Live data from Hacker News

Defending Our Brand

letsencrypt.org

91–100 of 275 posts

Re: Defending Our Brand

#91

Out of curiosity: Why didn't Letsencrypt applied for a trademark right at the start? That this happens was quite foreseeable and occurs quite often if people forget to secure trademarks (I know this won't be a popular opinion because most as I like Letsencrypt and their outstanding service)

It's a fair question, though you don't actually need to register your trademark to "own" it, it just provides some advantages and of course reduces the danger that someone will do what Comodo did.

Re: Defending Our Brand

#92
post #58

I'm pretty sure the lawyer would have known about letsencrypt.org and their Let's Encrypt project before filing this. So that being said, reading the fine print of what the lawyer had to sign in order to submit the application, shouldn't the lawyer be vulnerable to perjury charges? Excerpt from http://tsdr.uspto.gov/documentviewer?caseId=sn86790719&docId... : The signatory believes that: if the applicant is filing th…

You would have to prove the lawyer knew. It sounds difficult to prove short of an email exchange and I have no idea how the courts work but hopefully you can't get access to a company's emails just by filing a suit based on "I'm pretty sure"

You might argue "due diligence", that as Lets Encrypt appear on a simply internet search the lawyer's claimed ignorance [if they do claim ignorance] shows a wilful act to hide from knowing that it was already an established trademark. There is no way - on balance of probabilities - that any company enlists a trademark lawyer to register a mark without that lawyer first doing an internet search (eg for associations with nefarious businesses [or one's powerful enough to sue you], or negative associations with crime, etc.).

Google could probably provide the information about such a search being made from the lawyer's offices!

Re: Defending Our Brand

#93

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

I am on LetsEncrypt's side to defend their branding. However, Comodo's intent is understandably clear: you take away my business by giving away free certs I screw you in your branding. (not that I agree with this tactic.)

Re: Defending Our Brand

#94
post #56

Earlier quoted context omitted.

When hasn't StartCom been scummy?

Never I'm pretty sure - we run a ticket reselling website thru an exchange and tried to use the service to get developer certs for our testing site. The web site had a black banner with white text on the top that stated in high contrast that it was the developer site and no actual transactions would run and tickets could not be purchased if a transaction was attempted here. (even was using a test domain while clearly…

> I don't know how StartCom run's the actual process

Badly. We've used their service for five years in clear and constant violation of their ToS, and apart from demanding a one-time hush payment they didn't even pretend care.

Re: Defending Our Brand

#95
post #82
post #58

I'm pretty sure the lawyer would have known about letsencrypt.org and their Let's Encrypt project before filing this. So that being said, reading the fine print of what the lawyer had to sign in order to submit the application, shouldn't the lawyer be vulnerable to perjury charges? Excerpt from http://tsdr.uspto.gov/documentviewer?caseId=sn86790719&docId... : The signatory believes that: if the applicant is filing th…

I'm also puzzled that Let's Encrypt's Trademark policy [1] strongly suggests that 'Let's Encrypt' is a trademark (word mark?) that they have registered, and yet according to the most recent letter sent by the USPTO [2] "The Office records have been searched and there are no similar registered or pending marks that would bar registration [...]" [1] https://letsencrypt.org/trademarks/ [2] http://tsdr.uspto.gov/document…

I don't see anything in their trademark policy that implies they have registered any of their marks yet. In fact, all the marks in the "included, but not limited to" list use ™ instead of ®, the later which can only be used with registered trademarks. Searching the USPTO database[1] for "let's encrypt" only reveals Comodo's 1B registrations.

All that being said, under US law you still have trademark rights even before you register the mark, and ISRG definitely has first use on the Let's Encrypt mark.

[1] http://tmsearch.uspto.gov/bin/gate.exe?f=login&p_lang=englis...

Re: Defending Our Brand

#96
post #68

Earlier quoted context omitted.

I'm donating to keep this nested motivation going. :-)

So, "Pay it Forward" is playing out for real on Hacker News to fight mass or criminal surveillance? Hell, I'm in! Threw them some dough. :)

Is there an easy way to switch from CloudFlare's COMODO to Let's Encrypt? If so I'm in !

Re: Defending Our Brand

#97
post #3

This is disappointing, but not surprising given that Lets Encrypt threatens a large and out-dated revenue stream for Comodo. Thankfully Lets Encrypt is backed by Mozilla and the EFF, they have the resources to defend the brand. Good luck guys!

Couldn't this sort of behavior be against the Mozilla CA Inclusion Policy and thus grounds for no longer bundling Comodo CA certs?

The same could possibly be said for Chromium's Root Certificate Policy. It doesn't break the specific trusted tasks but I would say it counts as generally operating in a non-trustworthy way.

Seems dumb on Comodo's part.

Re: Defending Our Brand

#98
God damnit, I really need to find a decent alternative to Comodo Firewall and HIPS, something that offers similar granular control.

They're far too shady these days.

Re: Defending Our Brand

#100

Earlier quoted context omitted.

Comodo in particular has a long history of shady bullshit. Tarring all CAs with that brush strikes me as unduly harsh.

Indeed. Their PCI-DSS compliance scanning service is completely useless. Service version fingerprinting only, regardless of binary patch level or actual vulns. Yet somehow, the PCI SSC accepts their scan results as actionable for Level 1-3 compliance.

PCI verification is a rubber stamp all the way through, is how.
Post reply on HN