Why download somebody's SSL certificate?

When you surf an internet site and you get that "key" icon, it means your site is 'secure.' Well what it really means is your session is encrypted. The bits you sent over the Internet to buy your goods off Amazon or wherever are scrambed. You scrambed the bits with a public key that was provided to you by your Browser's authors, and thay key was provided to them by Amazon (in our fictional scenario). Amazon has a private key that only they have access to. The key unscrambles your message, so nobody who intercepted it along the way could have stolen it. Who would steal your message? Probably nobody, it's very difficult to do and they'd have to know what they're doing. Presumably if somebody had that expertise they'd use it to steal something more lucritive than my Visa number. But more power to them.

So the key Amazon has, what's so special about it? Nothing really. The only reason Microsoft's browser 'trusts' the key is that it was issued by some private 3rd party, who made really really sure Amazon (or whoever) was a real company and had real humans somewhere in the back room taking care of your money. Amazon had to pay a fee to this private 3rd company for the certificate. It's a trust issue. All of the parties involved promised they would never never never let the private key come into the hands of bad guys who want to steal from you or Amazon. The public key is free for the taking for whomever wants it, because it will only make messages that Amazon can read.

So why do you have to download my key? Why doesn't Microsoft's browser implicitly trust Greg's certificate? It doesn't because I didn't pay a 3rd company to issue me the key. Instead I made the key myself, with free software. It isn't any weaker than the 3rd party's keys that I would have to pay for. It's just as strong. If you download my key, you have to somehow trust that I'll keep the private key private, where nobody can get it to unscramble the secret messages you send to me, that you encrypted using my public key. They public key is the one you can click on and install on the previous page, just follow the instructions.

Go back and get it now.