Earlier quoted context omitted.
How dare they give you a free service, and then decide to charge for a revocation which they had said they would charge for (and is meaningless because by default all browsers ignore revocations). Unfortunately for various historical fuckups, we consider self signed certificates to be more dangerous than cleartext unsecured http. Lots of scary warnings pop up. That is absurd. Starcom is helping fix this by issuing fr…
> The Mozilla CA policy does not include a provision for obvious trolling and posturing. This isn't really trolling, after Heartbleed we should consider all SSL certs used by OpenSSL based servers as compromised. This sites just tries to make the point more obvious by putting such compromised cert in public view.
StartSSL, please revoke me – My private key has been compromised
31–40 of 71 posts
Re: StartSSL, please revoke me – My private key has been compromised
#32Re: StartSSL, please revoke me – My private key has been compromised
#33StartSSL is based in Isreal. They are hungry for money.
Re: StartSSL, please revoke me – My private key has been compromised
#34I've used these guys in the past and quite like them, but yeah, this is poor PR and I hope they get pulled for not paying attention to, you know, the overall security of the trust product they're selling. I don't want lock-in on my SSL cert but it's effectively a contract if I have to pay a fee to break it and the SSL padlock on my domain is held hostage if I don't. Maybe someone should open a bug report on Bugzilla.…
So, to verify, would you rather pay a (smaller) fee upfront for every registration (effectively, insurance against revocation), rather than pay a (larger) fee if and only if you ever need to revoke? (Or, are you saying that StartSSL is somehow evil, because they refuse to do everything you ever wished they could do for you with no compensation of any kind?) (Is the issue simply that they won't revoke without a fee, e…
Re: StartSSL, please revoke me – My private key has been compromised
#35Re: StartSSL, please revoke me – My private key has been compromised
#36Users don't trust Verisign or StartSSL, they trust whoever Mozilla, Microsoft or Google trust. Stop accepting new CAs in to the browser whitelist, start a CA for the public good with a true open source, full disclosure mentality. Why not?
Re: StartSSL, please revoke me – My private key has been compromised
#37perhaps startssl is thinking about ending their free cert "business", much like how dyn has stopped free dyndns..
Re: StartSSL, please revoke me – My private key has been compromised
#38Classic Big Lebowski moment: You're not wrong, you're just an asshole. Their stance is entirely correct. The customer used a file that StartCom provided in software that turns out to have had a security flaw. That's neither StartCom's problem nor liability. They didn't say "use this certificate with anything other than OpenSSL; you'll be sorry if you use OpenSSL," nor could they have foreseen it. On the other hand, s…
Their stance is entirely correct Well it sounds like their stance is wrong if they've agreed to the Mozilla CA Certificate Maintenance Policy: CAs must revoke Certificates that they have issued upon the occurrence of any of the following events: ... the CA obtains reasonable evidence that the subscriber’s private key (corresponding to the public key in the certificate) has been compromised
Re: StartSSL, please revoke me – My private key has been compromised
#39Why is the power of revocations in cert issuer's hands? As long as the private key is private, I don't see how a malicious entity could add your private key to the revocation list. In fact, a place in the revocation list should be reserved every time a cert is issued, possibly with a mechanism to trigger it with the private key. For example, if I send a message encrypted/signed with my private key to the revocation a…
Because a major reason for revocation is when the private key has been compromised.
Re: StartSSL, please revoke me – My private key has been compromised
#40Not that revocation will have much practical effect on the unlikely event of his keys having been compromised, and an attacker considering his website important enough to MITM - and having the means to do so to a sufficiently large audience to make it worthwhile. Seems like a lot of fuss over nothing much, in this case.
EDIT: Also just to note that the private key he has shown on this website was compromised solely by him putting it there, and not extracted via Heartbleed. Indeed, the certificate was created a few days after the vulnerability was reported and fixed. Makes this strange cry for attention even more absurd.
[1] https://freedomsponsors.org/faq#How%20do%20payments%20work?