Live data from Hacker News

GoDaddy SSL Cert Scam

rentzsch.tumblr.com

11–20 of 124 posts

Re: GoDaddy SSL Cert Scam

#11
I don't really see the problem here. GoDaddy products can be had very cheaply, they are so cheap with coupon codes the probably potentially make very little per sale.

All insurance companies work the same way, try hard to get a new customer, milk them dry on the tail end because they are too lazy to search out a better deal.

Re: GoDaddy SSL Cert Scam

#12
It's well known that domain/hosting companies often offer great discount for first year/payment, then charge for full price later. For example, Godaddy's $1.99 .info or Namecheap's free first year Privacy Guard or Gandi offers a free domain with their SSL cert.

Re: GoDaddy SSL Cert Scam

#13

Complain all you like but it seems at any given time I'm working for at least one organization that is running an expired SSL certificate on a server I need to use. More of these organizations should be using auto-renew.

Auto-renew won't automatically setup a renewed certificate on your server.

Re: GoDaddy SSL Cert Scam

#15
Timely...

At work we use RapidSSL (a division of GeoTrust) for a handful of certs. Last night I received an email with a banner warning me, "Your certificate is ABOUT TO EXPIRE". The email goes on to list the expiration date as "Oct 12, 2011". Four months is certainly generous notice, but I've always taken this as a simple marketing attempt to maintain customer loyalty.

Usually I take these emails as tickler reminders and delete the first couple. When I eventually decide it's time to renew, I pull up the site by typing the URL into the browser. Upon reading this article, I wondered whether following the link in the email would result in a different pricing structure. As it turns out, the answer is yes, though after playing around, it doesn't appear to have anything to do with the email link.

The first page of RapidSSL's order form handles both new orders and renewals with a pair of radio buttons. Another section of the form allows you to specify the validity period from one to five years. The prices appear alongside the choices, and are currently the same for both initial orders and renewals.

First I visited "www.rapidssl.com" and clicked the "buy/renew" link for a single domain cert. I got an order form with the following prices for 1-5 years:

49, 86, 122, 159, 196

Then I pasted the link from the email (which contains a fairly simple query string that does not appear to have a unique identifier in it) into a different browser. I clicked the "buy/renew" link for a single domain cert, I get the same form with the following prices:

79, 138, 198, 257, 316

It's interesting to me that the difference in price actually increases as the validity period increases:

30, 52, 76, 98, 120

Still more interesting, after resetting the browser and pulling up "www.rapidssl.com" directly, the prices are completely different:

29, 51, 72, 94, 116

I tried the email link one more time and got the 49-86-122 pricing again. Then I tried it one more time and got 19, 33, 48, 62, 76. So clearly RapidSSL is varying their prices on the fly, presumably to gain insight as to what people are willing to pay. I was ready to claim the link in the email yielded higher prices, but that seems not to be the case. So I guess after all that, this isn't particularly interesting. I'll definitely hit the site a few times when it comes time to purchase though.

Unfortunately the pricing structure for a wildcard certificate never seemed to vary.

Re: GoDaddy SSL Cert Scam

#16
post #15

Timely... At work we use RapidSSL (a division of GeoTrust) for a handful of certs. Last night I received an email with a banner warning me, "Your certificate is ABOUT TO EXPIRE". The email goes on to list the expiration date as "Oct 12, 2011". Four months is certainly generous notice, but I've always taken this as a simple marketing attempt to maintain customer loyalty. Usually I take these emails as tickler reminder…

Maybe they're just doing A/B(/C/D) testing to see which price is optimal.

Re: GoDaddy SSL Cert Scam

#17
I had the exact same thing happen to me. One of many reasons why I've not only stopped using GoDaddy for myself but also why I've decided to REFUSE to work with them for my clients. If my clients use GoDaddy, they can either get off GoDaddy or find another developer. Sometimes you have to force morality upon those without. :P

Re: GoDaddy SSL Cert Scam

#18

>I called GoDaddy Support this Sunday afternoon. While it was a long distance call, I only had to wait about a minute to reach a person in their Billing Department. They were happy to refund me the $49.99 after I deleted the cert and sent me the instructions to disable auto-renewals I linked to above. This times 1000 I experienced this exact same issue. I was pretty pissed to say the least but I called, got a human i…

> I see no problem here.

Really, you don't see a problem with their "better ask forgiveness than permission" tactic?

Re: GoDaddy SSL Cert Scam

#20

Complain all you like but it seems at any given time I'm working for at least one organization that is running an expired SSL certificate on a server I need to use. More of these organizations should be using auto-renew.

Auto-renew that charges you more than advertised, that you cannot opt out of without asking a human for assistance?
Post reply on HN