Skip to main content
Research Paper Undergraduate 5,806 words

Internet Trust Certificates: BBBOnline, TRUSTe, and VeriSign

~30 min read
Abstract

This paper examines the role of internet trust certificates and digital signatures in securing online commerce and building consumer confidence. Drawing on studies from Cranfield University, the London School of Economics, and multiple consumer surveys, the paper reviews the nature of online trust, the mechanics of digital certificates, and the privacy seal programs offered by BBBOnline, TRUSTe, and VeriSign. It evaluates whether these certificates genuinely prevent misuse of personal information, identifies loopholes in current self-regulatory frameworks, and considers consumer attitudes toward online privacy. The paper concludes with recommendations for best practices that Internet trust organizations should adopt to strengthen credibility and protect users.

Key Takeaways
  • Introduction: Online security and the rise of trust certificates
  • Understanding Trust and Digital Certificates: Definitions of trust, certificates, PKI, and revocation
  • Consumer Privacy Concerns and Trust Cues in E-Commerce: Research on consumer distrust and privacy seal programs
  • BBBOnline, TRUSTe, and VeriSign: Background and Services: Organization histories, seal types, and service offerings
  • Guidelines, Loopholes, and Real-World Effectiveness: Certificate guidelines evaluated against known violations
  • Consumer Attitudes Toward Internet Trust: Survey findings on privacy concerns and trust development
  • Conclusion and Best Practices: Recommendations for Internet trust organizations going forward
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • The paper grounds abstract concepts like "trust" and "digital certificates" in concrete definitions and real-world examples, making technical material accessible to a general academic audience.
  • It moves logically from theoretical foundations through institutional analysis to empirical consumer research, building a coherent argument across multiple sources.
  • The inclusion of specific case studies — such as the Batteries.com privacy violation and the FXWeb/Sonnet VeriSign use case — gives the evaluation of certificates tangible weight rather than remaining purely theoretical.

Key academic technique demonstrated

The paper demonstrates effective comparative institutional analysis. Rather than treating BBBOnline, TRUSTe, and VeriSign as interchangeable, the author systematically distinguishes each organization's structure, seal programs, privacy policy requirements, and enforcement mechanisms. This comparison is then used to evaluate whether self-regulation alone is sufficient — a technique that turns description into argument.

Structure breakdown

The paper opens with an introduction establishing the problem, followed by an extended literature review covering trust theory, certificate mechanics, and consumer behavior research. Three focused sections address the background, services, and guidelines of the three organizations. A dedicated evaluation section tests the certificates against real cases. Two final sections synthesize consumer attitude research and offer concluding best-practice recommendations. This question-and-answer subheading structure gives the paper clarity and makes each analytical section easy to locate.

Introduction

In every Internet-based transaction, online security is considered a matter of great concern. The susceptibility of internet auction sites to high proportions of deceptive activities has increased the significance of security measures. The emergence of Internet trust certificates and signatures is expected to extensively increase the security of electronic commerce and legal transactions conducted online.

Understanding Trust and Digital Certificates

Information and communication technology professionals at two prominent British universities assert that public reliance upon electronic media of communication — including the internet, mobile, and wireless communications — has been at its lowest point in the last decade. Analysts from Cranfield University, Oxfordshire, and the London School of Economics and Political Science (LSE), in collaboration with the Office of Science and Technology, sponsored a study that probed the evolution of the Internet, interactivity, and its influence on the level of trust and confidence among users.

Trust has been defined as a desire to depend upon an exchange partner in whom one has confidence. In a review of marketing literature, two approaches may be detected. First, trust is considered as a faith, confidence, or expectation about an exchange partner's trustworthiness arising from the partner's skill, dependability, or intentions. Second, trust is perceived as a behavioral intention indicating dependence on a partner, associated with vulnerability and uncertainty on the part of the trusting party.

Professor Brian Collins, head of the Information Systems Department at Cranfield University, observed that a primary cause of absent trust is the insecure nature of the technologies presently applied. Such technologies form a complex system of interactions and interdependencies that have not been well planned and are not well understood. Professor Robin Mansell similarly noted that as these technologies evolve, the vulnerabilities and risks confronted by web users also increase. Society's growing dependence on cyber trust systems is not balanced by the resilience or capacity for graceful degradation of those systems, giving rise to very unstable levels of trust among users. Data released by the Consumers' Association in March 2005 supports this view: approximately 20 million adults in the UK reported knowing someone who had been a victim of cybercrime or having had their identity compromised.

