Agent6376 wrote: » I'm just learning about this as well, so I may be wrong on this. From what I understand you're using their public key to send the information back, not your own. Once you download the certificate, the website establishes trust with you. You send info with the public key and it decrypts it with the private key, then it sends you info with the private. Anyone who can explain it better or knows about it more than I do, please chime in. I'd like to know this as well.