Why FurBuy Doesn't Have SSL + Account Security
14 years ago
So we've just received a couple nasty e-mails from upset users who said they'd shun our system from their large amount of business because of our policies. I figured it would be a good opportunity to explain why we do what we do. So without further adieu:
Why Doesn't FurBuy Have Secure Login/SSL?
This is a pretty simple one: because high quality CA certificate ownership and hosting is very expensive. The CA's (Certificate Authorities) have a monopoly on the ability to reliably and accurately and safely host the security certificate validations for every major domain out there, and every browser knows who the CA's are and who to trust. Purchasing a security certificate costs about $500 per year (a little cheaper through less reliable companies) plus another $200 per year to have the certificate hosted on a CA server. The whole process is automated and costs the CA's pennies per day per certificate to run, however since they have a monopoly and the only places that typically have security certs are big businesses, they can charge exorbitant prices to offer and host these security certificates. Without them, your browser would go APESHIT on you and your visit to FurBuy, which would cause a lot of folks to not even use our site at all. Since we can't even cover the $400/mo to keep FurBuy hosted, there's no way we can also afford an additional $700 per year of overhead for a secure server cert from a CA.
Why do I have to prove who I say I am?!
So lately a lot of folks have signed up using "Full Names" that look a lot like fan names. Things like "Lupine Silverback" as a fabricated example. Some of you may not know it, but our admins screen EVERY new account that's made on the system, and if we find one that's questionable, we place it in a "Pending" status which notifies the user that their account information may need to be updated and until they either update it accordingly or contact us about it, they will still be able to login and browse the site, but unable to bid, post or comment until the account issue is corrected. 95% or more of our users never see any admin interaction like this because they fill out their account information clearly and without anything questionable. When there is something questionable, we just need confirmation that you are who you say you are. If you had your name legally changed to a fan/spiritual/therianthropic/mythical/fantastic/gaysplosive name that you love then that's great - we just need some proof of that through a scan or photo of a photo ID and everything will be hunky dory.
Why do we do these checks? Quite simply, because there's a lot of trolls and flamers and miserable sods in fandom who honestly have nothing better to do than spin-up a new account on FurBuy (or other furry sites) to harass and create drama. We take fraud very seriously, and we assume quite rightly that our buyers and sellers on FurBuy do as well, and we take these measures to attempt to protect users from harmful accounts proactively whenever possible. So we do a cursory screen on every new account by verifying that all of the data looks accurate and correct, in order to protect our community. We also need people's full legal names on file for legal purposes, should anything arise of that nature. Thankfully in 11 years we've never needed to tap people's accounts for those purposes. We hope things stay that way. =)
As always, if you have questions or comments don't be shy. We're here to help folks buy and sell safely and successfully online, that's why we've invested so much time and money into FurBuy. Please feel free to tap us on the shoulder anytime. ;)
P.S. If you're angry about something we've done, please realize we're just doing our jobs and trying to protect our community. If you can't send a polite e-mail because you're raging, please walk away and cool down for a bit and THEN contact us. We really dislike shelling out to run this service and spending a ton of our personal time working on it, but what we really can't tolerate is being harassed and put-down and attacked after all of that hard work and effort. If you have some issue and you can't manage to be polite and professional, then we have two words for you: fuck off. Thanks. =)
Why Doesn't FurBuy Have Secure Login/SSL?
This is a pretty simple one: because high quality CA certificate ownership and hosting is very expensive. The CA's (Certificate Authorities) have a monopoly on the ability to reliably and accurately and safely host the security certificate validations for every major domain out there, and every browser knows who the CA's are and who to trust. Purchasing a security certificate costs about $500 per year (a little cheaper through less reliable companies) plus another $200 per year to have the certificate hosted on a CA server. The whole process is automated and costs the CA's pennies per day per certificate to run, however since they have a monopoly and the only places that typically have security certs are big businesses, they can charge exorbitant prices to offer and host these security certificates. Without them, your browser would go APESHIT on you and your visit to FurBuy, which would cause a lot of folks to not even use our site at all. Since we can't even cover the $400/mo to keep FurBuy hosted, there's no way we can also afford an additional $700 per year of overhead for a secure server cert from a CA.
Why do I have to prove who I say I am?!
So lately a lot of folks have signed up using "Full Names" that look a lot like fan names. Things like "Lupine Silverback" as a fabricated example. Some of you may not know it, but our admins screen EVERY new account that's made on the system, and if we find one that's questionable, we place it in a "Pending" status which notifies the user that their account information may need to be updated and until they either update it accordingly or contact us about it, they will still be able to login and browse the site, but unable to bid, post or comment until the account issue is corrected. 95% or more of our users never see any admin interaction like this because they fill out their account information clearly and without anything questionable. When there is something questionable, we just need confirmation that you are who you say you are. If you had your name legally changed to a fan/spiritual/therianthropic/mythical/fantastic/gaysplosive name that you love then that's great - we just need some proof of that through a scan or photo of a photo ID and everything will be hunky dory.
Why do we do these checks? Quite simply, because there's a lot of trolls and flamers and miserable sods in fandom who honestly have nothing better to do than spin-up a new account on FurBuy (or other furry sites) to harass and create drama. We take fraud very seriously, and we assume quite rightly that our buyers and sellers on FurBuy do as well, and we take these measures to attempt to protect users from harmful accounts proactively whenever possible. So we do a cursory screen on every new account by verifying that all of the data looks accurate and correct, in order to protect our community. We also need people's full legal names on file for legal purposes, should anything arise of that nature. Thankfully in 11 years we've never needed to tap people's accounts for those purposes. We hope things stay that way. =)
As always, if you have questions or comments don't be shy. We're here to help folks buy and sell safely and successfully online, that's why we've invested so much time and money into FurBuy. Please feel free to tap us on the shoulder anytime. ;)
P.S. If you're angry about something we've done, please realize we're just doing our jobs and trying to protect our community. If you can't send a polite e-mail because you're raging, please walk away and cool down for a bit and THEN contact us. We really dislike shelling out to run this service and spending a ton of our personal time working on it, but what we really can't tolerate is being harassed and put-down and attacked after all of that hard work and effort. If you have some issue and you can't manage to be polite and professional, then we have two words for you: fuck off. Thanks. =)