Live data from Hacker News

Domain validated SSL certs for google.com.mg and google.com.im (not Google)

certsimple.com

11–20 of 27 posts

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#12
post #8

Earlier quoted context omitted.

The tone of the article is such because the company writing it only sells EV certs and therefore is on a relentless quest to discredit DV certs as inferior.

Author here: DV certificates are inferior. Knowing whose key you're encrypting with is a good thing. DNS providers do not do identity checks. Edit: 100% agreed with laumars' point below regarding blogs and low trust sites. DV certificates have their place, it's just that high trust websites aren't it. I've added an author tag as requested.

If I'm connecting to my bank or preferred e-commerce store, then yes. If I'm connecting to Joe's wordpress blog or some random wiki then I barely care if the site is even under TLS to begin with, let alone whether the site had passed a human authorisation process prior to receiving their certificate.

And frankly, the vast majority of internet go-ers are non-technical and wouldn't even notice the different between DV and EV certificates (let alone care), so I question just how well EV even solves the problem you're claiming to address.

It's also generally good etiquette to disclose when you're the author and employee of the company in question (a company that specifically sells EV certificates) when replying on HN; since that highlights biases regarding your arguments

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#13
So, in a nutshell, these guys are saying that (a) it's too easy to get a misleading cert and (b) they make it easier to get a certain kind of cert. That's going to be a hard sell. They need to make a case that non-EV certs are worthless not only in terms of security but to consumers - i.e. that you, the certificate buyer, will lose business. Then they need to explain why EV certs are better, and lastly how that superiority can be preserved even on a shorter acquisition timeline. They do none of that. The article is not only too pitch-y for HN, but it's also a poor pitch.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#14

So, in a nutshell, these guys are saying that (a) it's too easy to get a misleading cert and (b) they make it easier to get a certain kind of cert. That's going to be a hard sell. They need to make a case that non-EV certs are worthless not only in terms of security but to consumers - i.e. that you, the certificate buyer, will lose business. Then they need to explain why EV certs are better, and lastly how that super…

[deleted]

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#15
post #10
post #4

I don't get the tone of the article. Why is this a bad thing? It's not the job of SSL to ensure a domain name is not owned by someone it shouldn't be. That falls to the domain registrar, if you have a problem with someone owning google.com.mg go take it up with the registrar or better yet leave it up to Google as it's THEIR trademark. I actually find this to be a good thing that someone was able to get a domain, crea…

> it's not the job of SSL to ensure a domain name is not owned by someone it shouldn't be. That's correct. CAs checked identity back in the 90s, but stopped and moved to domain validation for most certificates. The article mentions explicitly: the certificates aren't fake, they're just DV, and that's what DV is. Obviously most consumers have no idea about that, and have been conditioned to trust any kind of SSL. The…

> Obviously most consumers have no idea about that, and have been conditioned to trust any kind of SSL.

Is that actually the case? If I see a "check for HTTPS!" reminder, most of them clearly show and talk about the name from a DV cert.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#16
post #8

Earlier quoted context omitted.

The tone of the article is such because the company writing it only sells EV certs and therefore is on a relentless quest to discredit DV certs as inferior.

Author here: DV certificates are inferior. Knowing whose key you're encrypting with is a good thing. DNS providers do not do identity checks. Edit: 100% agreed with laumars' point below regarding blogs and low trust sites. DV certificates have their place, it's just that high trust websites aren't it. I've added an author tag as requested.

Person who just registered certsimple.org and certsimple.net here. Will you issue me a EV cert?

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#17
post #15
post #10

Earlier quoted context omitted.

> it's not the job of SSL to ensure a domain name is not owned by someone it shouldn't be. That's correct. CAs checked identity back in the 90s, but stopped and moved to domain validation for most certificates. The article mentions explicitly: the certificates aren't fake, they're just DV, and that's what DV is. Obviously most consumers have no idea about that, and have been conditioned to trust any kind of SSL. The…

> Obviously most consumers have no idea about that, and have been conditioned to trust any kind of SSL. Is that actually the case? If I see a "check for HTTPS!" reminder, most of them clearly show and talk about the name from a DV cert.

What do you mean by 'the name from a DV cert?'

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#18
Head of Let's Encrypt here.

We were aware of the "google.com.mg" cert soon after it was issued. We didn't revoke the cert for the same reason we don't revoke most certs: as far as we can tell, the cert was issued to the entity properly controlling "google.com.mg". Whether or not that is Google (the company) is not really within our purview.

That said, in this case, as a courtesy, we did notify Google employees and made the decision to report the site to Google Safe Browsing. GSB and SmartScreen are the right places to deal with things like this.

IIRC GSB did block the site for a while, but that block seems to be gone now.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#19
post #8

Earlier quoted context omitted.

Author here: DV certificates are inferior. Knowing whose key you're encrypting with is a good thing. DNS providers do not do identity checks. Edit: 100% agreed with laumars' point below regarding blogs and low trust sites. DV certificates have their place, it's just that high trust websites aren't it. I've added an author tag as requested.

Person who just registered certsimple.org and certsimple.net here. Will you issue me a EV cert?

That's pretty hilarious. I'm sure even if CertSimple won't issue you an EV cert that one of the many providers others will.

Re: Domain validated SSL certs for google.com.mg and google.com.im (not Google)

#20
post #8

Earlier quoted context omitted.

Author here: DV certificates are inferior. Knowing whose key you're encrypting with is a good thing. DNS providers do not do identity checks. Edit: 100% agreed with laumars' point below regarding blogs and low trust sites. DV certificates have their place, it's just that high trust websites aren't it. I've added an author tag as requested.

Person who just registered certsimple.org and certsimple.net here. Will you issue me a EV cert?

I just noticed he's in the UK, so surely he's registered certsimple.co.uk, right? Nope. Yay, now I have another domain!

I will begin issuing EV certs via my new company 'Certs Imple Limited' very soon. You can trust us, we have more domains than that other fly by night organization does.

Post reply on HN