This is not true at all. In order to have *verified* ssl you need to get a certificae. Otherwise anyone is free to run ssl on their webserver if they want, the customer will just have a popup screen that displays certificate info and asks them if they want to trust it. Which, imho, is better...