I just wonder why there's zero info about who's behind this.
Same nickname as the OP and tweets about tinycerts.
11–20 of 24 posts
I just wonder why there's zero info about who's behind this.
Same nickname as the OP and tweets about tinycerts.
> The generated keypairs are 1024-bit RSA public and private keys ... This is sufficiently strong for use on the web in the present day 1024-bit RSA certificates are considered deprecated, no longer issued, and if they don't already throw browser warnings then they will soon.
Indeed, this should be changed. The root is 2048 bits, but it's still unacceptable to issue 1024-bit certificates.
Not cool. Private keys generated on their servers and then the idea of inatalling the certs as trusted in your OS/browser is mentioned. Also 1024-bit keys. Is this some kind of test to see who falls for this?
It's nice that this service is trying to make it easier, but why should anyone trust tinycert? How can I trust that tinycert won't issue certificates without my concert? Or sell my private keys to others? The commands really aren't that complicated. You can (and really should) learn how to do this if you need to issue certificates. Also, deleting CA's doesn't seem to work.
As for why to trust it... you won't know to trust me any more than a real CA. With a real CA you also only have their word. I've taken as many steps as I can to ensure that the private keys are not kept unencrypted anywhere where this is not needed (and they are only needed when signing something and when you request a download) and that the passphrase is in flight as short as possible.
While anything is theoretically possible with enough malicious intent, I've made the selling private keys or issuing certificates with your private key without your consent as exceedingly difficult as possible for myself.
"Is it safe? ... Unless you install your own CA certificate in the browser or in the root certificate store of whatever other technology you use, they will complain about not being able to validate the certificates. This does not mean they are unsafe, just that they don't know to trust the certificates." Not being able to trust that you're talking to who you think to are seems like a serious example of "not safe". Te…
I can't control what people do with the certificates, but I'm recommending against the use of TinyCert certificates for the public web. When used as intended, only people who have themselves generated and installed the TinyCert certificates (or their associates if so instructed) will see them and click past. Anybody else should get the big scary warning and will hopefully, rightfully, heed it.
It's nice that this service is trying to make it easier, but why should anyone trust tinycert? How can I trust that tinycert won't issue certificates without my concert? Or sell my private keys to others? The commands really aren't that complicated. You can (and really should) learn how to do this if you need to issue certificates. Also, deleting CA's doesn't seem to work.
Thanks for the bug report. I'll look into that. As for why to trust it... you won't know to trust me any more than a real CA. With a real CA you also only have their word. I've taken as many steps as I can to ensure that the private keys are not kept unencrypted anywhere where this is not needed (and they are only needed when signing something and when you request a download) and that the passphrase is in flight as s…
This obviously should not be added to the list of trusted CAs in any browser, and these certs should not be used in the public web. Unfortunately, neither should many certificate authorities be trusted. https://www.youtube.com/watch?v=pDmj_xe7EIQ