Live data from Hacker News

Switch to HTTPS Now, For Free

konklone.com

191–200 of 264 posts

Re: Switch to HTTPS Now, For Free

#191

Earlier quoted context omitted.

> I've always heard and read otherwise. Those "Get better conversion rates with EV Certs" internal studies are pure marketing B.S. by the SSL vendors. Do not trust what they say. Every single person that has tested this on his site has come to the same exact conclusion - the green-bar has no meaning to the consumer, nor do they even notice it. http://www.theroiteam.com/blog/is-an-ev-ssl-worth-it-or-even... http://web…

The first link mentions EV certificate handshake is slower. Is that really the case? What is the reason?

Because the browser is going to check if the certificate is revoked as part of the ssl handshake. We have gotten sites being not available because the service that the browsers use to do this validation were not responding fast. The handshake took up to a minute.

Re: Switch to HTTPS Now, For Free

#192

Earlier quoted context omitted.

Do you not feel that, due to the security failure in 2011, they are one of the worst? I typically disable their certificate on my machines. The CA system is totally flawed anyway, I don't know why I bother.

Quitte the opposite. They themselves came forward about what happened, communicated clearly and took steps to mitigate the problem. From what I saw, they acted responsibly and it has only I erased my trust in them.

That's "increased", yeah?

Re: Switch to HTTPS Now, For Free

#193
post #38

Earlier quoted context omitted.

In my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party. The only reason why I want to support https is so that customers can confirm who they are downloading from. Ideally, I'd like an EV certificate, but I can't afford that. So I chose a business validation cert. A domain only certificate wouldn't really confirm anything. (Al…

Sorry, but you are still wasting your money on a business validation certificate. A domain validation certificate is the only thing that a browser actually validates and ensures the security between you and the website. The rest is just sprinkles on top to make people feel better and to charge website owners extra money.

>> so that customers can confirm who they are downloading from

This would seem that he was in fact looking to provide "some sprinkles [to] make his customers feel better."

Perhaps not a waste of money, then, if it provided what he was looking for?

Re: Switch to HTTPS Now, For Free

#194

Oh, the sweet irony - > SSL’s not perfect, but we need to make surveillance as expensive as possible immediately followed by - > And hey, bonus: more complete referrer information in Google Analytics Make up your mind already. Are you against the surveillance or for it? You can't really sit with one ass on two chairs. -- (edit) Point being is that if you are pulling the anti-surveillance card, then you shouldn't real…

/etc/hosts... # Screw Google... 127.0.0.1 www.google-analytics.com 127.0.0.1 ssl.google-analytics.com

Are you sure they only use one domain? Perhaps for analytics, but there is also adsense, doubleclick and who knows what else.

Re: Switch to HTTPS Now, For Free

#195
post #60

Earlier quoted context omitted.

Business validation is what you should be using for a business site. It's actually a good thing and means that the company is interested in verifying who you are. I went through the dance with Startcom and agree with the article that the web interface has horrible workflow. However they were clearly doing their best to verify that it actually was a business they were creating an account for. For example, they ignored…

Except not even 99.9995% of your customers will know or care about the level of your SSL Cert. It really does not add anything to the equation. Just extra costs and work for you. It's been studied and pointed out that a green-bar does nothing to conversions and sales. I suggest skipping it always, but often times a higher business type will override the suggestion of whomever has to implement it and maintain it - sim…

> It really does not add anything to the equation. Just extra costs and work for you.

Of course it adds something: It makes it more difficult for someone else to go buy a SSL certificate in your name. Security isn't just about driving sales, it's also about protecting yourself and your customers.

Re: Switch to HTTPS Now, For Free

#196
post #25
post #15

I just recently enabled SSL on my business website. It was anything but simple. First of all, I had to get a dedicated server, because a bunch of other sites were running on the same server, and the hosting company doesn't offer additional IP addresses. Then I wanted to get an SSL certificate. I picked Comodo, because they seemed to offer the cheapest full business validation certificate, but then accidentally bought…

Someone should probably point out: most of your problems were related to doing full business validation from a crappy provider. Business validation is optional and doesn't enhance the transport-layer security benefits of using SSL.

> Business validation is optional and doesn't enhance the transport-layer security benefits of using SSL.

Except that SSL isn't just about transport-layer security, it's also about identity. The entire model of SSL breaks down if anyone can buy a certificate for anything.

Re: Switch to HTTPS Now, For Free

#197

Earlier quoted context omitted.

Someone should probably also point out: most of the CAs are more or less equally 'crappy'. We've been through many CAs now and none of them has a process anywhere near 'perfect'. Btw, Comodo customer support is rather nice. We recently bought a code signing certificate from them and they walked us through the whole process via chat, worked quite well and we were done in about 30 min.

Do you not feel that, due to the security failure in 2011, they are one of the worst? I typically disable their certificate on my machines. The CA system is totally flawed anyway, I don't know why I bother.

> The CA system is totally flawed anyway

The flaw basically being that people aren't trustworthy, yes?

Do you have any alternatives? There's ssh's model, where you just hope it's the right certificate the first time; or maybe mob-source it like WoT?

Re: Switch to HTTPS Now, For Free

#198
post #38

Earlier quoted context omitted.

In my case, I don't care about encryption. On my website, I only offer software for download. No private data. Payment is handled by a third party. The only reason why I want to support https is so that customers can confirm who they are downloading from. Ideally, I'd like an EV certificate, but I can't afford that. So I chose a business validation cert. A domain only certificate wouldn't really confirm anything. (Al…

You're really just wasting your time with a "business validated" certificate. The browser doesn't treat it any differently and consumers like my parents would not know the difference or know what to look for. It's all (brilliant) marketing, nothing else. You're equally secure with a PositiveSSL cert from namecheap.com for $8 (or free with a domain registration)..

> You're really just wasting your time with a "business validated" certificate. The browser doesn't treat it any differently

If your vendor doesn't do a decent job verifying who you are (and this may or may not mean EV), then browsers won't treat the certificate any differently when it's entirely replaced by someone else either.

Re: Switch to HTTPS Now, For Free

#199
post #25

Earlier quoted context omitted.

Someone should probably point out: most of your problems were related to doing full business validation from a crappy provider. Business validation is optional and doesn't enhance the transport-layer security benefits of using SSL.

> Business validation is optional and doesn't enhance the transport-layer security benefits of using SSL. Except that SSL isn't just about transport-layer security, it's also about identity. The entire model of SSL breaks down if anyone can buy a certificate for anything.

Except the identity part is well and truly fucked and in serious need of redoing. It relies on trusted CAs, which has been shown is a bad idea, because some of the trusted CAs mismanaged their private keys or have been paid to or been coerced into giving out valid certificates to third parties, permitting them to impersonate websites.

Re: Switch to HTTPS Now, For Free

#200
post #105
post #102

Do people trust StartCom? Just curious ... I always wondered why you have all these very expensive cert providers who charge a lot for SSL certs, and then this mysterious company with ties to Israel is handing them out for free? I know it's pure paranoia, but this would seem to be an excellent way to compromise a lot of SSL traffic if you were into that, and the Israelis are pretty famous for all kinds of spying acti…

With StartCom, you just send them a CSR and they sign it. They don't get access to your key. StartCom passed an outside audit and is included in most modern browsers by default, indicating that they at least trust StartCom. They charge for the work they have to do. So, EV and identity validation cost money. Most "domain validated" certs are basically no work, as you can see from the incredibly cheap prices other SSL…

Actually, the default is for StartCom to generate your private key for you. They do let you generate your own private key and just upload the CSR though.
Post reply on HN