SlideShare a Scribd company logo
1 of 7
Download to read offline
WHITEPAPER:HOWEXTENDED
VALIDATIONSSLBRINGSCONFIDENCETO
ONLINESALESANDTRANSACTIONS
How Extended Validation SSL
Brings Confidence to Online
Sales and Transactions
White Paper
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions
2
How Extended Validation SSL Brings Confidence to Online Sales
and Transactions
CONTENTS
Introduction .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
Online Growth Slowed by Lack of Trust .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
Extended Validation Restores Confidence .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
Backed by the Most Trusted Name on the Internet .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
The Value of EV SSL .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 6
Conclusion .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 7
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions
3
Introduction
As customers increasingly choose to shop, share, bank, and view accounts online,
they have become more savvy about security. However, concerns about identity
theft and fraud still keep many website visitors from completing, or starting, their
transactions online. They need to be reassured that the confidential information
that they share will be protected from malicious activity.
Symantec™ Extended Validation (EV) SSL Certificates can be a key factor in
helping increase customer confidence during online business transactions. More
confidence can mean more conversions for customers with EV SSL certificates.
Symantec EV SSL turns address bars green in high-security browsers for an extra
layer of website security that customers can see and trust.
Online Growth Slowed by Lack of Trust
Today, more people have access to the Internet and spend more time online than
ever before. Financial industry experts predict that online banking, and other
accounts, will become the primary customer touch-point over the next decade. As
Internet adoption continues to grow and Web browsing becomes more common on
mobile devices, businesses have the opportunity to tap new markets with online
sales and account-based services. However, reluctance to conduct transactions
online remains due to concerns about protecting confidential information. Even
though identity theft occurs more often offline than online, many Internet users are
nonetheless extremely wary of identity theft. On the Web, the impact of this doubt
is easy to measure:
•	 Abandoned shopping carts add up to lost sales and missed revenue.
•	 Click-through tracking shows that potential customers reach enrollment forms,
but do not complete them.
•	 Search analytics and alerts show how brands and company names are hijacked
to lure customers away from legitimate sites.
Internet scams have become more coordinated and sophisticated, eroding the trust
that is essential to online business. In the second half of 2010 the Anti-Phishing
Working Group reported an average of 305 brands hijacked each month, with
September having the highest monthly incidence at 355.1
Phishing schemes use
emails and websites that appear legitimate to trick visitors into sharing personal
information. SSL stripping, a type of man-in-the-middle attack, redirects users
to “secure” websites that are fake (i.e., some security measures have been taken,
and are displayed, but the website is not really the one the visitor believes they are
visiting). These types of attacks often target webmail applications, secure sites,
and intranets.
1
Source: www.antiphishing.org. Anti-Phishing Working Group 2010.
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions
4
Phishing Defined
A type of fraud where emails and websites that appear to be from a
well-known brand are actually fake sites where information is captured and
used for identity theft.
APWG,Phishing Activity Trends Report: 1st Half 2011 (2011), Page 5,
http://www.antiphishing.org/reports/apwg_trends_report_h1_2011.pdf
Hijacked Brands by Month 1st Half ‘11
January
339
0
50
100
150
200
250
300
350
400
335
313
333 331
310
FebruaryM arch AprilM ay June
Financial,
47.1%
Social
Networking,
4.2%
Auctions, 4.3%
Most Targeted Industry Sectors 1st Half ‘11
Retail/Services,
6.1%
Gaming, 6.1%
Other, 1.5%
Classifieds,
1.0%
ISP, 2.7%
Goverment,
1.4%
Payment
Services, 25.6%
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions
5
Extended Validation Restores Confidence
Many website owners are familiar with the visual indications that a website is
using SSL – the closed padlock and “https” in the URL are examples. Before
Extended Validation SSL, website users had to trust that only legitimate sites were
secured with SSL. Fraudsters have abused this trust by taking advantage of lax
validation policies used by some Certification Authorities (CAs), and purchased
SSL certificates for fake domains. They have used these SSL certificates to create
“secure” sites from which to launch phishing and man-in-the-middle attacks,
thereby undermining overall consumer confidence.
Symantec EV SSL Certificates address this nefarious use of SSL, and offer an easy
way to help reduce abandonment and increase conversions. All accomplished while
lowering costs and protecting personally identifiable information (PII) through
more secure online transactions.
How Extended Validation Works
Extended validation authentication provides the highest level of authentication
available with a SSL certificate. EV SSL certificates provide an extra layer of
protection for consumers and website owners by requiring that applicants follow
a strict issuance and management process, as defined by the CA/Browser Forum,
prior to being issued an EV SSL certificate. Support for EV SSL has become a
