Live data from Hacker News

Defending Our Brand

letsencrypt.org

181–190 of 275 posts

Re: Defending Our Brand

#181
Sad. This reminds me of high school where I was constantly being bullied by the big guys.

- Oh, I like that what you have. You know what? I WANT it. And I'm going to take it just because I'm bigger than you.

They can go to hell. I'm not renewing my certs with those twats. Bullying is not fine just because is a company instead of a person doing it.

Let's encrypt, the community is with you. I just donated to your cause.

Re: Defending Our Brand

#183
post #102
post #33

Earlier quoted context omitted.

Why are you looking for another provider? Just use Lets Encrypt ;-)

Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.

...oh but they do. If you're in education and are an InCommon member, you get unlimited EV certs. It's pretty nice as you can add read certs to literally every server in your system and not have to abuse a *. cert. Hell you can even add real certs to every AD machine; no more creating your own CA and installing it via a group policy.

That was back in 2012 when I worked for a University. Good luck getting those certs though. Their web service was so broken and if you ever asked for a 2nd cert it'd revoke the first one (which is great if you use them for e-mail encryption because now you can't read any of your old e-mails :-P .. that was more of an Outlook/GAL issue though).

I really hate that InCommon was using Comodo considering all the shit they've done (like issue Google and Facebook certs to the Iranian government).

Re: Defending Our Brand

#184

The points made by ISRG seem well-taken and, if there is a formal fight over this, it should prevail given the facts as it recites them. There is a general lesson here for startups as well. If you have an important mark, do consider doing an intent-to-use (ITU) application earlier rather than later to prevent poaching of the mark by others. If you haven't actually used the mark in commerce (e.g., if you are in pure d…

There's a second lesson for start-ups - if you can't buy or develop goodwill with your customers, just steal it from someone else.

My experience(s) with Comodo have been well short of awe-inspiring and their reputation certainly isn't great - to me, this is just another mark against them.

Re: Defending Our Brand

#186

CloudFlare uses Comodo certificates–millions of them, I imagine–and that probably makes them a commercially significant Comodo customer. As a CloudFlare customer with a Comodo-issued certificate, I hope they’ll try to convince Comodo of the value of doing the right thing.

Comodo is just cross-signing CF certs[1] because the CF Origin CA is not yet in browser trust stores. GlobalSign and Digicert also cross-sign CF certs.

[1] https://blog.cloudflare.com/universal-ssl-encryption-all-the...

Re: Defending Our Brand

#187

Earlier quoted context omitted.

Please refrain from unnecessary humor-policing. It's not helpful and only detracts from the sense of community.

It's not humor-policing to point out that HN has a different culture and comments serve a different purpose here. I like pun threads - but I go to /r/jokes when I want them. Here, I expect a certain sort of signal - insight from experienced and intelligent people working hard on interesting technical problems. This isn't to say that humor should be verboten, or pun threads strictly banned - but they're definitely not…

> Here, I expect a certain sort of signal - insight from experienced and intelligent people working hard on interesting technical problems.

In a comment thread about somebody donating? You must be disappointed often.

Re: Defending Our Brand

#188

Earlier quoted context omitted.

It's not humor-policing to point out that HN has a different culture and comments serve a different purpose here. I like pun threads - but I go to /r/jokes when I want them. Here, I expect a certain sort of signal - insight from experienced and intelligent people working hard on interesting technical problems. This isn't to say that humor should be verboten, or pun threads strictly banned - but they're definitely not…

It's one thing to have rules, but don't confuse rule following with culture. Culture is emergent, and not something that is policed into place.

HN has a culture of pointing out that obvious, boring jokes have no place here. There's a constant struggle by people to introduce them, but (amongst others) those of us who watched Slashdot flush itself down the toilet of shitty humor are going to police the site because it's what we want.

Re: Defending Our Brand

#189
post #186

CloudFlare uses Comodo certificates–millions of them, I imagine–and that probably makes them a commercially significant Comodo customer. As a CloudFlare customer with a Comodo-issued certificate, I hope they’ll try to convince Comodo of the value of doing the right thing.

Comodo is just cross-signing CF certs[1] because the CF Origin CA is not yet in browser trust stores. GlobalSign and Digicert also cross-sign CF certs. [1] https://blog.cloudflare.com/universal-ssl-encryption-all-the...

CloudFlare's Origin CA was created exclusively for communication between CloudFlare and backend servers. I haven't seen any kind of announcement mentioning that CloudFlare has plans to operate a public CA and apply to root programs.

Re: Defending Our Brand

#190
post #150

Earlier quoted context omitted.

You might argue "due diligence", that as Lets Encrypt appear on a simply internet search the lawyer's claimed ignorance [if they do claim ignorance] shows a wilful act to hide from knowing that it was already an established trademark. There is no way - on balance of probabilities - that any company enlists a trademark lawyer to register a mark without that lawyer first doing an internet search (eg for associations wi…

I've received legal advice to take care not to discover patents. Because if we knew of the existence of a patent then it could be shown that we were knowingly infringing on the patent. I wonder if trademark law has similar incentives to behave irrationally.

" Because if we knew of the existence of a patent then it could be shown that we were knowingly infringing on the patent."

This legal advice was been valid at one point. However, nowadays, willful infringement requires more than just knowledge.

It has for a few years, but the most recent supreme court decision also strongly supports this.

See Halo Electronics v. Pulse electronics (http://www.supremecourt.gov/opinions/15pdf/14-1513_db8e.pdf) in the concurrence:

  First, the Court’s references to “willful misconduct” do
  not mean that a court may award enhanced damages
  simply because the evidence shows that the infringer
  knew about the patent and nothing more.
Second, also note:

  “failure of an infringer to obtain the
  advice of counsel . . . may not be used to prove that the
  accused infringer wilfully infringed.”
Post reply on HN