Rise said:Cool, I didn't realize that was available, I assume you are using a self signed cert.. so yeah the browser is going to freak out.
Nope, we pay for the certs, which is actually doubly useless:
1. It's useless because the "Certificate Authority" is most likely compromised
2. Having an official SSL cert isn't actually more secure cryptographically speaking anyway
And a "real" cert costs money. But, it does prevent certain browsers from displaying a large and annoying message about an "invalid/self-signed certificate".
But even if we buy a "real" certificate, some browsers still present a large and annoying message that says, "not all content on this page is secure" (this is especially problematic on SOTT where many embedded videos are not available via SSL). This then causes people to freak out and write to us, saying things like, "I think your site is sending me malware!"
Well, there are many other details, but you get the idea.