I'm getting the 3rd party SSL, ordered it last week, but it seems to take my provider ages to get process my purchase and install it. I hope it's all done by end of this week (I should have ordered it directly form the SSL provider rather than going through my hosting provider).
In regards to security, I made some comments on the post below, that sheds some light into the practices:
https://bt.irlbtc.com/view/34586.120Obviously we also have measures in place to address:
Session Fixation
Brute Force Account attacks
Session Hijacking
CSRF (Cross Site Request Forgery)
Cross Site Scripting (XSS)
SQL, CSS, Ajax injection
We are taking the security issues very serious and constantly update our countermeasures but obviuosly we dont want to discuss them in every detail here in public.