Live data from Hacker News

Show HN: My side project that grew - cheap SSL certificates

getssl.me

1–10 of 23 posts

Re: Show HN: My side project that grew - cheap SSL certificates

#5

Maybe I don't understand enough about SSL certificates, but I am hesitant to buy a critical piece of site infrastructure from someones side project. Am I being overly cautious?

They are Comodo certificates and are issued by Comodo CA. We can offer lower prices (yes, even lower than Comodo themselves) because we are a small team and we can put smaller margins.

Also we believe in friendly support and no hidden costs or tricks :)

Re: Show HN: My side project that grew - cheap SSL certificates

#6

Maybe I don't understand enough about SSL certificates, but I am hesitant to buy a critical piece of site infrastructure from someones side project. Am I being overly cautious?

While I agree with you, most vendors give the impression of about as much dependability and trustworthiness (if not less, given their longer-lived but far spammier presentation).

Re: Show HN: My side project that grew - cheap SSL certificates

#7

Maybe I don't understand enough about SSL certificates, but I am hesitant to buy a critical piece of site infrastructure from someones side project. Am I being overly cautious?

As long as the cert chains back to a root CA that is accepted everywhere, there's really nothing of value to separate the various vendors, except the purchasing price.

Unfortunately, ssl is a game where bad CAs ruin it for everyone, not just their customers: It does not matter for an attacker where they got a bogus certificate as long as it is considered valid, and there's little you can do to protect against it, certainly not by paying more or spending more effort on validation of your own cert. ("EV" (which is what the CAs really should have been doing all this time) and cert pinning comes to mind)

Re: Show HN: My side project that grew - cheap SSL certificates

#8

Maybe I don't understand enough about SSL certificates, but I am hesitant to buy a critical piece of site infrastructure from someones side project. Am I being overly cautious?

Almost every SSL vendor resells SSL certificates from a few big names, and other than the ordering/paying process and support (if needed) any certificate from Comodo is as good as any other Comodo Cert, no matter who you buy it through.

There are minor differences between providers (like a Godaddy wildcard for .company.com also including company.com as a secondary entry while RapidSSL wildcard does .company.com only and will give a warning if used for http://company.com) but I've never know a user to care unless a certificate warning pops up.

Post reply on HN