Starting from January 2017, Google Chrome (ver. 56 or later) will mark pages that collect passwords, emails, or credit card data as "Not Secure" if they are not published using the HTTPS protocol (green lock). The new Chrome warning represents only the first phase of a long-term plan to label all pages published via unencrypted HTTP as "Not Secure".

Installing an SSL certificate is important not only for security and compliance with privacy directives but also for improving SERP indexing (positioning of your site in Google searches). It has become essential to prevent visitors to our website from receiving warnings about its lack of security.

The SSL Certificates (Secure Sockets Layer) ensure identity through a validation process carried out by a Certification Authority and protect the data transmitted through encryption. They are divided into:

  • Domain Validation (DV): SSL certificates with domain validation belong to the category of "entry-level" certificates and can be issued very quickly at a low cost.
  • Organization Validation (OV) / full organization: SSL certificates validated on the Organization confirm to the user that the company owning the certified site is legitimate and its identity has been verified.
  • Extended Validation (EV) and Green Bar: EV (Extended Validation) SSL certificates are the most comprehensive certificates, activating the green bar in the latest generation browsers and displaying the company's name, creating a higher level of trust and reliability compared to all other types of certificates.

Protecting Yourself from Identity Theft

A new viral security alert is spreading on Facebook, once again based on a foundation of truth: IDENTITY THEFT, but providing distorted information about the precautions to take and how to defend oneself. IDENTITY THEFT is a criminal offense that has existed long before the Internet and before Facebook. In the worst-case scenario, it is used to obtain loans in someone else's name, who will then go through a judicial ordeal to prove their innocence.

How to tell if your identity has been stolen?
In the case of Facebook, it couldn't be simpler: if you search for your name and find another profile in your name, with your data and your photos, unless you created it yourself, it is a true identity theft. Similarly, if you read comments in your name that you did not author.
It is more difficult to discover identity theft for fraudulent purposes; in this case, pay attention to:

  • Unusual or unexpected withdrawals from your bank account;
  • Receiving invoices for products or services you do not possess;
  • Problems with credit cards.

Now, do not rush to open the first attachment that arrives with a suspicious email talking about a bank transaction you know nothing about; it is more likely to be ransomware. Simply keep an eye on your bank accounts and credit cards.

How to defend yourself?

Regarding Facebook, it is very simple: as soon as you notice that someone is using your name and photo, just report it to Facebook, and within a few minutes, the profile will be closed. If it reappears, before repeating the process, you should make a copy of the profile page; a screenshot is not enough as it does not provide temporal proof and authenticity. For this purpose, use HASHBOT: https://www.hashbot.com/ and file a report with the Postal Police.

Use only the reporting feature; do not engage in discussions with the person who stole your identity, and do not start warning your contacts. It is pointless, and especially if it is a Troll, they will find your reaction amusing.

For identity theft for fraudulent purposes:

  1. Be careful with your sensitive data; do not easily provide copies of your documents, for example. Especially if you enter your credit card details, ensure that the connection is protected by SSL (https://); even if it is a website of a company you know, the normal connection (http://) does not protect against potential data interception.
  2. Do not provide your access passwords and be careful where you enter them: a tactic used by hackers (phishing) is to send a fake email from your bank inviting you to confirm a transaction or reset your password by clicking on a link that opens a page that looks exactly like that of your financial institution. In this case, pay attention to the page address and especially that it is protected by the SSL protocol, meaning it is an https:// address and that something similar to a padlock appears in the browser.
  3. Keep an eye on your bank accounts and credit cards: personally, I prefer services that provide an alert for every access to my profile (regardless of whether an operation is performed or not) through communication via email or SMS, which, combined with a strong password, make it difficult for any potential wrongdoer to access without our knowledge.

How to recognize a secure connection?

In the address bar, in addition to the https:// protocol, a lock icon will appear in your browser. Clicking on it will display information about the type of connection (secure connection) and the certifying authority [See image above]. In a normal connection, neither the lock icon nor the protocol (https://) will be displayed; instead, it will show (http:// without the s) or simply the address [See image below].

If you are visiting a page to consult information, the fact that it is not protected by SSL is irrelevant, but if you are asked to enter sensitive data such as your credit card number and the connection is not secure, providing that data is at risk regardless of the seriousness and honesty of the page owner. Many sites, especially e-commerce sites, protect financial transactions with SSL precisely because it is at this stage that sensitive data is entered, which is best protected from potential interception.

This is heading element

Author: Loris Modena

SENIOR DEVELOPER

Per Ind Loris Modena, owner of Arte e Informatica, started working in the IT sector in 1989 as a system administrator responsible for the maintenance and installation of computer systems. He began programming for the web in 1997, focusing on CGI programming in PERL and later transitioning to programming in PHP and JavaScript. During this time, he became familiar with the Open Source world and the management of Linux servers.

Product added to wishlist