Live data from Hacker News

This seem legit...

trustico.ch

51–60 of 64 posts

Re: This seem legit...

#51

Earlier quoted context omitted.

I love the "Test another password?" prompt. I wonder how many people actually use it.

c. You agree to pay $ 100,000 for your use of the Estatis Free Password Security Checker if we ever ask for it.

I was assuming you were joking. but no, it's in there, point 6.c)

... Wat?

EDIT: I am a dumbass, the terms and conditions are clearly facetious. Read them, they are hilarious in parts.

Re: This seem legit...

#52
post #22

Related: http://www.inutile.ens.fr/estatis/password-security-checker/

I love the "Test another password?" prompt. I wonder how many people actually use it.

If you repeatedly test another password, the prompt changes. Quite hilarious.

Also, the terms and conditions are fake too.

"If you read all the legalese up to this point (or just got there by random scrolling), you probably have noticed that this document is complete nonsense. [...] First, chapter 10 of Mary Shelley's /Frankenstein/. Second, a copy of some treaty."

Re: This seem legit...

#53
post #7

Earlier quoted context omitted.

I love how suddenly the NSA is the only entity out there who has an interest in private keys.

at least we know that's it is the most interested, funded and staffed to do it.

No, they're just the only ones dumb enough to get caught ;)

Re: This seem legit...

#54

Hi, The tool was made available for customers to legitimately check if the Private Key matched the SSL Certificate that was being installed - a common question and feature request from our customers. However, upon review of the comments made in the internet community we have made a decision to remove this specific tool and to review all other tools that we make publicly available via our websites. We also saw a heavy…

Look, I have absolutely no background in security, but I could tell immediately that this was an absolutely horrible idea.

What were you thinking? That's not a loaded question. I literally have no idea what was going through the mind of anyone at your company when it was decided to build this abomination.

Re: This seem legit...

#55
"The page you have tried to access is not responding properly and we can't display it at the moment." - looks like they are embarrassed enough to take it down. Anyone have the original text for me to snigger at? Way-back machine and Google don't seem to have it cached.

Re: This seem legit...

#56

BITCOIN ADDRESS MATCHER Want to make sure that your bitcoin address works? Just send money to 1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau and if you don't receive an error, you can rest assured that your bitcoin address works!

https://blockchain.info/address/1JqjU7zBvbhyrDFjtJG6xAwMm5BU... Watching with interest... xD

Empty as expected :) Edit: Nevermind, somebody send a cent. Your address works! ;)

Re: This seem legit...

#57
post #37

BITCOIN ADDRESS MATCHER Want to make sure that your bitcoin address works? Just send money to 1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau and if you don't receive an error, you can rest assured that your bitcoin address works!

I'd rather use this 1PtQmxewNJWYeDUieM2cLqU9XcAoBEfWaQ You send the money there, it sends you back the double amount.

Doesn't work for me. Maybe I need to send a bigger amount for it to trigger?

Re: This seem legit...

#58

Hi, The tool was made available for customers to legitimately check if the Private Key matched the SSL Certificate that was being installed - a common question and feature request from our customers. However, upon review of the comments made in the internet community we have made a decision to remove this specific tool and to review all other tools that we make publicly available via our websites. We also saw a heavy…

Thank you for your prompt response.

Re: This seem legit...

#60
post #19
post #14

I just tested the form with a key+cert pair I created for this sole purpose. It actually performs as advertised - it checks if key and cert belong together.

You have not provided any proof that it actually performs as advertised. Maybe it just says that for any and all inputs??

To clarify the issue: I performed the following steps:

1. created a CA key+cert (selfsigned) 2. created a keypair K 3. signed the public key of K with the CA 4. uploaded the CA-signed cert and the private key of K --> "Your Certificate and Key match" 5. uploaded the CA cert (not the one of K) and the private key of K --> "Certificate an Key do NOT match."

Post reply on HN