Live data from Hacker News

Defending Our Brand

letsencrypt.org

261–270 of 275 posts

Re: Defending Our Brand

#261
post #12

Well done Comodo, this motivated me to donate to Let's Encrypt. https://letsencrypt.org/donate/

The anger, the convenience of your link, and the fact I had some cash sitting with Paypal made it easy for me to donate to holding as well. I think there's a lesson in there.

Let's Encrypt is a noble good-for-everyone effort so it depressing that there those out there that will do it harm.

Re: Defending Our Brand

#262
post #244

Earlier quoted context omitted.

I can't find pricing on your website. There's a page called 'pricing' that says I can find pricing on the home page. When I click the link, I find a lot of marketing text, but no pricing.

It's right underneath the 'Domain names' box, in to USD / GBP / EUR based on country (which is in turn based on your IP location).

Ok, now I discovered it. Had to put my phone in landscape mode (in portrait mode the website is totally different)

Pricing starts at 220€ per year, in case anyone is interested.

Re: Defending Our Brand

#263
post #227

Earlier quoted context omitted.

Sounds like we need a new type of TLS warning: > While this site's certificate is technically valid, it was issued by an untrustworthy (citation) agency (link to Comodo).

Awesome idea, couple years ago I dropped the few certs I had with Comodo after all their malpractices. This should be included as a warning for every website that has their cert: https://en.wikipedia.org/wiki/Comodo_Group#Controversies

Followup idea: a trusted neutral 3rd party that ranks CAs by various factors, such as controversiality. Quotes Wikipedia and other (arguably) objective sources [of fact] and welcomes debate about potential bias.

Perhaps this group could publish reports periodically so that they can then be picked up and bundled into browsers - that way you're not constantly sending [trackable] cert requests to a 3rd party, and you already have the cert info so there's no query server to DDoS.

Maybe Firefox could incorporate it into the TLS info popup and possibly the HTTPS icon... Chrome never would; this idea goes way too close to the advertising industry.

An extension would be nice, but something like this would never go viral so would never get adoption. Native browser integration would be a must.

Also, mozilla.org's cert is by DigiCert. What's their track record?

Re: Defending Our Brand

#264
post #172

Comodo is not a trustworthy security company. Their browser extensions break browser security: https://news.ycombinator.com/item?id=11021633 https://news.ycombinator.com/item?id=9091917 They issued fraudulent SSL certificates in 2011: https://www.schneier.com/blog/archives/2011/03/comodo_group_...

> They issued fraudulent SSL certificates in 2011: https://www.schneier.com/blog/archives/2011/03/comodo_group_... Moxie had an amusing anecdote about this incident in his Blackhat 2011 talk "SSL and the future of authenticity"[0]. Apparently the same IP as was used by the "sophisticated attacker" and disclosed by Comodo downloaded sslsniff[1] from moxies server the next day, referred by a video tutorial about interc…

Thanks, this video really made my day! :) I guess I won't be buying certificates from Comodo anytime soon.

Re: Defending Our Brand

#265
post #257

I'm cancelling an order for a code-signing certificate with Comodo. This is disgusting behaviour on their part. Can someone recommend a good provider for code signing certs?

DigiCert. After a year with Symantec (can't recommend) it was a joy to get one from DigiCert. Good site, good tools, reasonable prices, 3 yr option, painless validation process (I'm in a small EU country, which tends to complicate things on occasion). Can't recommend enough.

Thank you. I was already looking at digicert, this cements my choice :)

Re: Defending Our Brand

#266
This behaviour really piss me off.

Someone having a proper email to comodo so it is possible complain directly to them? (1)

I really hope alot of people will complain directly to them so they see this is not ok in no ways and they doing the right thing.

(1) “contact us" on there homepage is just emty for me on my mobile for some reason. Therefore the question.

Re: Defending Our Brand

#267
post #121
post #102

Earlier quoted context omitted.

Let's Encrypt doesn't offer EV certs. Which is reasonable; EV certs can't be automated (and they're a dumb idea anyway), but they're still necessary for some of my sites.

> EV certs can't be automated No entirely, but mostly: seeing as this is my job, I should have some idea. Currently writing a post about how we've used some psych techniques to automate the non-automatable parts which I'll post on HN. > (and they're a dumb idea anyway) EV matches identity to public keys. Nothing more, nothing less. If you need EV, we ( https://certsimple.com ) specialise in making those background ch…

Quick plug for a company I've used: SSLmate (http://sslmate.com) makes cert purchase (for those whom need this) painless and fast. They use Comodo and Geotrust FWIW. I've had my own pain with Comodo through other resellers, and moved on to sslmate and godaddy. Recently moved my home blog (http://scalability.org) to LE. Work (http://scalableinformatics.com) is using godaddy for now, though thinking hard on using sslmate going forward for it (because ... godaddy).

Re: Defending Our Brand

#269

The points made by ISRG seem well-taken and, if there is a formal fight over this, it should prevail given the facts as it recites them. There is a general lesson here for startups as well. If you have an important mark, do consider doing an intent-to-use (ITU) application earlier rather than later to prevent poaching of the mark by others. If you haven't actually used the mark in commerce (e.g., if you are in pure d…

> believed no one could in good faith possibly challenge

They were correct to believe that no one could in good faith do what Comodo are doing.

There is no way that Comodo are acting in good faith and any claim otherwise is either an outright lie or (if anyone claiming good faith genuinely believes that to be true) complete stupidity. Or both.

Never rely on good faith from your competitors.

Re: Defending Our Brand

#270
post #231

The CEO of Comodo has apparently replied on a Comodo forum, and boy, it's a doozy. https://forums.comodo.com/general-discussion-off-topic-anyth... > Isn't this why we have Trademark laws and courts? If they have right to it then more than happy to comply. But these kind of Intellectual copyrights can't be decided over a forum post or twitter account or trying to get your loyal but "blind" followers to bully another e…

He's conveniently leaving out that once your 90-day Comodo cert expires, you can't ever get another one for that domain. It's essentially a free trial for their paid certs. Let's Encrypt certs can be (and are intended to be) renewed indefinitely.
Post reply on HN