A certificate securely connects a public key to the entity that holds the related private key. With a certificate in place, host computers on the Internet no longer need to request passwords from individual subjects who require authentication before gaining access. Instead, the host establishes trust in a certification authority that authenticates individuals and resources linked to private keys. The host can then extend this trust through a certificate hierarchy ultimately anchored in a root certificate — that is, a certificate from a certification authority that establishes a defined level of integrity and security for the entire hierarchy. Practical examples of certificate use include connecting to a website via a Secure Sockets Layer (SSL) session, accepting a certificate during software installation, or accepting a certificate when receiving an encrypted or digitally signed email message.

When understanding public key infrastructure, it is important to understand not only how certificates are issued, but how they are revoked and how information about those revocations is made available to clients. This matters because revocation information is critical for any application seeking to verify whether a particular certificate is currently considered valid. Certificate revocation information is sometimes compiled in the form of a certificate revocation list (CRL), though that is not the only form it can take. Applications associated with a certificate may connect to an intranet or internet site for information about certification authorities and certificate revocation details.

In organizations where servers run Windows Server 2003 with SP1, various options exist for how certificates and certificate revocation lists are handled. The Update Root Certificate component in Windows Server 2003 with SP1 is designed to automatically check the list of trusted authorities on the Microsoft Windows Update website when required by an application. If an application is presented with a certificate obtained from a certification authority that is not directly trusted, the Update Root Certificate component connects to the Microsoft Windows Update website to determine whether Microsoft has added that authority to its list of trusted authorities. If so, the authority's certificate is automatically added to the trusted certificate store on the computer. The Update Root Certificates component is not mandatory and can be removed or excluded from installation.

Researchers have identified several trust models on the Internet that attempt to achieve maximum trust with minimum risk. These include the X.509 Standard Public Key Infrastructure (PKI), Pretty Good Privacy (PGP), the Simple Public Key Infrastructure (SPKI), and the Simple Distributed Secure Infrastructure (SDSI). Such models employ public key encryption techniques, certificates, and digital signatures. A certificate is used as a trust token among parties on the Internet to demonstrate that you are who you claim to be. This area of study surveys prevailing trust models, their certificates, their structures, the manner in which they address transitivity of trust, and Certificate Revocation Lists (CRLs).

Consumer Privacy Concerns and Trust Cues in E-Commerce

Bandyopadyay (2002) stated that emerging markets are "high context" cultures, where generating trust and establishing mutually obligatory relationships are sometimes preconditions for conducting business. He added that an emphasis on building trust and relationships reduces the vulnerability of transactions on the Internet where participants do not meet physically. A Consumer Union Survey conducted in 2002 revealed that Internet users are largely skeptical of websites that sell goods or offer purchasing advice. The survey found that only 29% of 1,500 US Internet users indicated they trust web merchants almost all of the time, while roughly two-thirds trusted web retailers only some of the time or never. A contemporaneous study by NFO World Group, sponsored by TRUSTe, indicated that privacy threats were anticipated to have a significantly negative impact on online shopping during the 2003 holiday season. Approximately 49% of respondents said they would limit their online shopping because they did not trust online retailers with their personal information.

Approximately 5.6% said they would not shop online at all due to privacy concerns. The three most significant reasons cited for reducing or stopping online shopping were fear of receiving spam after making a purchase, the threat of identity theft, and the possibility of credit card information being stolen. Such figures warn online retailers of the necessity of building trust with online consumers. Developing consumer trust is crucial for success in any business environment, and arguably even more critical in the online context.

Luo (2002) noted that trust plays a key role in the electronic marketplace, which is associated with high uncertainty and limited legal protection. Building online trust is put forward as a remedy for consumer privacy concerns. Trust is considered not merely a short-term problem, but the most important long-term obstacle to realizing the potential of e-commerce for consumers. A higher degree of trust is necessary in an online shopping environment than in a physical store. Trust alleviates concerns about insecurity that arise when the retailer is unknown, or when the consumer is uncertain about how a company will deliver purchased goods or services. Building trust in e-commerce requires a clear demonstration of rigorous security standards, data protection, and transparency of data use.

Morgan and Hunt (1994) indicate that trust can be generated when firms produce superior resources, uphold high standards of corporate values, communicate information about expectations and market intelligence, and refrain from maliciously exploiting their trading partners. Research dealing with trust from a conventional marketing perspective focuses on experience-based outcomes. In the online environment, however, trust must be established before the online shopping experience can occur. One major area of concern for consumers in developing trust is privacy. As Luo (2002) noted, in the context of internet marketing, invasion of privacy refers to the unauthorized collection, disclosure, or other use of personal information. Given the high priority consumers place on privacy, the FTC has been actively involved in establishing guidelines for online marketers in addressing and meeting privacy requirements.

The FTC has relied on fair information principles to guide privacy regulations and industry practice in the United States. These principles include "notice/awareness, choice/consent, access/participation, security/integrity, and redress/enforcement." Despite industry dependence on self-regulation, Milne and Boza (1998) found in a study of approximately 365 organizations that only about 38% notified consumers about personal data collection, 33% disclosed how the information would be used, and 26% requested permission to use that information. Many organizations use the Internet to collect information through cookies or other tracking software without the knowledge of consumers, adding to privacy concerns. Building trust may be a solution to these consumer anxieties.

