Live data from Hacker News

Don't submit to the SSL cert racket. You can get one for no charge

startssl.com

21–30 of 88 posts

Re: Don't submit to the SSL cert racket. You can get one for no charge

#21

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

I find their service excellent. The website doesn't have the latest hip look, but the service is solid, and they are very responsive and helpful in case you run into an issue. For a free service, that's impressive.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#24
post #22

[deleted]

They also, like any other CA, have the ability to generate keys in your name any time they like. That would have consequences - but so would abusing your private key.

If it's for something where it's that much of a concern (and it IS a legitimate concern, no argument there) then you need a paid certificate anyway - you'd likely want a business name, not a personal one, etc etc......

If we're talking business, you wouldn't be using a free cert from them anyway.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#25
post #14

Its worth to mention that their certificates cannot be used to secure a Java web service because their CA is not included in Java's cert bundle. I had to learn this when I tried to callout to a web service (with a startcom cert) from Salesforce. Also their certs are only free as long as you don't need to revoke it.

Came here to say something like this. While the site is a bit of a pain, and the certs are free, make damn sure you have your site configured the way you want it before you generate the certificate.

It's $25 to revoke a cert, i.e. free up the name so you can use it again elsewhere. I used part of my domain name for an XMPP cert that I later wanted to use for a web subdomain with the same name.. nope. Stupid.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#26

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

I second this experience, and "Lovecraftian" is indeed an excellent way to describe it. It's not just that the process was difficult, it's that my confidence dwindled through every strange and baffling step. Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )

Can you extrapolate on what you mean by feasibility, I use positive SSL on a few domains it works fine with no issues and isn't that hard to setup (basically you just need to be able to receive email on your domain).

Re: Don't submit to the SSL cert racket. You can get one for no charge

#27
post #2

I'd feel a lot better about using this if its website looked a bit more professional.

This seems to have been downvoted but its not an invalid point. The web is old enough now that a certain level of design is expected of things people need to trust. A shop down a side alley with a hand written sign inspires less confidence than something plastic on the high street - however wrong that initial impression may be. People with background knowledge may know startssl is legit/good but to a newcomer I can e…

Absolutely! I had never heard of Start before and I honestly thought for a moment that maybe this was spam that had somehow got on to the front page as a fluke. I'm serious. I'm not used to seeing a company website make it on the front page of HN or HN at all without there actually being some kind of article on the page you get to.

SSL certain are important and I don't think their design is helping them look like a legit business. I trust they are after all the comments here but on first glance I was skeptical and thought it was too good to be true. I know we all pride ourselves on being smart, critical thinker that can look past a site's design and see the true value behind it but I think in some cases it's perfectly normal and acceptable to react this way to a design. Superficiality be damned. I'd rather run from a poorly designed, non-legit looking site and be safe rather than risking it and being sorry later because I gave in to the PC, "don't be superficial" side of me.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#29

Keep in mind that Gandi includes 1 free SSL cert with every domain name. Per year.

I'm with Gandi and didn't actually realise I already had this facility under my nose. Thanks for the information!

I only recently bought a domain with Gandi after seeing it mentioned here.

This feature has just convinced me to stick with them for future purchases.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#30

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

I second this experience, and "Lovecraftian" is indeed an excellent way to describe it. It's not just that the process was difficult, it's that my confidence dwindled through every strange and baffling step. Since you mentioned paying "a few dollars" to Namecheap, can you comment on the feasibility of their $8.95 "PositiveSSL" certificate? ( http://www.namecheap.com/ssl-certificates/comodo.aspx )

The best (in terms of browser compatibility) cheap cert that Namecheap sell is the RapidSSL cert at http://www.namecheap.com/ssl-certificates/geotrust-ssl-certi...
Post reply on HN