Why I stopped using StartSSL (Hint: it involves a Chinese company)
pierrekim.github.io
Why I stopped using StartSSL (Hint: it involves a Chinese company)
1–10 of 187 posts
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#2What more, not using their services does not enhance or harm your security in many meaningful way as long as they remain a trusted CA who can sign any domain they want to. If nation-state espionage is really a concern for you, take a few minutes of your time and purge the list of trust anchors installed on your OS[2].
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#3Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#4There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#5There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.
When I can use Let's Encrypt to get a certificate in production without running anything on my production web server, I'll consider it. Right now, StartSSL validates my domain via email and I only have to touch it once a year, not once every 3 months like Let's Encrypt.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#6There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.
When I can use Let's Encrypt to get a certificate in production without running anything on my production web server, I'll consider it. Right now, StartSSL validates my domain via email and I only have to touch it once a year, not once every 3 months like Let's Encrypt.
I'll take an automated process I run via cronjob and that requires no manual intervention, over a process that requires I touch it once a year.
The decision (to me) is a no-brainer.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#7The article could certainly use a bit more connecting-the-dots to show how he gets from "they're hosted in China" to "I won't use them anymore".
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#8Isn't saying that a bit wrong? at least point on the hint that it is having connections with a state-owned company.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#9Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#10There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.
When I can use Let's Encrypt to get a certificate in production without running anything on my production web server, I'll consider it. Right now, StartSSL validates my domain via email and I only have to touch it once a year, not once every 3 months like Let's Encrypt.