standard security feature in mainstream Web browsers such as Internet Explorer
and Firefox, and on mobile devices such as the iPhone and Droid. These browsers
recognize EV-secured websites and show the presence of EV in a visually distinctive
way so that users can easily see that the website can be trusted. When customers
visit a webpage secured with an EV SSL certificate, the address bar turns green
(in high-security browsers) and a special field appears with the name of the
legitimate website owner along with the name of the security provider that issued
the EV SSL certificate. This visual reassurance has helped increase consumer
confidence in e-commerce.
Backed by the Most Trusted Name on the Internet
EV SSL also helps users determine who they are doing business with and who
validated the website. The address bar in EV SSL-compatible browsers shows the
name of the organization that owns the EV SSL certificate and the SSL provider
that issued it.
The Norton™ Secured Seal, is displayed over half a billion times per day on websites
in 170 countries and in search results on enabled browsers as well as partner
shopping sites and product review web pages. A Symantec EV SSL Certificate
reinforces the notion of brand and site security by placing the trusted Norton
Secured Seal with the Norton™ Check next to the website owner’s company name
in the address bar.
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions
6
Symantec: The #1 Provider of Online Security
Symantec is the world’s leading provider of SSL certificates and maintains more
EV SSL certificates than any other CA2
. Web users are accustomed to seeing
commercial e-commerce websites display the Norton Secured Seal – prominently
featured to assure online users that their online business is authentic and that
their site is capable of securing their confidential information with SSL encryption.
Higher Authentication Standard
Before issuing an EV SSL certificate, the SSL provider must:
•	 Verify the legal, physical and operational existence of the entity
•	 Verify that the identity of the entity matches official records
•	 Verify that the entity has exclusive right to use the domain specified in the
EV SSL certificate
•	 Verify that the entity has properly authorized the issuance of the EV SSL
certificate
The Value of EV SSL
As EV SSL adoption spreads, the green address bar is becoming a “must have” for
a wide range of industries doing business online. The ability to track impressions,
clicks, and interactions make it possible to measure the return on investment in
EV SSL and quantify the value of better security to any company’s bottom line.
Converting browsing shoppers into buyers and visitors to members requires a
high degree of trust and confidence in a given website. In industries where fraud
and scams are common, the rigorous authentication process behind EV SSL
sets reputable firms apart. Many companies have found that a Symantec EV SSL
Certificate helps them establish their online presence, because Internet users know
and trust the Symantec brand. In recent tests, 77 percent of consumers recognized
the Norton Secured™ Seal, more than our competitors’ trust seals3
.
Better Protection
For companies that must comply with regulatory standards related to securing
personally identifiable information, EV SSL certificates help reduce risk of non-
compliance and communicate the implementation of rigorous protection measures
against well-known threats. By using EV SSL, and educating customers to look
for the green bar, companies mitigate the risk of mid-stream interception and
demonstrate efficacy of security measures.
Choosing the right SSL certificate provider is also important to getting the best
possible protection. Symantec SSL Certificates secure more than one million Web
servers worldwide4
. Symantec’s rigorous authentication process, audited annually
by KPMG, leads the industry in reputation qualification measure to establish an
online business credibility.
2
Includes Symantec subsidiaries, affiliates, and resellers.
3
Symantec Consumer Research Study, January 2011.
4
Includes Symantec subsidiaries, affiliates, and resellers.
Copyright © 2012 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, and the Checkmark Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in
the U.S. and other countries. VeriSign and other related marks are the trademarks or registered trademarks of VeriSign, Inc. or its affiliates or subsidiaries in the U.S. and other countries and licensed to
Symantec Corporation. Other names may be trademarks of their respective owners.
Conclusion
Online services and sales have become areas of growth for businesses of all sizes
across a wide range of industries. Symantec SSL Certificates with EV are a proven
tool that makes it easy for customers to feel confident about sharing their personal
information online. They are a “must have” for businesses that want to maximize
their online growth potential.
More Information
Visit our website
http://go.symantec.com/ssl-certificates
To speak with a Product Specialist in the U.S.
Call 1 (866) 893-6565 or 1 (650) 426-5112
To speak with a Product Specialist outside the U.S.
For specific country offices and contact numbers, please visit our website.
About Symantec
Symantec is a global leader in providing security, storage, and systems
management solutions to help consumers and organizations secure and manage
their information-driven world. Our software and services protect against more
risks at more points, more completely and efficiently, enabling confidence
wherever information is used or stored.
Symantec Corporation World Headquarters
350 Ellis Street
Mountain View, CA 94043 USA
1 (866) 893 6565
www.symantec.com
White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions

