Live data from Hacker News

Ask HN: What's the best company to buy SSL certificates from?

news.ycombinator.com

51–60 of 71 posts

Re: Ask HN: What's the best company to buy SSL certificates from?

#51

Earlier quoted context omitted.

Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.

Thanks for clarifying! Will a free StartSSL certificate trigger an 'untrusted source' warning from the browser? Also, will a free certificate be adequate for encrypting authentication data in a web API?

should be ok for a web API, but for an e-commerce site, you'll likely want a recognized CA.

Re: Ask HN: What's the best company to buy SSL certificates from?

#54
post #14

FWIW, Stripe recommends DigiCert: https://stripe.com/help/ssl > We recommend DigiCert — their certificates have very wide acceptance (for example, Facebook uses a DigiCert certificate). Other options include NameCheap and GoDaddy. They have slightly lower acceptance but their basic certificates cost $10 to $20.

FB's been switching over the VeriSign -- at least, in my neck of the woods. I pay attention to certs, so I noticed this and took some time to somewhat reassure myself that no MITM was going on. (If I'm wrong, someone please tell me!)

Re: Ask HN: What's the best company to buy SSL certificates from?

#55

Earlier quoted context omitted.

What's the difference between a simple certificate and something higher-grade? What does the simple certificate lack that a higher grade certificate provides?

Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.

studies has shown that people dont know what the green bar actually means: http://en.wikipedia.org/wiki/Extended_Validation_Certificate...

imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.

Re: Ask HN: What's the best company to buy SSL certificates from?

#56

Earlier quoted context omitted.

Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.

studies has shown that people dont know what the green bar actually means: http://en.wikipedia.org/wiki/Extended_Validation_Certificate... imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.

Exactly! In fact the change to green out of the ordinary lack of it might make them think something is WRONG, not better.

These are users who also keep their browser sessions going forever and therefore session cookies never expire - thereby making what was supposed to make something more secure, exactly the opposite.

Re: Ask HN: What's the best company to buy SSL certificates from?

#57

Earlier quoted context omitted.

Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.

studies has shown that people dont know what the green bar actually means: http://en.wikipedia.org/wiki/Extended_Validation_Certificate... imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.

Carl,

You are pointing to a study that was published in 2006. This means the actual data is at least 7 years old.

Can you find a more current example?

Re: Ask HN: What's the best company to buy SSL certificates from?

#58
post #27

Earlier quoted context omitted.

All EV certificates provide that feature, not just the ones sold by Verisign. Are you a paid shill of Verisign? In general, no one should ever do business with Verisign, due to their practice of domain slamming, their Site Finder misfeature, and other shady practices.

Do they still do that? Thanks for pointing that out though, I found this: http://www.theregister.co.uk/2002/05/14/verisign_hit_with_sl... through Wikipedia: http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 "VeriSign was sued in 2002 for their actions in sending ambiguous emails informing people, often incorrectly, that their domain was about to expire and inviting them to click on a link to renew it. Renewi…

Verisign cannot do that anymore since they no longer operate a registrar (Network Solutions was spun-off/sold-off).

Re: Ask HN: What's the best company to buy SSL certificates from?

#59
post #24

Earlier quoted context omitted.

That's disingenuous. You should be bundling your CA cert with your cert anyway, which would avoid that problem.

Neither the linked article nor any of the parent comments talk about certificate chaining, which seems to be what you're referring to. Also, please check the definition of 'disingenuous', it's massively overused on Hacker News (often in a completely incorrect context).

jorangreef said "RE StartSSL..." then pointed to an article about the problems of SSL w.r.t mobile apps. Since this is in reply to a very positive post about StartSSL, the obvious inference is that his linked article provides some evidence on why one wouldn't want to use StartSSL. But that's pure FUD because the only mention of StartSSL in the whole article is that they close their connections so two more TCP connections are required to authenticate the cert... but anyone worth their salt would be bundling in the CA cert anyway, obviating the need for those connections.

I don't know what your beef is with 'disingenuous,' but that's exactly what I meant.

Re: Ask HN: What's the best company to buy SSL certificates from?

#60

Earlier quoted context omitted.

Do they still do that? Thanks for pointing that out though, I found this: http://www.theregister.co.uk/2002/05/14/verisign_hit_with_sl... through Wikipedia: http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 "VeriSign was sued in 2002 for their actions in sending ambiguous emails informing people, often incorrectly, that their domain was about to expire and inviting them to click on a link to renew it. Renewi…

Verisign cannot do that anymore since they no longer operate a registrar (Network Solutions was spun-off/sold-off).

Ok, I didn't know that. What I should investigate is whether the same people that authorized those shady tactics are still in charge there (or whether that culture persists).
Post reply on HN