This seem legit...
11–20 of 64 posts
Re: This seem legit...
#12To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
This just seems like some newbie programmer was like "hey, wouldn't it be cool if"... and built themselves a weekend project that they released on the site.
Obviously it's terrible for a site that sells SSL stuff, but concluding that this is the NSA is pretty hugely premature.
edit: Duh, didn't pick up on the sarcasm. In my defense, the parent text was way more vague at the time. :)
Re: This seem legit...
#13Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private?
Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost.
Me: But it would be sent over HTTP and viewable to anyone along the network.
Emanuele: The page can also be accessed through HTTPS.
Me: I think it should be enforced. Also something like this should be done client side. Perhaps using crypto.js
Emanuele: OK, I will pass your comment to our General manager.
Re: This seem legit...
#14Re: This seem legit...
#15To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
Re: This seem legit...
#16Want to make sure that your bitcoin address works? Just send money to
1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau
and if you don't receive an error, you can rest assured that your bitcoin address works!
Re: This seem legit...
#17To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
Never attribute to malice that which is adequately explained by stupidity. This just seems like some newbie programmer was like "hey, wouldn't it be cool if"... and built themselves a weekend project that they released on the site. Obviously it's terrible for a site that sells SSL stuff, but concluding that this is the NSA is pretty hugely premature. edit: Duh, didn't pick up on the sarcasm. In my defense, the parent…
Re: This seem legit...
#18Evon Latrail is the author of a children's book "When Mommy Went to Heaven". She wrote/recorded a few songs; "Lord Bless My Enemies. And, even has a song entitled, "Can't You See (Abortion Is Murder). She went Pro-life after having a abortion! Really???? Now here is a photo of her posing in chocolate as a "Swamp Girl". The word Hypocrite is floating around somewhere. This story has made front page news in the local paper. Go to Google or YouTube and search, Evon Latrail.
Re: This seem legit...
#19I just tested the form with a key+cert pair I created for this sole purpose. It actually performs as advertised - it checks if key and cert belong together.
Maybe it just says that for any and all inputs??