When consumers provide information online, they want their transactions secured. Consumers therefore need some form of indicator on a website that serves as a surrogate for trust. Warrington and others (2000) identified several cues that consumers use when shopping online. These include privacy, return, and security policies, as well as the presence of a company address and telephone number for alternative ordering procedures. The researchers also noted that the overall professional appearance of a site promotes consumer trust. Turban and others (2002) echoed this and identified privacy and product return policies as components of a model that builds consumer trust in the online merchant. This model incorporates the presence of trust certificates and seals such as VeriSign and TRUSTe, along with vendor evaluation mechanisms like the Better Business Bureau logo. Of the various seal-of-approval programs available, two are most prominent: TRUSTe and BBBOnline.

In a review of the top 500 Internet consumer websites as ranked by Media Metrix in 2000, approximately 23.9% of sites displayed some form of seal emblem, symbol, or endorsement. The TRUSTe program addresses fair information principles: its authorization covers notice, choice, security, data quality, and access. Sites carrying the TRUSTe seal are evaluated through an initial inspection, seeding, and external audits. The BBBOnline program aims to assure consumers that their personal information will be protected by participating companies. Both TRUSTe and BBBOnline intend to increase consumer confidence in and trust of the online companies displaying their seals of approval.

Zemke and Connellan (2001) reiterated the importance of several such indicators in their publication Keys to Build Trust from the First Click. In particular, the presence of seals of approval — including BBB Online, TRUSTe, and VeriSign — along with Visa or American Express logos, is identified as a significant trust signal. The importance of consumer privacy and security policies, third-party seals of approval, return guarantees, and telephone and email support is also endorsed by Urban, Sultan, and Qualls (2000). By the end of 2002, five online privacy seal programs were available to website operators: BBBOnline, CPA WebTrust On-Line Privacy, the Direct Marketing Association's Privacy Promise, SecureAssure, and TRUSTe.

Additional analysis of seal-of-approval programs was provided by Miyazaki and Krishnamurthy (2002). These authors found that the mere display of an Internet seal of approval logo increases consumer perceptions of the favorableness of a site's privacy policy. The presence of such logos was found to enhance anticipated disclosure and patronage rates among consumers with comparatively high online shopping risks, but had no impact on consumers with low online shopping risk perceptions. Notably, the FTC found after surveying heavily trafficked websites that only 8% displayed a seal, and that nearly half of the sites displaying seals did not meet the standards set for fair information practices. It is evident that establishing trust is significant for retailers in the online environment.

While name and brand recognition of established conventional retailers can provide a baseline of confidence for consumers going online, uncertainty still arises when dealing with unknown merchants. Online companies have at times failed to deliver on promises — particularly during the 2000 and 2001 holiday seasons — and unfulfilled commitments have deepened consumer hesitation about purchasing online. As Hemphill (2002) observed, electronic commerce will not reach its full potential in the US economy unless consumers feel confident that their privacy and confidentiality are protected.

Yoon (2002) revealed that to secure trust for a website, managing the overall image of the site was more important than emphasizing its functionality. He also found that websites operating exclusively online are in greater need of trust acknowledgment than those with both online and offline presences. These findings further highlight the necessity of improving communication with consumers to foster their trust in websites. Since consumers often draw on cues from their environment, companies must generate trust signals and create favorable conditions in which transactions can take place. Based on a review of the literature, several trust cues were identified: privacy, security, and return policies; shipping strategies; warranty follow-up; email contact; physical address or location; phone or fax numbers; alternative ordering options; and logos from BBB, TRUSTe, VeriSign, or credit card companies.

According to a survey conducted by the Ponemon Institute and interactive advertising firm Dotomi, opt-in online marketing campaigns are among the more effective means of building trust with Internet users and obtaining personal information from them. The Online Permissions Survey, sponsored by Dotomi, was based on responses from a statistically representative group of 1,799 Internet-accessing adults across the United States. Researchers presented respondents with two sample environments, both offering the option to permit or refuse an online merchant from sharing their information with third-party marketers. In both cases, the approach that provided opt-in restrictions on data sharing and frequency of contact resulted in higher levels of trust. The outcomes showed that consumers were willing to share more information — including sensitive data — with organizations that assured them of confidentiality. Findings included the conclusion that approximately 84% of consumers desired control over the types and frequency of internet ads received from a particular merchant, and roughly 64% said they would trust an online marketer more if they had control over the online communications they received.