More Related Content

More from CheapSSLsecurity

More from CheapSSLsecurity (20)

The Top Five Cybersecurity Threats for 2018
The Top Five Cybersecurity Threats for 2018The Top Five Cybersecurity Threats for 2018
The Top Five Cybersecurity Threats for 2018
 
Is your business PCI DSS compliant? You’re digging your own grave if not
Is your business PCI DSS compliant? You’re digging your own grave if notIs your business PCI DSS compliant? You’re digging your own grave if not
Is your business PCI DSS compliant? You’re digging your own grave if not
 
Phishing Scams: 8 Helpful Tips to Keep You Safe
Phishing Scams: 8 Helpful Tips to Keep You SafePhishing Scams: 8 Helpful Tips to Keep You Safe
Phishing Scams: 8 Helpful Tips to Keep You Safe
 
How Hashing Algorithms Work
How Hashing Algorithms WorkHow Hashing Algorithms Work
How Hashing Algorithms Work
 
Quantum Computing vs Encryption: A Battle to Watch Out for
Quantum Computing vs Encryption: A Battle to Watch Out forQuantum Computing vs Encryption: A Battle to Watch Out for
Quantum Computing vs Encryption: A Battle to Watch Out for
 
Symantec (ISTR) Internet Security Threat Report Volume 22
Symantec (ISTR) Internet Security Threat Report Volume 22Symantec (ISTR) Internet Security Threat Report Volume 22
Symantec (ISTR) Internet Security Threat Report Volume 22
 
Hashing vs Encryption vs Encoding
Hashing vs Encryption vs EncodingHashing vs Encryption vs Encoding
Hashing vs Encryption vs Encoding
 
Understanding SSL Certificate for Apps by Symantec
Understanding SSL Certificate for Apps by SymantecUnderstanding SSL Certificate for Apps by Symantec
Understanding SSL Certificate for Apps by Symantec
 
Thawte Wildcard SSL Certificates – Enable Sub-Domains Security
Thawte Wildcard SSL Certificates – Enable Sub-Domains SecurityThawte Wildcard SSL Certificates – Enable Sub-Domains Security
Thawte Wildcard SSL Certificates – Enable Sub-Domains Security
 
Shift to HTTPS and Save Your Website from the Wrath of Blacklisting
Shift to HTTPS and Save Your Website from the Wrath of BlacklistingShift to HTTPS and Save Your Website from the Wrath of Blacklisting
Shift to HTTPS and Save Your Website from the Wrath of Blacklisting
 
Microsoft Exchange Server & SSL Certificates: Everything you need to know
Microsoft Exchange Server & SSL Certificates: Everything you need to knowMicrosoft Exchange Server & SSL Certificates: Everything you need to know
Microsoft Exchange Server & SSL Certificates: Everything you need to know
 
Comodo Multi Domain SSL Certificate: Key Features by CheapSSLsecurity
Comodo Multi Domain SSL Certificate: Key Features by CheapSSLsecurityComodo Multi Domain SSL Certificate: Key Features by CheapSSLsecurity
Comodo Multi Domain SSL Certificate: Key Features by CheapSSLsecurity
 
Why Green Address Bar EV SSL Certificates are Critical to E-commerce
Why Green Address Bar EV SSL Certificates are Critical to E-commerceWhy Green Address Bar EV SSL Certificates are Critical to E-commerce
Why Green Address Bar EV SSL Certificates are Critical to E-commerce
 
4 Major Reasons for Big Organizations to Have Wildcard SSL Certificates
4 Major Reasons for Big Organizations to Have Wildcard SSL Certificates4 Major Reasons for Big Organizations to Have Wildcard SSL Certificates
4 Major Reasons for Big Organizations to Have Wildcard SSL Certificates
 
