Our First Certificate Is Now Live
191–200 of 263 posts
Re: Our First Certificate Is Now Live
#192Does anybody know if there is any protection built in against MITM or DNS poisoning attacks? It feels like this makes network hop security far more important. If I'm able to insert a MITM or DNS poisoning anywhere between where letsencrypt.org's servers are and where it thinks the requesting server should be then I can generate a false certificate. For example, Amazon's DNS resolves for letsencrypt as 1.2.3.4 which r…
According to their 31C3 talk, they will use multiple connections from multiple locations (possibly including Tor?) to mitigate against these attacks.
Re: Our First Certificate Is Now Live
#193Re: Our First Certificate Is Now Live
#194Re: Our First Certificate Is Now Live
#195Quick question, apart from having a prettier website, what's the differentiator with StartSSL which is also free, automated, and open?
* validation taking up to six weeks, with recurring ridiculous demands for documentation, such as energy provider bills etc
* very unpleasant interface
* nightmarish authentication scheme with client-side certs. Try signing on with Chrome on one box, then exporting the cert to Firefox on another for example
* the client-side cert expires. When it does, there is no way to get back into your account. Support says 'just make a new one'
* there doesn't seem to be a mechanism for designating a technical contact, and I've been admonished by them several times for having the gall of taking over the process for my customers
Re: Our First Certificate Is Now Live
#196Earlier quoted context omitted.
Maybe so, but you know every regular guy driving a regular car would rather have a Ferrari and might even spend time looking at them even though he can't buy one.
You're wrong. EV is a scam. I can afford to buy EV for most of my sites, but I don't do it. Because consumers don't really care. Even HN doesn't have an EV! Ferrari is what everybody wants, EV is a different story! And stop downvoting all my comments - it shows your subpar human material. Downvote my main point and stop right there. No need to go aggressive and try to silence me and not comment further, because you w…
Re: Our First Certificate Is Now Live
#197Earlier quoted context omitted.
You're wrong. EV is a scam. I can afford to buy EV for most of my sites, but I don't do it. Because consumers don't really care. Even HN doesn't have an EV! Ferrari is what everybody wants, EV is a different story! And stop downvoting all my comments - it shows your subpar human material. Downvote my main point and stop right there. No need to go aggressive and try to silence me and not comment further, because you w…
As per the guidelines, please keep discussions civil on HN and please don't complain about being downvoted. https://news.ycombinator.com/newsguidelines.html
Re: Our First Certificate Is Now Live
#198-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 For the record, the cert I've downloaded (using SSL over the Let's Encrypt site) from the Let's Encrypt site has the following SHA256 fingerprint: SHA256 Fingerprint=96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6 Works great. To install on Firefox, just click on the first certificate listed here, in der format (just be su…
Re: Our First Certificate Is Now Live
#199Earlier quoted context omitted.
You're wrong. EV is a scam. I can afford to buy EV for most of my sites, but I don't do it. Because consumers don't really care. Even HN doesn't have an EV! Ferrari is what everybody wants, EV is a different story! And stop downvoting all my comments - it shows your subpar human material. Downvote my main point and stop right there. No need to go aggressive and try to silence me and not comment further, because you w…
I really would not care if any of your sites had EV. And I don't care that HN does not have EV. But I may care whether the place I am going to spend money does have one.
Re: Our First Certificate Is Now Live
#200Earlier quoted context omitted.
Actually it's automated in most places, simply requiring you to confirm a request via an e-mail address associated with the domain you're getting an SSL for (typically admin@ hostmaster@ webmaster@, though it varies between certificate providers).
Most of the reputable CAs have some practices in place to check for keywords related to big brands and auto-reject certificate requests. (So you can't get a certificate for "login-facebook.com" or whatnot, for instance.)