Earlier quoted context omitted.
I'd be very interested to know which of the EFF's political positions you object to, but it appears pretty clear you're avoiding answering that question...
I don't think net neutrality is a good idea. I also have far-right ideas, while they have repeatedly expressed themselves to be liberal. I'm not the kind of person who believes in boycotting (especially in this case, where I'd be all alone it seems :-) but if I could avoid them, I would. If not, no biggie.
WoSign and StartCom: Mozilla’s proposed conclusion
201–210 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#202As someone who's using StartCom for several years I'm really anxious now. I may use Let's Encrypt for a few sites but not for all and I also got my email certificates from StartCom. As far as I know there's no suitable alternative that does not cost $500+ per year, or does anyone have an advice for me?
I hate to say it, but if you need the functionality that Let's Encrypt won't offer (wildcard certificates, longer validity lengths, not wanting/needing to run certbot, code signing, etc) ... your best bet is to look for the SSL resellers. I'm not going to name the one I used (as I'm not marketing for them), but I purchased a three-year AlphaSSL wildcard certificate recently for a little over $110 (for all three years…
I think that's the kind of thing you should expect in any market where the cost of serving a new customer is dominated by the marketing & sales costs in acquiring that customer.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#203Earlier quoted context omitted.
> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…
Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#204Wow, this would be devastating if they actually went through with revoking their root certificate. StartCom is (well, was ) the only competition to Let's Encrypt in the free certificate space. It is far and away the cheapest direct provider of wildcard certificates (which are impossible to get for free), unless you move into reseller territory. And even their free certificates last four times as long, and don't requi…
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#205Well shit. I always liked StarCom because of their approach to charge for verification (with increasing costs for each higher trust level) but not for issuing certs (while still manually checking every cert request, at least for any OV&EV cert in my case). This entire WoSign acquisition is incredibly shady. Shortly after that some of the customer reps had chinese names, service quality declined and we got offered to…
What use case do you have for wildcards that you can't use Let's Encrypt or similar automated issuance? Just curious, as I've yet to hear a terribly compelling one...
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#206Goddammit. I really liked StartCom for free S/MIME certificates and TLS certs that don't expire after a month. So people, is there a comparable free product out there (don't say LetsEncrypt, they don't do S/MIME unless I'm mistaken)?
Do people use S/MIME with the standard (web-based) trust stores? If you're using it with a small group of people you're in communication with, you can always generate your own CA pretty easily with the openssl command. (Except for the part about the openssl command, this is what Exchange does: everyone joined to an Active Directory domain gets config from the AD servers, so AD generates its own CA for S/MIME certs an…
Microsoft's CA services (in Windows) is actually an awesome product. You can create your own root CAs and intermediates and use the included templates or build your own to (automatically) issue certificates for anything and everything that needs to communicate (users, web servers, file servers (including encryption for data at rest), e-mail, etc.).
The CA services are one of the few things I will happily concede that Microsoft did "right" (along with Active Directory and SQL Server).
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#207Earlier quoted context omitted.
Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…
So wosign's best bet might be to call Mozilla's bluff and issue backdated certs now?
> It is true that this date is chosen by the CA and therefore WoSign/StartCom could back-date certificates to get around this restriction. And there is, as we have explained, evidence that they have done this in the past. However, many eyes are on the Web PKI and if such additional back-dating is discovered (by any means), Mozilla will immediately and permanently revoke trust in all WoSign and StartCom roots.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#208Earlier quoted context omitted.
there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…
> Connecting to TLS to news.ycombinator.com is nice in that I know nobody has read or altered the message in transit. The fact that a third party vouches that news.ycombinator.com is who they say they are doesn't add anything for me, because I don't trust news.ycombinator.com any more than I would trust somebody impersonating news.ycombinator.com. The CA in this situation simply complicates things and adds nothing fo…
I'm personally not a huge fan, but (if I'm interpreting her/his argument correctly), it'd at least be secure against a casual MITM.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#209When it comes to shady shit like this... I would reference the title of Metallica's first album.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#210Earlier quoted context omitted.
> worst case Can you develop please? To me it seems that the worst case would be an immediate and permanent revocation of their certs because of fraud. I find Mozilla/Google very lenient in this affair, and that's probably because I don't understand what's the problem with revoking a CA with short notice. Ok it's annoying for customers, but they just have to subscribe to a new CA and install the new cert. It's annoyi…
Immediate distrust of all StartCom certificates might be the worst case for WoSign/StartCom, but it's not the worst case for the incumbent CAs as a whole, and it's only marginally worse than what's being done already for WoSign/StartCom. The fact that they have a way to punish the CA business itself without punishing its customers is a good thing . It sends a clear message that the browsers can't be blackmailed out o…