This seem legit...
21–30 of 64 posts
Re: This seem legit...
#22Re: This seem legit...
#23Re: This seem legit...
#24To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
I love how suddenly the NSA is the only entity out there who has an interest in private keys.
Re: This seem legit...
#25haha, Its hilarious, reminded me of this http://d24w6bsrhbeh9d.cloudfront.net/photo/350850_700b_v1.jp...
Re: This seem legit...
#26Re: This seem legit...
#27Related: http://www.inutile.ens.fr/estatis/password-security-checker/
Re: This seem legit...
#28Re: This seem legit...
#29I contacted their support: Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private? Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost. Me: But it would be sent over HTTP and viewable to anyone along the network. Emanuele: The page can also be accessed through HTTPS. Me: I think it should be enforced. Al…
I don't think you've thought this through.
Re: This seem legit...
#30To clarify: DO NOT DO THIS. 1. Never give your private key to anyone 2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https) 3. Don't. Just don't. This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
Nobody else got the subtle sarcasm, but I did. No worries, man. But seriously, if it was the NSA, I like how quick everyone is to dismiss the notion!
(Rest assured, it's the latter, not the former.)