Live data from Hacker News

Ask HN: What's the best company to buy an SSL certificate from?

news.ycombinator.com

31–40 of 89 posts

Re: Ask HN: What's the best company to buy an SSL certificate from?

#31

1. DigiCert. They're not the cheapest, but they really have their stuff together. Their support is awesome (speedy, technically competent, and human). They're also proactive about identifying issues with your certs, they handled the heartbleed incident perfectly - reissued for free with no issues. 2. No

DigiCert also has a nice "enterprise" offering where you can confirm your domain with them once then have role accounts that can approve and issue certificates without them needing to re-do verification. Others within your company can then make their own sub-accounts and request certificates.

I've dealt with their support people a few times as well, and agree that they are fantastic.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#32
post #21

1. DigiCert. They're not the cheapest, but they really have their stuff together. Their support is awesome (speedy, technically competent, and human). They're also proactive about identifying issues with your certs, they handled the heartbleed incident perfectly - reissued for free with no issues. 2. No

Wow, one needs a super premium $595 "Wildcard Plus™" plan to secure an entire domain. Is this normal or a blatant ripoff?

It's a rip-off but plenty of people think it is normal so I'm not sure what to answer your question with.

I think the whole certificate business is a rip-off, the only thing that 'green bar/lock icon/whatever' says is that someone at some point in time was able to pay some low dollar amount, but not who, what amount and if they're trustworthy in any way.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#33

https://www.startssl.com 2 Years wildcard for $59.90

StartSSL's UI is awful.

If you need a cheap wildcard cert you can get a two year wildcard AlphaSSL cert from garrisonhost for $79 without the pain of dealing with StartSSL.

http://www.garrisonhost.com/ssl-certificates/alphassl.html

Re: Ask HN: What's the best company to buy an SSL certificate from?

#36
post #9

https://www.startssl.com 2 Years wildcard for $59.90

They charge for reissuing certs though. https://news.ycombinator.com/item?id=7557764

StartSSL also requires you to send a copy of your passport out of country (to Israel). Fine; they need to verify identity.

They retain the records for seven years though. Why preserve the documents at all after validation is complete for non-EV certs? Seems like it creates an unreasonable liability given that data breaches happen. They will also not say how the records are secured. When I inquired, they simply said "We obviously can't provide any technical details about our security measures, but the documents are secure." While I can understand the need to maintain operational security, disclosing whether documents are stored encrypted or not should not violate this security.

The lack of openness, combined with the charge for cert re-issuance made me look elsewhere. When the heartbleed vulnerability hit and I had to regenerate certs, I was very happy to have chosen a different CA.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#39

My startup is actually centered around this. If anyone wants to purchase a certificate through me, I'll happily give you the lowest rates I can. ($25 EV or $40 wildcard) Our homepage is https://certly.io , shoot me an email at ian@certly.io

I am an early adopter, but the blank home page and blank blog are a little too early for my tastes.

Re: Ask HN: What's the best company to buy an SSL certificate from?

#40
Don't EV certs create a net increase in security risk (if any web users understood what they were supposed to mean)? I'm not expert in these issues, but I've always doubted their security value:

EV certs are supposed to communicate certainty[1] to typical web users about identity, confidentiality, and integrity. But, if I understand correctly, obtaining EV certs in someone else's name (or something close enough to fool web users) is possible without great cost, and so that message of high security is misleading. If EV certs were believed by end users, wouldn't we merely be creating a social engineering security hole? Competent thieves also would use EV certs and increase trust in their websites too.

Thankfully, I've never met an end user without technical knowledge who understood what an EV cert was. I do know what they are and I don't trust them more than regular certs (which is not much for identity, but I do as protection against low-cost confidentiality and integrity attacks).

[1] Re: "certainty": I know EV certs are supposed to be more secure and not perfectly secure, and that there is no perfect or 'certain' security. However, few end users understand the latter, and of the ones that do few would take the time to learn the degree of increased security EV provides. We shouldn't say, 'trust the green bar' unless we expect people to do it.

Post reply on HN