Comodo: The Benefits of EV SSL Certificates - CheapSSLsecurity
Comodo: The Benefits of EV SSL Certificates - CheapSSLsecurityComodo: The Benefits of EV SSL Certificates - CheapSSLsecurity
Comodo: The Benefits of EV SSL Certificates - CheapSSLsecurity
 
Reduce the Domain Validation time with Symantec Automated Authentication Process
Reduce the Domain Validation time with Symantec Automated Authentication ProcessReduce the Domain Validation time with Symantec Automated Authentication Process
Reduce the Domain Validation time with Symantec Automated Authentication Process
 
Hidden Dangers Lurking in E-Commerce and Reducing Fraud with the Right SSL Ce...
Hidden Dangers Lurking in E-Commerce and Reducing Fraud with the Right SSL Ce...Hidden Dangers Lurking in E-Commerce and Reducing Fraud with the Right SSL Ce...
Hidden Dangers Lurking in E-Commerce and Reducing Fraud with the Right SSL Ce...
 
Extended Validation SSL Certificates, A new standard to inspire trust, improv...
Extended Validation SSL Certificates, A new standard to inspire trust, improv...Extended Validation SSL Certificates, A new standard to inspire trust, improv...
Extended Validation SSL Certificates, A new standard to inspire trust, improv...
 
The Hidden Costs of Self-Signed SSL Certificates
The Hidden Costs of Self-Signed SSL CertificatesThe Hidden Costs of Self-Signed SSL Certificates
The Hidden Costs of Self-Signed SSL Certificates
 
Website Anti-Malware Scans - Set up a Malware Free Business Over the Internet
Website Anti-Malware Scans - Set up a Malware Free Business Over the InternetWebsite Anti-Malware Scans - Set up a Malware Free Business Over the Internet
Website Anti-Malware Scans - Set up a Malware Free Business Over the Internet
 

Recently uploaded

Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
panagenda
 
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
FIDO Alliance
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc
 

Recently uploaded (20)

Generative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdfGenerative AI Use Cases and Applications.pdf
Generative AI Use Cases and Applications.pdf
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
State of the Smart Building Startup Landscape 2024!
State of the Smart Building Startup Landscape 2024!State of the Smart Building Startup Landscape 2024!
State of the Smart Building Startup Landscape 2024!
 
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdfFrisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
Frisco Automating Purchase Orders with MuleSoft IDP- May 10th, 2024.pptx.pdf
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptxHarnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
Harnessing Passkeys in the Battle Against AI-Powered Cyber Threats.pptx
 
Navigating the Large Language Model choices_Ravi Daparthi
Navigating the Large Language Model choices_Ravi DaparthiNavigating the Large Language Model choices_Ravi Daparthi
Navigating the Large Language Model choices_Ravi Daparthi
 
Simplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptxSimplifying Mobile A11y Presentation.pptx
Simplifying Mobile A11y Presentation.pptx
 
Introduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptxIntroduction to FIDO Authentication and Passkeys.pptx
Introduction to FIDO Authentication and Passkeys.pptx
 
Vector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptxVector Search @ sw2con for slideshare.pptx
Vector Search @ sw2con for slideshare.pptx
 
ERP Contender Series: Acumatica vs. Sage Intacct
ERP Contender Series: Acumatica vs. Sage IntacctERP Contender Series: Acumatica vs. Sage Intacct
ERP Contender Series: Acumatica vs. Sage Intacct
 
AI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by AnitarajAI in Action: Real World Use Cases by Anitaraj
AI in Action: Real World Use Cases by Anitaraj
 
The Ultimate Prompt Engineering Guide for Generative AI: Get the Most Out of ...
The Ultimate Prompt Engineering Guide for Generative AI: Get the Most Out of ...The Ultimate Prompt Engineering Guide for Generative AI: Get the Most Out of ...
The Ultimate Prompt Engineering Guide for Generative AI: Get the Most Out of ...
 
Top 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development CompaniesTop 10 CodeIgniter Development Companies
Top 10 CodeIgniter Development Companies
 
الأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهلهالأمن السيبراني - ما لا يسع للمستخدم جهله
الأمن السيبراني - ما لا يسع للمستخدم جهله
 
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
TrustArc Webinar - Unified Trust Center for Privacy, Security, Compliance, an...
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
Overview of Hyperledger Foundation
Overview of Hyperledger FoundationOverview of Hyperledger Foundation
Overview of Hyperledger Foundation
 
How to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cfHow to Check CNIC Information Online with Pakdata cf
How to Check CNIC Information Online with Pakdata cf
 
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
TEST BANK For Principles of Anatomy and Physiology, 16th Edition by Gerard J....
 

