Then there's the whole question of what it means to be "secure". As someone pointed out above, a "secure connection" is mainly about encrypting it to secure against eavesdroppers. As another person pointed out, certificates also help with *authentication*, i.e., making sure you're really talking to the party you *think* you're talking to. But... as someone else said elsewhere long ago, most so-called web security is like ensuring you use an armored car to take a loose wad of cash from someone living on a park bench to someone living in a fridge box under a bridge. That is, once the secure *connection* has been used, to the *authenticated* party, your "security" worries are *not* over, by any stretch.