Web Performance 101: SSL and Web Security
The web cannot guarantee the safety of your data unless you ensure it is transferred and stored securely
Join the DZone community and get the full member experience.Join For Free
the internet is an ever-growing repository of data – data which can be accessed publicly, and data that is either personal or highly classified which can only be accessed by those authorized to do so (in an ideal world, at least). there are a number of ways in which this data can be stolen or altered by hackers; the worldwide web cannot guarantee the safety of your data unless you ensure it is transferred and stored securely. customers using online shopping and banking sites are easy targets for hackers and this has made it more important than ever to use data encryption as the first line of defense against cyber-attacks.
the big picture
securing the online world is an ongoing battle; the number of data breaches has been on the rise for years. we have already witnessed a number of high-profile data breaches this year including the clinton campaign’s data breach and the 500 million user accounts stolen from yahoo’s database. hackers use a number of different techniques to access customer data like phishing, dns spoofing, code injection, to name a few. to keep your customer data safe, it is important to first collect/transfer data only through an encrypted channel. http does not provide data security by default and this makes the connection vulnerable. on the other hand, https encrypts and secures the data exchange between the user (browser) and the website (server). https is a protocol that uses secure sockets layer or ssl along with regular http to establish a secure connection to transfer sensitive data over the internet.
ssl or tls?
the terms ssl and tls (transport layer security) are often used interchangeably as both provide authentication and data encryption between a client and server. there are several versions of ssl, the successor to the last version of ssl (ssl 3.0) is called tls – it is an improved version of the original ssl protocol. even though tls is the protocol currently supported by all browsers, it is commonly referred to as ssl.
why do we need ssl?
ssl provides a secure channel between the client and server, allowing only encrypted transfers. anyone trying to eavesdrop over an http connection that uses ssl (https) will not be able to decipher the data being transferred. in addition to keeping your data safe, ssl is also used to protect the user’s identity. when a website requests for the geolocation or collects private information or preferences of the user as part of the website workflow, it must be encrypted or this data is exposed to anyone interested in harvesting sensitive user information.
data such as phone numbers, social security numbers, bank account details and credit card info are constantly shared online by customers. the transfer of such data can be easily intercepted – a hacker can read the unsecured data, steal it or even rewrite the data making it easy to inject malicious code into the client’s system.
how is ssl integrated?
implementing ssl on your website creates a trusted environment for your customers and significantly cuts down the chances of a data breach. to set up ssl –
- first you need to purchase an ssl certificate from an authorized vendor.
- the next step is to install or add this certificate to your webserver.
- once the certificate is installed and activated, the pages that require encryption must be set to use https instead of http.
how does it work?
when a customer transacts on a page that uses https, the server sends a copy off the ssl certificate to the browser for verification. a symmetric key pair is generated which is used to establish a secure channel between the browser and the server. the image explains the process; you can read a detailed explanation on this post .
ssl vs user experience
if ssl is not implemented correctly it can affect site availability and performance. it is important to verify the authenticity of the ssl certificate vendor to prevent certificate errors. if the browser is unable to authenticate the server’s certificate, then it will block the user from accessing the website compromising the user experience altogether. unsecured elements (including 3 rd party objects) on pages served over https can be a major bottleneck. the page may either render with broken links and images or the page may not load at all. you must ensure ssl has been integrated properly and that it does not affect the digital experience. read this interesting post to understand how ssl impacts performance and how catchpoint was able to pinpoint the root cause of the issue.
ssl and http/2
http/2 is the latest version of http that was developed using google’s spdy protocol. this version of http provides enhanced speed, efficiency, and security. although http/2 supports secured and non-secured connections, browsers like chrome and firefox allows the use of http/2 only over ssl. to enable http/2 on a website it is mandatory to have the latest version of ssl/tls implemented.
most companies and businesses shy away from implementing ssl due to the cost and the overhead https adds to the page load time. we have explored the actual impact that ssl has on website performance here . when the page has ssl enabled, it requires extra round trips to establish a secure connection which impacts the site performance. studies comparing http/2 vs regular https transactions show that http/2 is faster and more efficient as it allows multiplexing which has a positive impact on the page performance.
a highly disturbing fact about the online world today is that cybercrime has become the norm. every industry – ecommerce, healthcare, banking, educational and even military databases have become targets of cyber-attacks. it is important to implement at least the basic measures when it comes to protecting sensitive information. using ssl/tls provides a secure environment for users to share information and effectively prevent data breaches.
Published at DZone with permission of Kameerath Abdul Kareem, DZone MVB. See the original article here.
Opinions expressed by DZone contributors are their own.