How EV SSL Certificate Brings Confidence to Online Sales and Transactions

  • 2. White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions 2 How Extended Validation SSL Brings Confidence to Online Sales and Transactions CONTENTS Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Online Growth Slowed by Lack of Trust . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Extended Validation Restores Confidence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5 Backed by the Most Trusted Name on the Internet . . . . . . . . . . . . . . . . . . . . . . . . . 5 The Value of EV SSL . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
  • 3. White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions 3 Introduction As customers increasingly choose to shop, share, bank, and view accounts online, they have become more savvy about security. However, concerns about identity theft and fraud still keep many website visitors from completing, or starting, their transactions online. They need to be reassured that the confidential information that they share will be protected from malicious activity. Symantec™ Extended Validation (EV) SSL Certificates can be a key factor in helping increase customer confidence during online business transactions. More confidence can mean more conversions for customers with EV SSL certificates. Symantec EV SSL turns address bars green in high-security browsers for an extra layer of website security that customers can see and trust. Online Growth Slowed by Lack of Trust Today, more people have access to the Internet and spend more time online than ever before. Financial industry experts predict that online banking, and other accounts, will become the primary customer touch-point over the next decade. As Internet adoption continues to grow and Web browsing becomes more common on mobile devices, businesses have the opportunity to tap new markets with online sales and account-based services. However, reluctance to conduct transactions online remains due to concerns about protecting confidential information. Even though identity theft occurs more often offline than online, many Internet users are nonetheless extremely wary of identity theft. On the Web, the impact of this doubt is easy to measure: • Abandoned shopping carts add up to lost sales and missed revenue. • Click-through tracking shows that potential customers reach enrollment forms, but do not complete them. • Search analytics and alerts show how brands and company names are hijacked to lure customers away from legitimate sites. Internet scams have become more coordinated and sophisticated, eroding the trust that is essential to online business. In the second half of 2010 the Anti-Phishing Working Group reported an average of 305 brands hijacked each month, with September having the highest monthly incidence at 355.1 Phishing schemes use emails and websites that appear legitimate to trick visitors into sharing personal information. SSL stripping, a type of man-in-the-middle attack, redirects users to “secure” websites that are fake (i.e., some security measures have been taken, and are displayed, but the website is not really the one the visitor believes they are visiting). These types of attacks often target webmail applications, secure sites, and intranets. 1 Source: www.antiphishing.org. Anti-Phishing Working Group 2010.
  • 4. White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions 4 Phishing Defined A type of fraud where emails and websites that appear to be from a well-known brand are actually fake sites where information is captured and used for identity theft. APWG,Phishing Activity Trends Report: 1st Half 2011 (2011), Page 5, http://www.antiphishing.org/reports/apwg_trends_report_h1_2011.pdf Hijacked Brands by Month 1st Half ‘11 January 339 0 50 100 150 200 250 300 350 400 335 313 333 331 310 FebruaryM arch AprilM ay June Financial, 47.1% Social Networking, 4.2% Auctions, 4.3% Most Targeted Industry Sectors 1st Half ‘11 Retail/Services, 6.1% Gaming, 6.1% Other, 1.5% Classifieds, 1.0% ISP, 2.7% Goverment, 1.4% Payment Services, 25.6%
  • 5. White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions 5 Extended Validation Restores Confidence Many website owners are familiar with the visual indications that a website is using SSL – the closed padlock and “https” in the URL are examples. Before Extended Validation SSL, website users had to trust that only legitimate sites were secured with SSL. Fraudsters have abused this trust by taking advantage of lax validation policies used by some Certification Authorities (CAs), and purchased SSL certificates for fake domains. They have used these SSL certificates to create “secure” sites from which to launch phishing and man-in-the-middle attacks, thereby undermining overall consumer confidence. Symantec EV SSL Certificates address this nefarious use of SSL, and offer an easy way to help reduce abandonment and increase conversions. All accomplished while lowering costs and protecting personally identifiable information (PII) through more secure online transactions. How Extended Validation Works Extended validation authentication provides the highest level of authentication available with a SSL certificate. EV SSL certificates provide an extra layer of protection for consumers and website owners by requiring that applicants follow a strict issuance and management process, as defined by the CA/Browser Forum, prior to being issued an EV SSL certificate. Support for EV SSL has become a standard security feature in