Well done Comodo, this motivated me to donate to Let's Encrypt. https://letsencrypt.org/donate/
Eh, I want to donate, but not via PayPal. If anyone relevant is reading this, consider adding more donation methods.
Defending Our Brand
221–230 of 275 posts
Re: Defending Our Brand
#222Earlier quoted context omitted.
If they're not trustworthy, let's remove them from the trusted CA lists of major FOSS browsers / distros. Anyone know the proper mailing list / bugtracker this should be filed on in the case of Firefox?
While a worthy cause, Firefox would be utterly broken if Comodo was no longer a trusted CA.
> While this site's certificate is technically valid, it was issued by an untrustworthy (citation) agency (link to Comodo).
Re: Defending Our Brand
#223Re: Defending Our Brand
#224Earlier quoted context omitted.
That's not always an option. For example, when I was looking into it for google app engine, I came across these directions: http://blog.seafuj.com/lets-encrypt-on-google-app-engine and http://igorartamonov.com/2015/12/lets-encrypt-ssl-google-app... That's not so bad if you have to do it once a year or better yet once every two years, but I'm not doing that every 3 months. There's an issue open to allow for the proces…
I know this doesn't help you, but the best fix for this would be for App Engine to implement letsencrypt support directly, so they can automatically provision and renew certificates for anyone that uses app engine
Re: Defending Our Brand
#225Earlier quoted context omitted.
CloudFlare uses them for Universal SSL, so that's roughly 5% of all websites[1]. Their overall market share (in the CA business) appears to be around 40%[2]. [1]: https://w3techs.com/technologies/details/cn-cloudflare/all/a... [2]: https://w3techs.com/technologies/overview/ssl_certificate/al...
Oh, CloudFlare uses them. That's quite a market share. It is sad that they have such a bad reputation... Hopefully someone buys them out who restructures them or something....
Re: Defending Our Brand
#226Earlier quoted context omitted.
Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.
> EV certs can't be automated No entirely, but mostly: seeing as this is my job, I should have some idea. Currently writing a post about how we've used some psych techniques to automate the non-automatable parts which I'll post on HN. > (and they're a dumb idea anyway) EV matches identity to public keys. Nothing more, nothing less. If you need EV, we ( https://certsimple.com ) specialise in making those background ch…
Re: Defending Our Brand
#227Earlier quoted context omitted.
While a worthy cause, Firefox would be utterly broken if Comodo was no longer a trusted CA.
Sounds like we need a new type of TLS warning: > While this site's certificate is technically valid, it was issued by an untrustworthy (citation) agency (link to Comodo).
This should be included as a warning for every website that has their cert: https://en.wikipedia.org/wiki/Comodo_Group#Controversies
Re: Defending Our Brand
#228Re: Defending Our Brand
#229Comodo's CEO has responded on their forums: https://forums.comodo.com/general-discussion-off-topic-anyth...
> One a separate note, since we are talking about protecting intellectual property, there is no law protecting business models. When Lets Encrypt copied Comodo's 90 day free ssl business model, we could not protect it. Lets encrypt could have chosen 57 days, 30 days or any other number for the lifetime of their certificates. But they chose to use Comodo's 90 day Free SSL model that we established in the market place for over 9 years!!! We invented the 90 day free ssl. Why are they copying our business model of 90 day free ssl is the question! Comodo has provided and built a Free SSL model that give SSL for free for 90 days since 2007! Trying to piggy back on our business model and copying our model of giving certificates for 90 days for free is not ethical. They clearly wanted to leverage the market of Free SSL users we had helped create and establish and that's why they created exactly same 90 day free ssl offering. So why did they choose 90 day? That is the question!
I'm not sure if he's delusional, or if he honestly thinks this is a "business model". Following that logic, all CAs are copying each other's business model when they offer one-year certificates. I don't have words for this.
Re: Defending Our Brand
#230Comodo's CEO has responded on their forums: https://forums.comodo.com/general-discussion-off-topic-anyth...
Isn't this why we have Trademark laws and courts? If they have right to it then more than happy to comply. But these kind of Intellectual copyrights can't be decided over a forum post or twitter account or trying to get your loyal but "blind" followers to bully another enterprise via their tweets. It won't work! This is not wild west and there are legal framework and courts for these kind of disputes. So lets all stop being the judge and jury and follow the law!
One a separate note, since we are talking about protecting intellectual property, there is no law protecting business models. When Lets Encrypt copied Comodo's 90 day free ssl business model, we could not protect it. Lets encrypt could have chosen 57 days, 30 days or any other number for the lifetime of their certificates. But they chose to use Comodo's 90 day Free SSL model that we established in the market place for over 9 years!!! We invented the 90 day free ssl. Why are they copying our business model of 90 day free ssl is the question! Comodo has provided and built a Free SSL model that give SSL for free for 90 days since 2007! Trying to piggy back on our business model and copying our model of giving certificates for 90 days for free is not ethical. They clearly wanted to leverage the market of Free SSL users we had helped create and establish and that's why they created exactly same 90 day free ssl offering. So why did they choose 90 day????? That is the question!
What they have is nothing new. We have been giving 90 day free certificates since 2007. Unlike them, our certificates are managed, even the free ones, so that consumers are protected. If a certificate is being used maliciously we revoke it. They don't! How is that making internet safer??? Actually consumer are less safe with their certificate because if it is used maliciously they don't revoke (Unmanaged)!
Lets get the facts right guys! We are the good guys that have been giving free SSL certificates since 2007 and managing them!"