Live data from Hacker News

Why I stopped using StartSSL (Hint: it involves a Chinese company)

pierrekim.github.io

31–40 of 187 posts

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#31
post #18
post #16

Earlier quoted context omitted.

By default, StartSSL's wizard generates private keys for you. (Providing your own key is of course an option).

For the higher account levels, they also require uploaded scans/photos of sensitive ID documents like passports / drivers' licenses.

Yes, that's a problem. If a company starts to ask for this sort of information I will refuse unless there are no alternatives.

Trusting a CA to provide your private key is on another matter.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#32
post #29

On a related note, Cloudflare use Baidu servers in China operated by Baidu staff. My understanding is that this means private SSL keys given to Cloudflare live on Baidu owned and operated servers. http://www.cnbc.com/2015/09/14/chinas-baidu-and-cloudflare-i... They offer "keyless" ssl which puts the private key back in the data center but this adds complexity and latency on the initial connect so I suspect most don't…

Baidu is like Google but in China. They must already have a certificate in any browser's trust store. And also, think about all the keys contained in AWS servers, and AWS is in America...

Using a local CA seems like a bad way for a government to compromise HTTPS. If they got caught, that CA would get demolished practically overnight when the browser makers remove it from the trust stores. Compromising a foreign CA seems like a much better strategy. (Although not nearly as simple)

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#33
post #21
post #5

Earlier quoted context omitted.

Cert rotation every 3 months is a feature, IMHO. It encourages you to automate everything related to rotation.

I got downmodded before for saying this, but I still feel this way: Automating this simply means that if someone hacks your machine, they also have full access to generate any certs they like. I don't consider this a positive thing. You can separate the generation onto another machine, but it's much more complicated, and the default install is not that way. I have yet to hear any useful reason to rotate the key.

>Automating this simply means that if someone hacks your machine, they also have full access to generate any certs they like.

Well, they can generate certs for your domain. But what exactly is the big difference between generating a new certificate for your domain and having your private key. I fail to see why it would be a huge risk, they can access all your users data in any case.

>I have yet to hear any useful reason to rotate the key. http://security.stackexchange.com/questions/85963/what-is-th...

Basically limiting damage in case of a compromise.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#34
post #22
post #3

There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.

Lack of support for wildcard certificates is still an issue for Let's Encrypt. Rate limiting and SNI are two issues that means a wildcard certificate is still highly desirable.

I'm struggling to think of a browser that supports SHA-2 TLS encryption, and doesn't support SNI, which one am I missing?

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#35
post #4
post #3

There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.

When I can use Let's Encrypt to get a certificate in production without running anything on my production web server, I'll consider it. Right now, StartSSL validates my domain via email and I only have to touch it once a year, not once every 3 months like Let's Encrypt.

I'm afraid you'll have to go through renewal every 3 months, but I'll still make a shameless plug of my client [1]. It uses DNS validation exclusively so you can generate certificates wherever you want.

In addition, domain authorizations last for 10 months, so you don't have to go through the DNS verification each time: just renewing is sufficient. Run the issue command, drop new certs into configuration management, done. Couple minutes tops. Just set your calendar!

[1] https://github.com/veeti/manuale

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#36
post #3

There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.

StartSSL has some of the worst support I've ever encountered. Normally bad support means clueless or non-responsive. However StartSSL support is often actively hostile, treating customers as idiots or worse. I should point out that this isn't always the case, and I have used them in the past without trouble, but the times when it is bad are bad enough to write them off. Their site also looks like it was made in 1998, and while using client certificates is secure and everything, it's also seriously user-hostile. I have to remember which computer and browser I used a year ago to sign up? Yeah, I know I should back up client certificates, but seriously who does that?

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#37

Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.

Would like to add Baidu isn't better, too.

Example, try search proprietary software, say 'Autocad', first few results are always pirate sites, while google will show the Autodesk site and the wikipedia post.

Recently Baidu also under the spotlight for monetizing illness-related forums[1]. The issue is some patients accused the Internet giant selling their private info to _unqualified_ private hospitals. These hospitals charge a lot but usually their hardware and staff are underqualified.

[1] http://www.chinadaily.com.cn/business/2016-01/12/content_230...

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#38
I had a bad experience with StartSSL using their free SSL cert. Basically they just treat you like a thief or scumbag trying to take advantage of their freebie. Eventually I found a company selling $10/year cert which I am happily paying. Now this adds another excuse for me to avoid StartSSL even more.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#39
post #3

There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.

Just today, I'm setting up my first https by myself.

Started with Let's Encrypt. Running Mac OS X. Failed. Guessed cause has something to do with macports vs homebrew and having the proper Python version active. Disabled macports. Now the app runs.

But I got "Failed to connect to host for DVSNI challenge".

Start googling, reading, messing around with this for a while. No joy.

Bailed on Let's Encrypt, started over with StartSSL, because its the first source of free for not-for-profit certs I found.

Happy to take recommendations for alternatives.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#40

On a related note, Cloudflare use Baidu servers in China operated by Baidu staff. My understanding is that this means private SSL keys given to Cloudflare live on Baidu owned and operated servers. http://www.cnbc.com/2015/09/14/chinas-baidu-and-cloudflare-i... They offer "keyless" ssl which puts the private key back in the data center but this adds complexity and latency on the initial connect so I suspect most don't…

Nope.

Your "understanding" is completely wrong.

CloudFlare's network in China does not contain configuration, settings, SSL certificates etc. from non-China CloudFlare customers. We run separate infrastructure there and only if you go through the hoops to expose your web site on our network inside China do we send information about your web site there.

Source: me (I'm CloudFlare's CTO)

Post reply on HN