, though, is the same problem you get with ID checking - it takes a lot of time. So much so that you stop doing it consistently. You only use SSL for some parts of the page and not others. You can encrypt the login page only, for example, like a hypothetical Apple store where only the cashiers get IDs. The person taking your credit card is legit but who knows if the sales person is selling you a legit product? Of course, SSL's value as the "ID card for the web" started to diminish as well. As with physical IDs, hackers can generate fakes. And despite the fact that it's not necessarily a good idea, the cool kids started to cut back on where they used SSL and eventually, the world had to follow suit. Internet Explorer's error message, once a message that conveyed actual risk, was now more of a nuisance. Internet Explorer 9, for example, still pops up a warning but you now don't have to click on it to use the webpage and it's all the way at the bottom of the page. Chrome gives you a small, albeit somewhat alarming visual cue:

Chrome gives you a stern look but stays out of your way

Firefox is the most subtle of all.

Firefox being all passive-aggressive

In practical terms, SSL was never all that useful as its creators hoped it would be for ferreting out fraudulent websites. Largely, this was due to the fact that good technology can't stop bad people. In the end, there's no single, clear way to determine if a site is fake or not. You just have to use your best judgement and stay alert. Anyone who tells you any different is just trying to sell you a bridge.

Information Resources

  • Academic Commons Vision
  • Blog
    • Yesterday's Internet Outage
    • Using OxyConnect with Internet Explorer 8
    • So Is Our Anti-Virus Totally Broken?
    • Information Resources 2012 Fall Newsletter now available!
    • Deptprinters queues
    • Academic Commons Taskforce: Progress and Process
    • Academic Commons….the history
    • Building and Rebuilding
    • By the Book – The Evolution of the Library
    • Do you love or hate conversation view for Gmail?
    • Does private browsing work?
    • One Perspective on The Digital Scholarship Institute
    • Optimizing Resources
    • OxyScholar Feb '12 Stats
    • Mapping New Directions in Academic Technologies
    • Making (Art) History With the Help of the DSI
    • Enumerating Badness: The latest way Facebook conspires to destroy you
    • Google Calendar sharing changes
    • How do you pick when to do maintenance?
    • Is there really a safety in numbers on Facebook?
    • A “Site” For More Eyes
    • A new method for accessing your files from off campus
    • Why does my antivirus icon look different?
    • Worried about losing your phone?
    • Why will the Internet go down for everyone if you're just doing work in HSC?
    • yeah, that was an earthquake
    • Where We Go To Learn
    • What's the point of all this maintenance?
    • A brief history of computing at Occidental
    • A Darker Shade of Green: Saving Power in the Datacenter
    • 2x upgrade
    • 2011/12 Library Break Hours extended thanks to student feedback
    • "Takeaway" Lunch - Scholars Discuss Their Experiences at the 2010 DSI
    • Pharos Print Drivers
    • The Definition of Simplicity
    • The DSI, Then and Next
    • The Attention Economy: Calculating the “Cost” of Information Overload
    • What does an Internet problem look like?
    • What exactly is a NOS anyway?
    • Welcome
    • Using Oxyconnect's Appointments Feature
    • The Right Tech For Real Results
    • Update on the 2011/10/07 network outage
    • Print your reports as PDFs from Banner
    • So what is central storage and why are you doing so much maintenance because of it?
    • SSL is supposed to solve two problems but most people only care about one of them
    • The Academic Commons Emerges
    • Scheduled Maintenance for Saturday, April 14th
    • Release to Print update - Coming Soon to Res Halls
    • Scheduled Maintenance for 15 Oct 2011
    • Scheduled Maintenance for 17 Sep 2011
  • Hours
  • People
  • Employment
  • Info Center:

    (323) 259-2640


  • Technology Helpdesk:

    (323) 259-2880 helpdesk@oxy.edu


  • IR Operations Offices: (323) 259-2832


  • Information Resources VP/CIO: (323) 259-1451
Tweet

Occidental College

  • For Parents
  • Employment
  • Contact Us
  • Maps & Directions

1600 Campus Road Los Angeles, California 90041