Live data from Hacker News

Show HN: Snitch.io – SSL auditing and alerting

snitch.io

31–40 of 49 posts

Re: Show HN: Snitch.io – SSL auditing and alerting

#32

This is seems potentially quite useful. It would be nice if it could also notify you if your server is not configured according to best practices in terms of things such as protocol versions and cipher suites.

Thanks for the feedback!

That is definitely on the roadmap and will go out soon.

Re: Show HN: Snitch.io – SSL auditing and alerting

#33
post #21

Earlier quoted context omitted.

Thanks for your feedback but I strongly disagree and I think recent history supports that CAs don't do much for you once they've collected your payment. CAs won't alert you if someone breaks into your server and replaces your certificate. They won't alert if you if you accidentally push a config change and start serving the wrong certificate to customers... And they certainly will not alert you if you are using a rev…

"CAs won't alert you if someone breaks into your server and replaces your certificate. They won't alert if you if you accidentally push a config change and start serving the wrong certificate to customers... And they certainly will not alert you if you are using a revoked certificate in production." You have valid points, my advice would be to make that part of the message as clear as possible. as a sys admin I could…

Thank you for that feedback! It is very valuable to hear that I didn't message this effectively - I'll work on improving that.

I'd love to chat more out-of-band - would you mind emailing me (this username at currylabs.com or gmail.com)

Re: Show HN: Snitch.io – SSL auditing and alerting

#34
post #18

Earlier quoted context omitted.

I would think that bigger companies would use dedicated IT staff over a start-up for something crucial like SSL cert checking.

Given that Microsoft and Amazon have both had their SSL certs for their cloud businesses expire, a little extra reminding probably can't hurt. That said, I wouldn't pay for a service like this from a random person, I'd have my registrar do it (MarkMonitor or similar -- that's why they're paid the big bucks).

[Full disclosure - I've been beta testing snitch and been very happy with it].

In an old job for a mid-level bank, we had many behind the scenes (never showed up as a green padlock in any browser) integrations that would quit working when certs expired, frequently ones that we didn't purchase or control.

At the time, it was definitely worth it to me to get some notice before that happened. And it can be easier to plonk down a credit card than work though internal processes to have nagios (or patrol express, ) do the monitoring. It's the same thing that makes pingdom valuable.

Re: Show HN: Snitch.io – SSL auditing and alerting

#35
I think this is a brilliant idea, and seeing what you've built I'm sort of kicking myself for not having acted on the same idea. It's the sort of thing that is feasible for a company to do on their own but is difficult enough that it is very seldom done.

Re: Show HN: Snitch.io – SSL auditing and alerting

#36
post #35

I think this is a brilliant idea, and seeing what you've built I'm sort of kicking myself for not having acted on the same idea. It's the sort of thing that is feasible for a company to do on their own but is difficult enough that it is very seldom done.

Thank you for the kind words, msane.

Re: Show HN: Snitch.io – SSL auditing and alerting

#37
post #23

Great idea, will definitively check it out. Where are you incorporated, if? The terms says nothing about it. Who is my contract party when I signup?

Thanks for the feedback. We're in Oakland, California.

And who's behind it?

Re: Show HN: Snitch.io – SSL auditing and alerting

#38

I think you're trying to solve a non-problem since the company that sells the certificates warns you (sometimes even more than those intervals), afterall, they want you to renew as well. As for checking for quality, that should be the sys admin task or the webmaster. good luck though!

I let a RapidSSL cert lapse lately. They sent me 11 emails about it. They were really rather insistent:

    Early bird special: Renew your  to save
    Keep  Secure, renew your SSL
    Last chance to save: Your  is expiring
    ACTION REQUIRED: Your SSL needs attention
    FINAL NOTICE: Your SSL expires tomorrow
    LAST CHANCE: Your SSL expires today
    SECURITY ALERT: Your  may not be secure
    ACTION REQUIRED: Your SSL needs attention
    SSL EXPIRED: Renew to rescue
    CALL US: SSL for  is expired
    Your last SSL expiration notice for 
I was actually relieved when they finally stopped mailing me...

Re: Show HN: Snitch.io – SSL auditing and alerting

#39

I think you're trying to solve a non-problem since the company that sells the certificates warns you (sometimes even more than those intervals), afterall, they want you to renew as well. As for checking for quality, that should be the sys admin task or the webmaster. good luck though!

I let a RapidSSL cert lapse lately. They sent me 11 emails about it. They were really rather insistent: Early bird special: Renew your to save Keep Secure, renew your SSL Last chance to save: Your is expiring ACTION REQUIRED: Your SSL needs attention FINAL NOTICE: Your SSL expires tomorrow LAST CHANCE: Your SSL expires today SECURITY ALERT: Your may not be secure ACTION REQUIRED: Your SSL needs attention SSL EXPIRED:…

[deleted]
Post reply on HN