Live data from Hacker News

Defending Our Brand

letsencrypt.org

161–170 of 275 posts

Re: Defending Our Brand

#161
post #43

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

Just curious, but do you think companies you consult care enough to switch? It's usually easier to just renew, and I wonder if consultants have the leverage to get customers to care.

Is it easier? How automated can you make renewal with Comodo? Even big companies goof and have a few hours of downtime where their cert expired. With Let's Encrypt, you make it not a human's error anymore.

Re: Defending Our Brand

#163

Earlier quoted context omitted.

Please refrain from unnecessary humor-policing. It's not helpful and only detracts from the sense of community.

It's not humor-policing to point out that HN has a different culture and comments serve a different purpose here. I like pun threads - but I go to /r/jokes when I want them. Here, I expect a certain sort of signal - insight from experienced and intelligent people working hard on interesting technical problems. This isn't to say that humor should be verboten, or pun threads strictly banned - but they're definitely not…

I don't want to be petty... but your comment would have a lot more weight if you made it with your primary account.

That said, I agree with all your points... but we're humans... Even if most of our time is spent on science, we still get amused by the most silly of things; and if those things help support LetsEncrypt... Hurrah!

Re: Defending Our Brand

#164
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Lets encrypt certs are only valid for 3 months. In many situations the auto-renewal stuff is inconvenient. Then its easier to just buy a commercial cert that's valid for a few years.

[deleted]

Re: Defending Our Brand

#165
post #114

Earlier quoted context omitted.

I don't see anything in their trademark policy that implies they have registered any of their marks yet. In fact, all the marks in the "included, but not limited to" list use ™ instead of ®, the later which can only be used with registered trademarks. Searching the USPTO database[1] for "let's encrypt" only reveals Comodo's 1B registrations. All that being said, under US law you still have trademark rights even befor…

This seems like a good example of why you should go through the registration though. Because now they are going to have to use the courts to resolve the situation; presumably (I hope?), if they'd registered, a new registration application for the exact same mark would not even be accepted.

There's a challenge period during trademark registration when they can voice their objections. They may be able block it if they're not too late.

> You may challenge an application for trademark registration at the USPTO by filing an opposition with the TTAB within 30 days after it is published in the Official Gazette.

http://www.uspto.gov/page/about-trademarks

Re: Defending Our Brand

#166
post #102
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.

> EV certs can't be automated

Not entirely, but Let's Encrypt could partially automate the verification process (e.g. looking up business entities and contacting their registered agent with an authorization code), and then fully automate obtaining a certificate with those verified credentials.

Re: Defending Our Brand

#167
post #43

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

Just curious, but do you think companies you consult care enough to switch? It's usually easier to just renew, and I wonder if consultants have the leverage to get customers to care.

It'd be easy to make a case that Comodo is no longer trustworthy, pointing to several of their past actions, and recommending a switch to a safer provider. If the consultant does the work to make the switch happen, and the cost doesn't increase, I doubt the customer would object.

Re: Defending Our Brand

#168
post #23

Learning this, I will not renew my certs with Comodo. This is childish behaviour on Comodos part. If it helps I'll advise any companies I consult to do the same until this changes. Money is the only thing this company will understand.

Turns out I have a Comodo cert expiring soon. Let's see if they do the right thing before I do...

I had a Comodo cert expiring in a year or so, but still went with Let's Encrypt since I was setting it up for other domains.

Re: Defending Our Brand

#169
post #102
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.

(Not to sound like an advertisement, but) I got an email from StartCom the other day, saying that they're moving their StartSSL service to work on a similar policy to Let's Encrypt (which I hope means they're just running an ACME server)—but with the proviso that, since they do have the background-checking infrastructure required for EV "trust verification", they've combined the two.

If I recall, StartSSL sort of hoists their EV identity-verification out into its own step before you actually apply for certs. The identity-verification process costs money (and it can't not; it involves paying real people to do background checks), but any EV certs issued to a verified identity are free.

I think what this will mean is that, if you do an ACME request to StartSSL using an identity they've verified—and for a domain associated with that identity—then the cert in the response will automatically be an EV cert.

This is pretty huge, in that usually EV certs cost a large amount per issuance—whereas a pre-verified ACME-issued cert effectively has zero marginal cost to reissue. Previously, EV certs were usually used only for apex domains, with a secondary DV cert collecting the internal SANs together—because the DV cert had a low (now zero) reissuance cost, while the EV cert cost the full amount each time to get reissued. Now you can just use your EV cert for everything, and alter it as suits you: much simpler.

I hope other CAs adopt the same approach; it's a very good idea. (Pie-in-the-sky thought: maybe one day we'll have the equivalent of the semi-automated KYC service providers that have phone apps to scan drivers' licenses, but for corporations. Then issuing EV certs will just mean an API call.)

Re: Defending Our Brand

#170

Comodo is not a trustworthy security company. Their browser extensions break browser security: https://news.ycombinator.com/item?id=11021633 https://news.ycombinator.com/item?id=9091917 They issued fraudulent SSL certificates in 2011: https://www.schneier.com/blog/archives/2011/03/comodo_group_...

If they're not trustworthy, let's remove them from the trusted CA lists of major FOSS browsers / distros. Anyone know the proper mailing list / bugtracker this should be filed on in the case of Firefox?
Post reply on HN