Live data from Hacker News

Switch to HTTPS Now, For Free

konklone.com

161–170 of 264 posts

Re: Switch to HTTPS Now, For Free

#161
post #132

You can also get free SSL certificates from LOLroot CA! http://lolroot.ca/

That's dumb. If you're going to install a new root certificate on all your client machines, you could just as well generate your own CA inside your organization and do the same thing without trusting some third party. (Edit: I think I've been trolled.)

Ya Think?

"Self-signed certs as a service! IN THE CLOUD! Need Support for your self-signed cert? 5k/year - 1 (800) 555 - 5549"

I wonder if they have an affiliate program

Re: Switch to HTTPS Now, For Free

#162
post #42

Earlier quoted context omitted.

I wouldn't exactly categorize "everyone can see your data" and "we can now track your movement on our own site" together. The idea of surveillance, in this case, is that no 3rd parties can snoop on your data. If you are actively using a site, it should be under the assumption that they can and will track anything you do on their site.

> no 3rd parties can snoop on your data And Google is what... ?

Someone you are willfully sending information about requests to? What's so hard to understand. Just because you let your doctor put his finger in your ass doesn't mean you want to let everyone...

Re: Switch to HTTPS Now, For Free

#163
And hey, bonus: more complete referrer information in Google Analytics for people visiting from sites already using HTTPS (like Hacker News)

If I enable SSL on my website do you think I will be able to get the referring keyword from Google? Now that Google is making all searches secure about 80% of the searches show up as 'Keyword Unavailable'. http://searchengineland.com/post-prism-google-secure-searche...

Re: Switch to HTTPS Now, For Free

#165

Earlier quoted context omitted.

Someone should probably also point out: most of the CAs are more or less equally 'crappy'. We've been through many CAs now and none of them has a process anywhere near 'perfect'. Btw, Comodo customer support is rather nice. We recently bought a code signing certificate from them and they walked us through the whole process via chat, worked quite well and we were done in about 30 min.

Do you not feel that, due to the security failure in 2011, they are one of the worst? I typically disable their certificate on my machines. The CA system is totally flawed anyway, I don't know why I bother.

Quitte the opposite. They themselves came forward about what happened, communicated clearly and took steps to mitigate the problem. From what I saw, they acted responsibly and it has only I erased my trust in them.

Re: Switch to HTTPS Now, For Free

#166
post #38

Earlier quoted context omitted.

I would be willing to bet over 95% of SSL-secured sites don't have business validation certificates. Given virtually nobody visiting your site will know what that means, let alone how to check anything about the certificate you're using, it just doesn't make sense to pay extra for no benefit. A domain-validated certificate costs less while providing the same padlock icon and level of encryption, and takes just minute…

In my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party. The only reason why I want to support https is so that customers can confirm who they are downloading from. Ideally, I'd like an EV certificate, but I can't afford that. So I chose a business validation cert. A domain only certificate wouldn't really confirm anything. (Al…

You're really just wasting your time with a "business validated" certificate. The browser doesn't treat it any differently and consumers like my parents would not know the difference or know what to look for. It's all (brilliant) marketing, nothing else. You're equally secure with a PositiveSSL cert from namecheap.com for $8 (or free with a domain registration)..

Re: Switch to HTTPS Now, For Free

#167
post #59

Make sure you do not use compression with SSL. Using compression with SSL could make your site vulnerable to the CRIME and BREACH attacks. See... SSL Gone in 30 Seconds - A BREACH Beyond CRIME [video]: http://www.youtube.com/watch?v=pIKIXQNFplY&hd=1 BREACH Attack (HTTP Compression): http://breachattack.com , http://security.stackexchange.com/questions/39925/breach-a-n... CRIME Attack (SSL/TLS/SPDY Compression): http:…

Don't use HTTP compression on private responses when using TLS. It's okay to HTTP compress publicly available images/scripts/stylesheets

Re: Switch to HTTPS Now, For Free

#168
post #66

Summary: obtain a certificate from StartSSL. They provide free certificates as long as it is for an individual, not a company's website. Their process to get a cert is a little more difficult that the competition, but konklone.com provides a nice step-by-step guide.

Nope, you can use it for a company as well.

If you read their terms, and I have, you definitely can't use the free certs for shopping or banking sites. It's kind of vague as to whether you can use it for a commercial site that doesn't involve shopping or banking though.

Re: Switch to HTTPS Now, For Free

#170

Earlier quoted context omitted.

Webfaction enabled SNI on all of their servers in December 2011 [1], which means you no longer need to buy a dedicated IP address to use SSL. In fact, when they made this switch, they switched my server over to SNI automatically and stopped charging me the extra $5/month automatically. Awesome! A small fraction of Internet users on extremely out-of-date system cannot use SNI. If you need to support those users, you w…

Almost 1 in 5 people on the web are still running Windows XP. No version of Internet Explorer on XP supports SNI. Neither does Safari on XP, the browser in Android 2.x, the BlackBerry browser or Opera Mobile before 10.1. It may be a minority of users, but it's not just "people who are still running IE6". Pretty much everyone would love to use SNI; site owners wouldn't have to pay for extra IPs, hosting companies woul…

But they're all in China, so if that isn't your market, then don't worry about it.
Post reply on HN