mainstream Web browsers such as Internet Explorer and Firefox, and on mobile devices such as the iPhone and Droid. These browsers recognize EV-secured websites and show the presence of EV in a visually distinctive way so that users can easily see that the website can be trusted. When customers visit a webpage secured with an EV SSL certificate, the address bar turns green (in high-security browsers) and a special field appears with the name of the legitimate website owner along with the name of the security provider that issued the EV SSL certificate. This visual reassurance has helped increase consumer confidence in e-commerce. Backed by the Most Trusted Name on the Internet EV SSL also helps users determine who they are doing business with and who validated the website. The address bar in EV SSL-compatible browsers shows the name of the organization that owns the EV SSL certificate and the SSL provider that issued it. The Norton™ Secured Seal, is displayed over half a billion times per day on websites in 170 countries and in search results on enabled browsers as well as partner shopping sites and product review web pages. A Symantec EV SSL Certificate reinforces the notion of brand and site security by placing the trusted Norton Secured Seal with the Norton™ Check next to the website owner’s company name in the address bar.
  • 6. White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions 6 Symantec: The #1 Provider of Online Security Symantec is the world’s leading provider of SSL certificates and maintains more EV SSL certificates than any other CA2 . Web users are accustomed to seeing commercial e-commerce websites display the Norton Secured Seal – prominently featured to assure online users that their online business is authentic and that their site is capable of securing their confidential information with SSL encryption. Higher Authentication Standard Before issuing an EV SSL certificate, the SSL provider must: • Verify the legal, physical and operational existence of the entity • Verify that the identity of the entity matches official records • Verify that the entity has exclusive right to use the domain specified in the EV SSL certificate • Verify that the entity has properly authorized the issuance of the EV SSL certificate The Value of EV SSL As EV SSL adoption spreads, the green address bar is becoming a “must have” for a wide range of industries doing business online. The ability to track impressions, clicks, and interactions make it possible to measure the return on investment in EV SSL and quantify the value of better security to any company’s bottom line. Converting browsing shoppers into buyers and visitors to members requires a high degree of trust and confidence in a given website. In industries where fraud and scams are common, the rigorous authentication process behind EV SSL sets reputable firms apart. Many companies have found that a Symantec EV SSL Certificate helps them establish their online presence, because Internet users know and trust the Symantec brand. In recent tests, 77 percent of consumers recognized the Norton Secured™ Seal, more than our competitors’ trust seals3 . Better Protection For companies that must comply with regulatory standards related to securing personally identifiable information, EV SSL certificates help reduce risk of non- compliance and communicate the implementation of rigorous protection measures against well-known threats. By using EV SSL, and educating customers to look for the green bar, companies mitigate the risk of mid-stream interception and demonstrate efficacy of security measures. Choosing the right SSL certificate provider is also important to getting the best possible protection. Symantec SSL Certificates secure more than one million Web servers worldwide4 . Symantec’s rigorous authentication process, audited annually by KPMG, leads the industry in reputation qualification measure to establish an online business credibility. 2 Includes Symantec subsidiaries, affiliates, and resellers. 3 Symantec Consumer Research Study, January 2011. 4 Includes Symantec subsidiaries, affiliates, and resellers.
  • 7. Copyright © 2012 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, and the Checkmark Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. VeriSign and other related marks are the trademarks or registered trademarks of VeriSign, Inc. or its affiliates or subsidiaries in the U.S. and other countries and licensed to Symantec Corporation. Other names may be trademarks of their respective owners. Conclusion Online services and sales have become areas of growth for businesses of all sizes across a wide range of industries. Symantec SSL Certificates with EV are a proven tool that makes it easy for customers to feel confident about sharing their personal information online. They are a “must have” for businesses that want to maximize their online growth potential. More Information Visit our website http://go.symantec.com/ssl-certificates To speak with a Product Specialist in the U.S. Call 1 (866) 893-6565 or 1 (650) 426-5112 To speak with a Product Specialist outside the U.S. For specific country offices and contact numbers, please visit our website. About Symantec Symantec is a global leader in providing security, storage, and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. Symantec Corporation World Headquarters 350 Ellis Street Mountain View, CA 94043 USA 1 (866) 893 6565 www.symantec.com White Paper: How Extended Validation SSL Brings Confidence to Online Sales and Transactions