Live data from Hacker News

Defending Our Brand

letsencrypt.org

121–130 of 275 posts

Re: Defending Our Brand

#121
post #102
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.

> EV certs can't be automated

No entirely, but mostly: seeing as this is my job, I should have some idea. Currently writing a post about how we've used some psych techniques to automate the non-automatable parts which I'll post on HN.

> (and they're a dumb idea anyway)

EV matches identity to public keys. Nothing more, nothing less.

If you need EV, we (https://certsimple.com) specialise in making those background checks far less painless with a bunch of unique tech. This means you get your certificate faster and with a lot less effort on your behalf (and a lot more on ours) during the verification process: https://certsimple.com/about

If a DV cert is fine, go with Let's Encrypt (Hi Richard!), dnsimple (Hi Anthony!) or CloudFlare (Hi John and Filippo!) or Heroku.

Re: Defending Our Brand

#122
post #51

Your motivation motivated me to donate

Please refrain from starting and continuing "comment chains". It's not funny and doesn't add to the conversation.

I disagree. I think it's important to show that multiple people decided to donate because of this single comment. It's prompted me to donate to Let's Encrypt.

Re: Defending Our Brand

#124
post #27

Ah, the death throes of a big company that suddenly had its business model invalidated. Well, not entirely; there are market niches that Let's Encrypt doesn't cover: org-validated and extended validation certs, wildcard certs, anyone who needs a cert that expires in years, ECDSA certs (for the time being)... But theres no doubt that their revenue will be significantly cut, they'll lose shareholder value and need layo…

And code signing certs, especially those for Windows kernel driver development.

Re: Defending Our Brand

#125
FWIW, at $DAYJOB we've been actively getting rid of our Comodo certs and replacing them with Let's Encrypt certs, because the Comodo certs don't work with certain older Android versions that we have to support - but Let's Encrypt's all just work.

If others are doing the same, this would be motivation for Comodo.

Re: Defending Our Brand

#126

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

It's quite a bit more than being childish. They're basically saying F U to the security community and to people who want a secure Internet.

How is this company still alive after their numerous security breaches/issue (https://en.wikipedia.org/wiki/Comodo_Group#Controversies) and then on top of those, this thing? They need to go out of business.

Re: Defending Our Brand

#128

This post made me hover over the green lock icon for this page: "Verified by: COMODO CA Limited"

When I hover over the green lock it says: "Verified by: IdenTrust".

Parent post is correct, HN/YCombinator is using Comodo:

https://thumbsnap.com/i/5ZkbUd6F.png?0623

Re: Defending Our Brand

#129
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Lets encrypt certs are only valid for 3 months. In many situations the auto-renewal stuff is inconvenient. Then its easier to just buy a commercial cert that's valid for a few years.

The whole idea is to motivate you to automate the process as far as possible. This is basically a good idea. It's a faff for us at present 'cos we don't have direct access to our load balancers at this moment (just switched hosting), but we're working on that.
Post reply on HN