Well done Comodo, this motivated me to donate to Let's Encrypt. https://letsencrypt.org/donate/
Defending Our Brand
171–180 of 275 posts
Re: Defending Our Brand
#172Comodo is not a trustworthy security company. Their browser extensions break browser security: https://news.ycombinator.com/item?id=11021633 https://news.ycombinator.com/item?id=9091917 They issued fraudulent SSL certificates in 2011: https://www.schneier.com/blog/archives/2011/03/comodo_group_...
Moxie had an amusing anecdote about this incident in his Blackhat 2011 talk "SSL and the future of authenticity"[0]. Apparently the same IP as was used by the "sophisticated attacker" and disclosed by Comodo downloaded sslsniff[1] from moxies server the next day, referred by a video tutorial about intercepting SSL..
Re: Defending Our Brand
#173Earlier quoted context omitted.
Please refrain from unnecessary humor-policing. It's not helpful and only detracts from the sense of community.
It's not humor-policing to point out that HN has a different culture and comments serve a different purpose here. I like pun threads - but I go to /r/jokes when I want them. Here, I expect a certain sort of signal - insight from experienced and intelligent people working hard on interesting technical problems. This isn't to say that humor should be verboten, or pun threads strictly banned - but they're definitely not…
Re: Defending Our Brand
#174Earlier quoted context omitted.
I'm also puzzled that Let's Encrypt's Trademark policy [1] strongly suggests that 'Let's Encrypt' is a trademark (word mark?) that they have registered, and yet according to the most recent letter sent by the USPTO [2] "The Office records have been searched and there are no similar registered or pending marks that would bar registration [...]" [1] https://letsencrypt.org/trademarks/ [2] http://tsdr.uspto.gov/document…
You don't have to register trademarks, even though it's a good idea to do so, if only for the sake of clarity. Trademarks can be established through market use (common law usage), which is what Let's Encrypt's claim is based on. Let's Encrypt will likely defend their claim, if it comes to it, through the tort of passing off: https://en.wikipedia.org/wiki/Passing_off Edit: I can English good.
Here's a reasonable article on it: http://www.fr.com/news/prior-user-vs-federal-registrant-whos...
Re: Defending Our Brand
#175The bullshit the CAs pull never ceases to amaze me.
Comodo in particular has a long history of shady bullshit. Tarring all CAs with that brush strikes me as unduly harsh.
While I'm sure there are CAs who aren't as egregiously bad as Comodo, it's hard to get around the fact that they basically shouldn't exist as a class, and any CA that isn't working to put itself out of business is sort of hurting the Internet ecosystem.
Re: Defending Our Brand
#176Out of curiosity: Why didn't Letsencrypt applied for a trademark right at the start? That this happens was quite foreseeable and occurs quite often if people forget to secure trademarks (I know this won't be a popular opinion because most as I like Letsencrypt and their outstanding service)
Re: Defending Our Brand
#177Re: Defending Our Brand
#178Comodo is not a trustworthy security company. Their browser extensions break browser security: https://news.ycombinator.com/item?id=11021633 https://news.ycombinator.com/item?id=9091917 They issued fraudulent SSL certificates in 2011: https://www.schneier.com/blog/archives/2011/03/comodo_group_...
If they're not trustworthy, let's remove them from the trusted CA lists of major FOSS browsers / distros. Anyone know the proper mailing list / bugtracker this should be filed on in the case of Firefox?
Re: Defending Our Brand
#179There is a general lesson here for startups as well.
If you have an important mark, do consider doing an intent-to-use (ITU) application earlier rather than later to prevent poaching of the mark by others.
If you haven't actually used the mark in commerce (e.g., if you are in pure development phase), anybody can go out and file an ITU application for your mark and thereby effectively poach it - even if the person doing it is just trying to extort you (of course, they won't say this is their motive). During this phase, you are vulnerable to such poaching risks. For the vast majority of startups, it probably doesn't matter because no one cares about the typical mark or marks they plan to use when there is nothing yet noteworthy about them. But it can and does happen. Autocad got poached in this fashion when it first started. I had a client that had the domain name gmail.net, planning to use if for "graphics mail" back in the day and they could have blocked Google had they filed a "Gmail" ITU application (they didn't). Particularly if your mark is distinctive and fanciful, and tied to a credible venture, you should not be lax on this issue. At least give it some careful thought even if your decision is to take the poaching risk to avoid what you see as unnecessary up-front costs on legal items. Remember: an ITU application gives priority over someone who has not yet used a mark and it gives it to anyone and his uncle who happens to file it even if they have done nothing yet in your field.
Once you begin to use a mark in interstate commerce, then you get common law protections by which the person who is first to use a mark in a given geographical area automatically gets priority to the mark with that area. This happened with an outfit called Amazon Books in the Minneapolis area at the time Amazon.com launched and they eventually got a settlement payout from Amazon for infringement of their common law trademark rights in that area by the bigger organization. Thus, if you are indeed using a mark in this way, and someone comes along and tries to register a mark (whether ITU or otherwise), you keep your priority over the late arrival and can sometimes even block them from getting the registration (or have it set aside through a formal legal fight). But this is a path with many potential pitfalls. Unless your actual use was open, prominent, and notorious, you may have proof issues to establish it or to establish its extent. Even if you can prove first use and broad extent, you still may have to fight the latecomer and incur large legal expenses in the process. Moreover, if you have not registered your mark, you do not get a "presumption of validity" for it and this leaves it more vulnerable to a legal argument that the mark is not protectible at all (meaning that many people can use it without infringing on others' rights). Or it can be argued that it is at most entitled to weak protection so that a use by another is a slightly unrelated field will not cause customer confusion and hence not infringe even if the mark is protectible. And so on and so on. The situation is just not clean in this scenario or at least can more readily be gummed up by a determined adversary who has "lawyered up."
As someone who has worked for years with early-stage startups, I would be the last to say "go out right away and spend away on legal things" to cover a bunch of theoretical risks. This poaching risk, for most startups, remains primarily theoretical and should not cause you to have to run out and spend a bunch of money on trademark filings before you know if you even have a viable venture. But, for the right cases (good mark, credible venture), it usually pays to be attentive to this issue up front and eliminate the risk through some proactive action.
ISRG is non-profit and its use of this mark was open and widespread. So I can see why they did not go out and incur trademark filing costs to protect a mark that I assume they believed no one could in good faith possibly challenge. This was probably the right judgment to make for their situation. Yet, in hindsight, we can see that the failure to do their own filing has left them vulnerable - not to poaching (as I said, they likely will win) but to having to go through an otherwise unnecessary legal fight to defend what is legitimately theirs.
It is unfortunate and I hope people will give support as needed. In all too many cases, underfunded people or organizations who are in the right do wind up getting overwhelmed by people who simply have more resources and who are determined to make life difficult. Even with a likely winning legal position, someone in this position can wind up having to do some compromise (such as a trademark co-existence agreement) giving the other party significant rights just to resolve the fight. Better to avoid that pressure here if it means enough to the relevant community.
Re: Defending Our Brand
#180Earlier quoted context omitted.
Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.
(Not to sound like an advertisement, but) I got an email from StartCom the other day, saying that they're moving their StartSSL service to work on a similar policy to Let's Encrypt (which I hope means they're just running an ACME server)—but with the proviso that, since they do have the background-checking infrastructure required for EV "trust verification", they've combined the two. If I recall, StartSSL sort of hoi…
StartEncrypt, the equivalent of an ACME client for their API, appears to be a closed-source binary blob with no documentation whatsoever (based on what's visible on their product landing page and what's inside the downloaded files).