
Keeping up with SSL Certificate changes in 2021
When browsing the internet, we are always looking out for SSL certificates subconsciously. SSL, or secure sockets layer, is represented by the little lock icon in our search bar that assures us that a website is safe to visit. Having a secure website that is up to date with SSL is essential. Without it, customers will face a barrier to entry to your site and your search listing could be compromised. There are SSL changes coming in 2021 that will primarily affect Android users on earlier devices – we’ve outlined what you need to know to stay secure.
Overview
SSL is the method where websites can communicate securely with the user.
All traffic and interaction between you and the website is encrypted and cannot be read by anyone else between. This encryption is extremely important, especially regarding activities such as sending payment details over the internet. Before SSL, data would have previously been sent between the user and website in an unencrypted form and could therefore be read by anyone who managed to gain access to it.
SSL used to cost a lot of money (about $250 to $500 per website), but in 2016 a non-profit organisation called ‘Lets Encrypt’ decided to shoulder that cost on their own and offer free SSL certificates to anyone who needs them. In order to be able to start issuing SSL certificates, ‘Let’s Encrypt’ needed to have someone that was already trusted to sign the certificates – much like how you may be the guarantor on someone’s mortgage or loan. ‘IdenTrust’ was this partner, as they offered SSL for banking services.
After several years, ‘Let’s Encrypt’ became so widely trusted that they could issue their own certificates with no more need for cross-signing.
The Problem
Since ‘Let’s Encrypt’ are now able to sign their own certificates, they no longer need ‘IdenTrust’ and on the 21st of September 2021, this partnership will expire. This means all cross-signed certificates will expire and not be renewed. In most cases, this is not a problem since ‘Let’s Encrypt’ will automatically move you to a new SSL certificate.
However, older Android phones, specifically ones before Android 7, cannot be updated in this fashion and they will fail after this date. It is thought that about 33% of all androids in use are older than Android 7.
So what does this mean?
Well, since most websites not only use SSL (since it is now a standard) – they enforce it. So, a device without a valid certificate, such as those on Android 7 or older, will no longer be able to gain access to a large majority of the internet, including YouTube, Facebook, and most importantly, Yellow Cherry Digital sites.
The Solution
Currently, the best solution to combat this issue is to either update your Android device to a version beyond Android 7.
Alternatively, you can download ‘Firefox Browser’ as an app. Firefox uses its own certificate instead of whatever is already on the device. This quick-fix will only help for web browsing. All other apps such as Facebook and YouTube will continue to be inaccessible as they rely on the installed certificate to form a connection to their respective services.
If you need further assistance with SSL or have any questions, contact the Yellow Cherries today.