Live data from Hacker News

Why I stopped using StartSSL (Hint: it involves a Chinese company)

pierrekim.github.io

91–100 of 187 posts

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#91

Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.

Even as a Chinese company, where the regulation is none and government involvement is normal, Qihoo is just EXCEPTIONAL.

It has absolutely no respect to user privacy, and will not hesitate to threaten users into their favor, if that doesn't work, hijack your computer.

Shameless, no bottomline......it is worst of the worse.

Mark my words. DONT EVER TRUST IT.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#92
post #49

Earlier quoted context omitted.

For Chinese people working in IT industry, Qihoo is an awful company for the reasons mentioned above, but also for allegedly assisting government Internet censorship. Now let's make their awful name worldwide. ;)

Like it or not, they do have a crack team of engineers. 90%+ of the Windows kernel hackers in China have worked, or still is with Qihoo.

Source?

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#93
post #3

There's really not much reason to use StartSSL now that Let's Encrypt, AWS Certificate Manager and others offer free certs with vastly better support, tooling and interfaces.

Except for third-party services you need to provide your own SSL certificates for. AFAIK there's no way to automate renewing the certificate you use for GitHost (with a custom domain), for example.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#94

Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.

I've worked with a company that at least 30% of our user base uses Qihoo brower. They blocked few of our domains and now, someone from Qihoo asked us to pay so that they will unblock our domains.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#95
post #47

Earlier quoted context omitted.

StartSSL has some of the worst support I've ever encountered. Normally bad support means clueless or non-responsive. However StartSSL support is often actively hostile, treating customers as idiots or worse. I should point out that this isn't always the case, and I have used them in the past without trouble, but the times when it is bad are bad enough to write them off. Their site also looks like it was made in 1998,…

I agree that their style in responding to questions is really bad (one liners etc). Yet I'm having the experience that they responded quickly and with helpful information if you had a question. I'm now just curious what happens to my data if they're sold to China. I mean, the amount of personal data they are asking for when acquiring a certificate is not really small.

It really varies. Sometimes you're right, and they respond quickly (if tersely) to questions. However other times they're rude and dismissive.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#96
post #12
post #7

The author doesn't say why this is worrisome. He just says he's worried "that the PKI front-end (auth.startssl.com) is now hosted within a Chinese Antivirus Company, who uses a Chinese ISP for 2 months and that there hasn't been any news around". The article could certainly use a bit more connecting-the-dots to show how he gets from "they're hosted in China" to "I won't use them anymore".

I think the implication is that the Chinese government exerts a lot of control over the internet there, and are openly monitoring/intercepting internet traffic. As such, they shouldn't be considered a trusted authority for security related purposes.

I'm not convinced that is any more worrisome than the US situation as long as you don't trust them with your private keys. The US also monitors/intercepts internet traffic, except they do so (pre-Snowden anyway) secretly. They actually do a lot of things China gets accused of -- just think of the CISCO router "upgrade" facility.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#97
post #18
post #16

Earlier quoted context omitted.

By default, StartSSL's wizard generates private keys for you. (Providing your own key is of course an option).

For the higher account levels, they also require uploaded scans/photos of sensitive ID documents like passports / drivers' licenses.

There are people who use StartSSL for paid certificates? I though the free certs were the only reason people put up with their craptacular website.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#98

Earlier quoted context omitted.

Nope. Your "understanding" is completely wrong. CloudFlare's network in China does not contain configuration, settings, SSL certificates etc. from non-China CloudFlare customers. We run separate infrastructure there and only if you go through the hoops to expose your web site on our network inside China do we send information about your web site there. Source: me (I'm CloudFlare's CTO)

Not that wrong. You're just saying you have to enable China. Do you make it clear in the UI that a private key is ending up on Baidu's servers operated by Baidu's people? I don't use CF so I don't know - I'm just curious what the user experience is like. I'm asking because your CEO addressed concerns in the CNBC article about Baidu having access to your intellectual property so they seem to have full access. I think…

I'm the person designing this UX and yes, we plan to make quite clear/explicit the option of putting your private key in China. By default, keys will remain outside the country.

Re your comments on user education: if you'd like to learn more about our current UI, I encourage you to sign up for a free account at https://www.cloudflare.com/a/sign-up.

And if you encounter any experiences you feel are not sufficiently clear, I hope that you'll submit specific suggestions to me here: pat@cloudflare.com.

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#99

Chinese company is not a red flag. but Qihoo is. The company has known bad reputation. a. they labeled their own browser as a Microsoft security update, which triggered MS investigation b. they cheated on the anti-virus lab testing and got banned. ....etc.

I've worked with a company that at least 30% of our user base uses Qihoo brower. They blocked few of our domains and now, someone from Qihoo asked us to pay so that they will unblock our domains.

What do you mean by "blocked few of our domains"?

Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)

#100

Earlier quoted context omitted.

So every other CA in the world is doing it half-assed? I'm not aware of any others that require client certs to access the site.

I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I know it's more common in enterprise situations. I'm supposed to have a workflow to backup my browser client certificates just for one site? It's not their fault that browsers mostly have poor UI for handling client certs, but it is their fau…

> I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication.

I don't know what you have been doing the last 20 years on the web (and I'll assume it's more than just surfing facebook), but it's not entirely uncommon, and I've encountered it several places.

Symantec's CA uses it. My online bank used to do so too. I've seen VPNs using it. Iirc some IPv6 tunnel-providers also require you to authenticate using certificates before letting you set up new IPv6 subnets.

It may not be mainstream, but it's part of the standard. And it's much more secure than a regular username/password, for the same reason SSH keys are more secure than allowing username/password logins.

Post reply on HN