Earlier quoted context omitted.
Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.
Thanks for clarifying! Will a free StartSSL certificate trigger an 'untrusted source' warning from the browser? Also, will a free certificate be adequate for encrypting authentication data in a web API?
Ask HN: What's the best company to buy SSL certificates from?
51–60 of 71 posts
Re: Ask HN: What's the best company to buy SSL certificates from?
#52Re: Ask HN: What's the best company to buy SSL certificates from?
#53http://blog.cloudflare.com/easiest-ssl-ever-now-included-aut...
Re: Ask HN: What's the best company to buy SSL certificates from?
#54FWIW, Stripe recommends DigiCert: https://stripe.com/help/ssl > We recommend DigiCert — their certificates have very wide acceptance (for example, Facebook uses a DigiCert certificate). Other options include NameCheap and GoDaddy. They have slightly lower acceptance but their basic certificates cost $10 to $20.
Re: Ask HN: What's the best company to buy SSL certificates from?
#55Earlier quoted context omitted.
What's the difference between a simple certificate and something higher-grade? What does the simple certificate lack that a higher grade certificate provides?
Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.
imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.
Re: Ask HN: What's the best company to buy SSL certificates from?
#56Earlier quoted context omitted.
Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.
studies has shown that people dont know what the green bar actually means: http://en.wikipedia.org/wiki/Extended_Validation_Certificate... imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.
These are users who also keep their browser sessions going forever and therefore session cookies never expire - thereby making what was supposed to make something more secure, exactly the opposite.
Re: Ask HN: What's the best company to buy SSL certificates from?
#57Earlier quoted context omitted.
Extended verification certificates (EV; "actually verified") cause the browser bar to turn green. That will make people more likely to trust you.
studies has shown that people dont know what the green bar actually means: http://en.wikipedia.org/wiki/Extended_Validation_Certificate... imho a extremely overrated (and overpriced) features, which imposes no extra security what so ever.
You are pointing to a study that was published in 2006. This means the actual data is at least 7 years old.
Can you find a more current example?
Re: Ask HN: What's the best company to buy SSL certificates from?
#58Earlier quoted context omitted.
All EV certificates provide that feature, not just the ones sold by Verisign. Are you a paid shill of Verisign? In general, no one should ever do business with Verisign, due to their practice of domain slamming, their Site Finder misfeature, and other shady practices.
Do they still do that? Thanks for pointing that out though, I found this: http://www.theregister.co.uk/2002/05/14/verisign_hit_with_sl... through Wikipedia: http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 "VeriSign was sued in 2002 for their actions in sending ambiguous emails informing people, often incorrectly, that their domain was about to expire and inviting them to click on a link to renew it. Renewi…
Re: Ask HN: What's the best company to buy SSL certificates from?
#59Earlier quoted context omitted.
That's disingenuous. You should be bundling your CA cert with your cert anyway, which would avoid that problem.
Neither the linked article nor any of the parent comments talk about certificate chaining, which seems to be what you're referring to. Also, please check the definition of 'disingenuous', it's massively overused on Hacker News (often in a completely incorrect context).
I don't know what your beef is with 'disingenuous,' but that's exactly what I meant.
Re: Ask HN: What's the best company to buy SSL certificates from?
#60Earlier quoted context omitted.
Do they still do that? Thanks for pointing that out though, I found this: http://www.theregister.co.uk/2002/05/14/verisign_hit_with_sl... through Wikipedia: http://en.wikipedia.org/wiki/Domain_name_scams#cite_note-6 "VeriSign was sued in 2002 for their actions in sending ambiguous emails informing people, often incorrectly, that their domain was about to expire and inviting them to click on a link to renew it. Renewi…
Verisign cannot do that anymore since they no longer operate a registrar (Network Solutions was spun-off/sold-off).