Live data from Hacker News

This seem legit...

trustico.ch

1–10 of 64 posts

Re: This seem legit...

#2
To clarify: DO NOT DO THIS.

1. Never give your private key to anyone

2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https)

3. Don't. Just don't.

This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security

Re: This seem legit...

#4
Woah, I couldn't ever envisage ever trusting a "security company" that not only encouraged you to disclose your private key, but also provided a form for doing it over a non encrypted connection!

My personal opinion is don't use these guys; this is either a school boy error/complete incompetence or totally dubious.

Re: This seem legit...

#7
post #2

To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security

I love how suddenly the NSA is the only entity out there who has an interest in private keys.

Re: This seem legit...

#8
I had these guys @reply me on Twitter when I tweeted about how it's easier to figure out what cipher suite to use compared to figuring out what SSL product I need.

They were helpful but thank god I didn't buy a cert from them: this page is a terrible, terrible idea that erodes their trust completely.

Re: This seem legit...

#9
post #7
post #2

To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security

I love how suddenly the NSA is the only entity out there who has an interest in private keys.

I think it is pretty hard to argue that they are not one of the most aggressive entities doing this.
Post reply on HN