Earlier quoted context omitted.
It does not force you to use any particular software. You can even write your own client. Shorter validity time makes your users safer. If you lose the private key, it will only be a problem for three monts or less. Reloading your webserver should be a complete non-issue.
Because everyone should love to waste their time writing their own client. And running let'sencrypt scripts as root. And risking their security. And/or renewing certificates every now and then instead of focusing on stuff that matters. And anyone who disagreees should be downvoted to oblivion. YEAH!
Why I stopped using StartSSL (Hint: it involves a Chinese company)
131–140 of 187 posts
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#132Earlier quoted context omitted.
Because everyone should love to waste their time writing their own client. And running let'sencrypt scripts as root. And risking their security. And/or renewing certificates every now and then instead of focusing on stuff that matters. And anyone who disagreees should be downvoted to oblivion. YEAH!
You don't have to run anything as root if you don't want to. There are tons of clients out there without that requirement. Your argument is basically that Let's Encrypt should have put more focus on working like other CAs do, while they decided to focus on better security and automation. Luckily, there are plenty of other CAs out there, and it's quite likely that more of them will start offering free DV certs soon, s…
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#133Earlier quoted context omitted.
Because everyone should love to waste their time writing their own client. And running let'sencrypt scripts as root. And risking their security. And/or renewing certificates every now and then instead of focusing on stuff that matters. And anyone who disagreees should be downvoted to oblivion. YEAH!
You are not getting downvoted for a different opinion, but for false statements.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#134Earlier quoted context omitted.
StartSSL has some of the worst support I've ever encountered. Normally bad support means clueless or non-responsive. However StartSSL support is often actively hostile, treating customers as idiots or worse. I should point out that this isn't always the case, and I have used them in the past without trouble, but the times when it is bad are bad enough to write them off. Their site also looks like it was made in 1998,…
> while using client certificates is secure and everything, it's also seriously user-hostile. I have to remember which computer and browser I used a year ago to sign up? Yeah, I know I should back up client certificates, but seriously who does that? So you want a secure website, and you agree that SSL is needed for things to be secure. But you're not willing to put in one inch of effort yourself to secure your own SS…
If you accidentally visit their page with the wrong browser (Safari or Chrome, I forget) when you need to renew an expiring client certificate - the browser doesn't download it properly, you can't ever request another one. Anyway, letsencrypt sorts that out.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#135Earlier quoted context omitted.
You don't have to run anything as root if you don't want to. There are tons of clients out there without that requirement. Your argument is basically that Let's Encrypt should have put more focus on working like other CAs do, while they decided to focus on better security and automation. Luckily, there are plenty of other CAs out there, and it's quite likely that more of them will start offering free DV certs soon, s…
I don't think anyone will be offering free DV certs while let's encrypt is still so dysfunctional and unusable in a real life situation. There was the potential for that, sure, but they've screwed up.
[1]: https://certsimple.com/blog/domain-validated-ssl-will-be-fre...
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#136but this is how PKI/SSL/CA works. You are borrowing someone else's trust. You are hoping that the company you get a cert from won't pretend to be you. There is no technical mechanism to stop this, no matter where the parent company is based. Also the other thing to note is that virtually all communications companies have some sort of government involvement regardless of where they are based.
Actually, any company can pretend to be you, whether you got the cert from them or not.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#137Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#138Earlier quoted context omitted.
Source?
This is pretty anecdotal and I doubt there will be a list of names written down somewhere. However have a look at the number of acknowledgements in Microsoft's security bulletins from last year: Palo Alto Networks - 34 Qihoo/360 - 27 FireEye - 14 Tencent - 14 Trend Micro - 12 Fortinet - 7 McAfee - 2 VMware - 2 Kaspersky - 1 They are a pretty unsavory company but they really know what they are doing. Source: https://t…
And therein lies the problem... no?
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#139Earlier quoted context omitted.
You are not getting downvoted for a different opinion, but for false statements.
tobltobs: If you say I'm lying you should point out the falsehoods, or you're just another manipulator at work. At least pfg isn't arguing whether I'm telling the truth, he just has a different opinion.
wrong, there are different ways to get a cert, even web interfaces, which you can install everywhere.
> It forces you to reload your web server config every two months, unattended
wrong, if you like that kind of work you can replace it by hand.
> Because everyone should love to waste their time writing their own client.
wrong, because again you are not forced to, you could use one of the many clients available.
> And running let'sencrypt scripts as root. And risking their security.
You don't have to run at root, you could use a client which supports non root.
> If you say I'm lying you should point out the falsehoods, or you're just another manipulator at work.
Wrong again, because your errors have been pointed out already by others. You should start reading the answers and stop your "rage against censorship" quest.
Re: Why I stopped using StartSSL (Hint: it involves a Chinese company)
#140I had a bad experience with StartSSL using their free SSL cert. Basically they just treat you like a thief or scumbag trying to take advantage of their freebie. Eventually I found a company selling $10/year cert which I am happily paying. Now this adds another excuse for me to avoid StartSSL even more.
Opposite experience with their paid service. They respond quickly, even during the night.