Live data from Hacker News

StartCom launches a new service – StartEncrypt

startssl.com

1–10 of 12 posts

Re: StartCom launches a new service – StartEncrypt

#5
Okay, there's a lot that's dubious about this.

Firstly, they've completely ignored the existing standards effort of ACME, which Let's Encrypt has cooperated with to develop, and created their own API. This detracts from the effort to standardise this, to no real end. Use Let's Encrypt and you can avail yourself of the entire ecosystem of ACME clients, of which there are many (I develop one). It's likely there will be other CAs supporting ACME in time as well. Whereas this is a CA-specific API with, presently, one implementation.

Secondly, they're still carrying out the dubious practice of charging for revocations.

Thirdly, they claim "Not just for one domain, but up to 120 domains with wildcard support", but this is under their 'Pro' offering, yet Let's Encrypt supports up to 100 SANs per certificate for free. Their free service is limited to 5 SANs.

The only apparent benefit of their free certificates over LE certificates is the one year expiry time. But the whole point of the LE 90 day expiry time is to motivate automation, which is a gain in the long term.

Fourthly, their website is full of broken English, which is impressively amateurish for a CA and the high barriers to entry you generally expect that to imply.

Re: StartCom launches a new service – StartEncrypt

#8
post #5

Okay, there's a lot that's dubious about this. Firstly, they've completely ignored the existing standards effort of ACME, which Let's Encrypt has cooperated with to develop, and created their own API. This detracts from the effort to standardise this, to no real end. Use Let's Encrypt and you can avail yourself of the entire ecosystem of ACME clients, of which there are many (I develop one). It's likely there will be…

They were recently acquired by a Chinese company. Most stuff they have put out since their acquisition seems to imply that whoever is writing their text is not a native English speaker.

Re: StartCom launches a new service – StartEncrypt

#10
Yeah, this isn't sketchy as hell or anything.

StartCom are well known for their misunderstanding of how TLS works (see: the heartbleed revocation bull), and... this apparently costs money?

IIRC StartCom also used to generate private keys on their servers... They're utterly incompetent.

Post reply on HN