The study also revealed that consumer willingness to be contacted directly by merchants is strongly influenced by purchasing incentives. About 82% of respondents wanted to be notified if they were offered a price discount or a free offer, and about 92% said they would prefer to be notified if a product or promotion was relevant to them based on past purchasing behavior. The Ponemon/Dotomi study complements a study by ReleMail which found a tendency among Internet users to subscribe to email newsletters from organizations that demonstrated trustworthiness. In that research, about 72% of Internet users indicated they would be more inclined to subscribe to a newsletter from a company licensed by a third-party certificate vouching for good email practices.

3 locked sections · 2,500 words
Sign up to read the full analysis
BBBOnline, TRUSTe, and VeriSign: Background and Services900 words
BBBOnline is a subsidiary of the Council of Better Business Bureaus. TRUSTe was established by the Electronic Frontier Foundation (EFF) and Commerce.Net,…
Guidelines, Loopholes, and Real-World Effectiveness780 words
The nature of these certificates is quite legalistic and it is difficult to say whether they represent the best possible methods for achieving their stated objectives. To understand the advantages of having these services, consider the case…
Consumer Attitudes Toward Internet Trust820 words
It is clear that these organizations do not possess real punitive authority, and unless consumers see that laws are being obeyed, satisfaction remains elusive. A study conducted in August 2000 by the Pew Internet and…
Read the full paper →
Plus 130,000+ examples & all writing tools

Conclusion and Best Practices

It is clear from all discussions that consumers did not mind passing on certain types of information to a website, but these types are what they do not consider personal information. They are unwilling to pass on financial information such as credit card numbers or social security numbers. Some data types are superficially similar, but consumers are far more sensitive about certain categories. For example, postal mail addresses, phone numbers, and email addresses are all methods of contacting individuals, but consumers are generally comfortable sharing their email address while reluctant to share their phone number. Sensitivity to postal mail addresses falls between these two extremes.

The reason for this may be partly psychological. An unwanted email requires only a single click to dismiss, and computer users have long been accustomed to this type of nuisance. Even the abundance of email generated by free email services has not deterred widespread use of such services. A phone call, by contrast, can intrude at any hour, and the effort required to end an unwanted call is far more disruptive. Postal mail occupies a middle ground, with many individuals also habituated to discarding mail without opening it. It is therefore plausible that consumers' classification of personal information is partly based on the level of intrusion or harassment associated with its misuse.

To some extent, continued Internet use over time tends to generate a higher level of trust in the medium. Studies distinguish two general categories of cyber trust: "Net-confidence" and "Net-risk." Analysis of individuals across these categories reveals that, in general, continuing Internet users have greater confidence in the information and people they can access online than non-users, many of whom have no opinion on the subject. Moreover, the greater the intensity of Internet use — measured by years of use, breadth of application, and level of expertise — the more trust tends to develop. Trust appears to be reinforced through use of the Internet.

Getting down to more specific terms, when cyber trust is present it is more positively linked with e-commerce usage. At the same time, those who use the Internet more, such as for online shopping, are more exposed to spam and other negative experiences, which can undermine trust and heighten awareness of risks. The Internet user primarily seems to be communicating three things: due regard to their time, due regard to their privacy, and due regard to their user experience.

In conclusion, there is a need for public discourse on the issue of governing cyberspace developments in order to enhance trust, limit the potential for harmful attacks, encourage collective security, and constrain privacy violations. There also remains a significant need for research to support policy interventions in these areas, given the uncertainty about whether such interventions will function as anticipated or generate new difficulties for businesses, governments, and citizens.

Regarding best practices for Internet trust companies, it is clear that their business will not grow until Internet users develop greater faith in the medium and in the practices of online commerce. While nothing much can be done about sites beyond the control of Internet trust companies, the companies do have a number of sites under their coverage, and the practices of these sites must be actively regulated in order to build user trust and thereby attract potential consumers. Specifically, certified companies should be prevented from sharing email addresses or other personal data without permission, and privacy must be protected across all affiliated sites in every manner possible. It may also be worth considering whether Internet trust companies could play a role in the payment collection and disbursement process between customers and merchants. This would ensure that personal addresses and financial data are not misused and would assign a direct responsibility for delivering goods and services to the trust company. Ultimately, these companies earn commissions, and it is reasonable to expect that they provide genuine service in exchange.

Key Concepts in This Paper
Digital Certificates Consumer Trust Privacy Seals Certificate Revocation Public Key Infrastructure Self-Regulation Online Privacy E-Commerce Security TRUSTe Program BBBOnline Seal VeriSign Digital ID Opt-In Consent
Cite This Paper
PaperDue. (2026). Internet Trust Certificates: BBBOnline, TRUSTe, and VeriSign. PaperDue. https://www.paperdue.com/study-guide/internet-trust-certificates-bbbonline-truste-verisign-70124

Always verify citation format against your institution’s current style guide requirements.