“I Don’t Take Payments Online.” Kelowna Still Needs the Padlock.
91.4% of Kelowna sites hand an insecure visitor over to the secure copy, the best showing of any city I audited. The objection I hear most, taken seriously, then taken apart.
The padlock on your website has never won you a job.
That’s true, and I’ve said it out loud to people who pay me money. What it has done, on mornings neither of us will ever hear about, is lose you two or three.
So when a Kelowna owner waves this off as a designer’s hobby horse, I don’t argue with him. I’ve heard the objection enough times to recite it back before he’s finished saying it.
You don’t take card payments on the site. No cart, no accounts, nobody types anything private into anything. So what exactly is being kept secret, and why should you care about a small symbol in the corner of a browser?
Good question, and the honest answer to it starts with the half of that objection I agree with.
The half of it that’s right
The argument that got handed down to you was about protecting information, and a five page website for an ordinary local business has almost no information on it worth protecting.
Nobody is intercepting your opening hours. Nobody wants the photo of your van.
If the whole case rested on secrets, you’d be right, and I’d have nothing to sell you.
It stopped being about secrets years ago, and nobody sent you the memo.
Kelowna is quietly good at the thing that replaced it. 91.4% of sites here hand an insecure visitor over to the secure copy, against 88% of the small business sites in my sample, and hardly anybody here chose it on purpose.
The screen she gets instead of your homepage
Your customer never learns the word HTTPS, she learns it as the difference between a page that opens and a page that stops her with a full screen warning, and she makes her decision in the second and a half before your name would have appeared.
That warning says nothing about card payments, and what it does say is that her connection isn’t private, printed in a color you associate with hospitals, with a button underneath offering to carry her back to safety.
What would you do with a screen like that in front of you, on a Tuesday, looking for a company you’d never heard of an hour ago?
She takes the button. The search results are still sitting there behind it, warm, with four other companies on them who did nothing smarter than you did.
And the strangers aren’t the only ones who meet that wall. Pool companies showed me the pattern clearest, because the people typing an address from memory are usually the regulars.
Two addresses, one instruction
Your website answers to two versions of its own address, and only one of them earns the padlock.
The redirect is the instruction that catches a visitor on the wrong version and puts her on the right one before she sees a single pixel of anything. Working, you’d never know it was there. Missing, it’s the red screen.
95.7% of the sites I audited in this town answer on the secure version, a shade over the 94% I get across every small business site I checked.
Hosting companies hand you that half now whether you asked for it or not, which is why I don’t get excited about it.
The handover is a separate question, and it’s the one nobody checks. Kelowna manages it on 91.4% of sites, which is the half I care about.
The instruction behind that number, which put this city top of the 24 when I lined them up, is a checkbox in a settings panel that someone ticked once and forgot.
Nobody here earned it. Their hosts did it for them, and I’d take lucky over clever any day of the week.
This town gets a lot handed to it that way, which is why the free afternoon’s work I’d do on a Kelowna site has nothing to do with padlocks.
The address you never type
Now the part that makes this so hard to catch on your own site.
You open it out of your own history, on your own laptop, the way you’ve opened it a thousand times. It lands on the good version every time, because your browser learned the good version years ago and quietly stopped asking.
Your customer doesn’t arrive that way. She arrives off something printed.
A business card from 2018. The sponsor board at the rink. A supplier’s site that still lists you. A directory nobody has logged into since the last owner sold up.
Printed things are old, and old things point at the version without the padlock.
When did you last reach your own website the way a stranger does, off a piece of paper, rather than out of your own history?
What the objection gets wrong
Nothing about encryption. It’s right about encryption, and I’ll keep saying so.
It’s wrong about who’s doing the deciding.
You think the question is whether your customer cares about security. She’s never asked. Her browser answers on her behalf, before your page has even arrived, and it answers by parking a wall in front of your business.
A stranger who hits that wall doesn’t conclude that a certificate expired on a server in another province. She concludes something about you instead, and what she usually concludes is that you closed.
I used to put the whole problem down to aging websites until wedding photographers talked me out of it. Only one of the four answers I get about this holds up, and it isn’t the one about age.
Every page, not only the front one
One more thing worth saying, because it’s where most of the failures I find are hiding.
The forwarding gets set up on the homepage and nowhere else. Your front page behaves beautifully and your prices page doesn’t.
Which page gets linked from a forum post, an old email, or a supplier’s website? Never the homepage. It’s always some page deep in the site that a person actually needed.
So when you ask for this, ask for all of it.
What to ask, and who to ask
You don’t need a developer here and you don’t need me.
Ring or email whoever keeps your site online. Two sentences will do it.
Do you know who that is without looking it up? Most owners I ask can’t say, and finding out is honestly half the job.
Ask for the insecure version of your address to forward to the secure one permanently, on every page. Then ask them to confirm in writing when it’s live, because a promise to look into something can sit in a queue for a season.
That’s the entire job. No rebuild, no plugin, no invoice with my name on it.
Once it’s done, the rest of what I’d do to keep a small site safe is about as cheap and about as dull.
A cheap thing to be wrong about
A client rang me last spring because her phone had gone quiet. Not dead. Quiet enough that she spotted it in her bank statement before she spotted it at her desk.
Her website was fine. Lovely, even. The version printed on her sign board wasn’t, and it hadn’t been since a host migration the previous fall.
How many strangers was that over one quiet season, and would she have felt any of it going? Neither of us will ever know what it cost her, and that’s the cruel part of this one. No bounce, no error, no angry email. The people it happens to never tell you, because as far as they’re concerned you don’t exist.
If yours turns out to be sitting on the wrong side of this, most of my work happens within twenty minutes of here, though your host will probably fix it before I’ve finished reading your email.
Not sure which side you’re on? Send me the address and I’ll go and knock on both versions of it.
If it were my business, I’d send one email to my host tonight, one sentence long, and go back to my dinner.