Live data from Hacker News

Switch to HTTPS Now, For Free

konklone.com

261–264 of 264 posts

Re: Switch to HTTPS Now, For Free

#261

Earlier quoted context omitted.

I did read their terms, which is why I posted that. Nowhere does it say that you can't use the free certificate for a company. In fact if you read their FAQ ("The certificate is for my company, what shall I do?") it says "even in case he/she decides to obtain certification as an employee or representative of an organization". So it is specifically saying that you can use it for a company website. Also it doesn't say…

@cpncrunch, you need to re-read section 3.1.2.1 of StartSSL's policy: Class 1 certificates are limited to client and server certificates, whereas the later is restricted in its usage for non-commercial purpose only. Subscribers MUST upgrade to Class 2 or higher level for any domain and site of commercial nature, when using high-profile brands and names or if involved in obtaining or relaying sensitive information suc…

Ah, yes, you're correct. I guess their FAQ just needs clarified a bit.

Re: Switch to HTTPS Now, For Free

#262

Earlier quoted context omitted.

This is mostly the fault of the SSL certificate providers, which vary in complexity between the obnoxious GoDaddy and even more obtuse and impossible to deal with. Compounding this, the configuration file formats for each web server platform vary wildly, selecting the correct format and installing it properly can be tricky. Making matters worse, it's very easy to set up something that looks like it's working, but is…

Can't the providers be disposed of, and replaced with an open-source automated system?

It's not that they need to be open-source or not, it's that their user interface is absolutely awful.

You can set up your own CA but you can't sign for domains unless you're in the proper chain. The ones holding the keys for these are the big providers.

Re: Switch to HTTPS Now, For Free

#263
post #217
post #187

Earlier quoted context omitted.

(a) That's not my experience. This site of mine is secured with a StartCom cert, and Safari has always been perfectly happy with it: https://mappiness.me (b) Why? I understood they were among the better providers.

a) Well, if you setup your startcom SSL cert with the browser, that means you've been forced to add StartCOM to your truststores. b) I simply don't trust them, particularly since they use a keybased auth system -- any compromised computer that was used to setup a startcom cert can download the private keys

a) True, but I set it up from Firefox.

b) I think it's moot whether this is better or worse than a password, but I'd probably pick the key-based system (which requires you to physically have my computer) over a password-based one (which might be hacked remotely).

Re: Switch to HTTPS Now, For Free

#264
post #189
post #187

Earlier quoted context omitted.

(a) That's not my experience. This site of mine is secured with a StartCom cert, and Safari has always been perfectly happy with it: https://mappiness.me (b) Why? I understood they were among the better providers.

> This site of mine is secured with a StartCom cert, and Safari has always been perfectly happy with it: https://mappiness.me My Safari can't verify the identity of that website. This is Safari 5.1.7.

Interesting, and a bit concerning. I just checked it on a friend's MacBook too, and that worked (Safari 6.0.5). Perhaps there's been a change at some point?
Post reply on HN