Live data from Hacker News

Our First Certificate Is Now Live

letsencrypt.org

91–100 of 263 posts

Re: Our First Certificate Is Now Live

#91
post #66
post #60

Earlier quoted context omitted.

Sure, but registrars would need to start doing a lot better job of checking the identity of people applying for domains, otherwise we'd just end up with domain validated certificates all over again. As the grandparent post notes, all CAs completely automate domian validation at present.

My point is that regular domain validated CA should be the sole job of registrars. It would even prevent parallel certs being fraudulently issued - a domain can only be registered at one registrar at one time. Sure, you could have the other CAs still offer EV (real-world identity) validation as a value-add. But it's pretty silly that, currently, you have to pay a third party (today's CAs) to validate something that t…

The other side of that argument is that if your registrar is also your CA, they have the ability to give bogus SSL certs to an evil server and the ability to direct your domain to that evil server.

Re: Our First Certificate Is Now Live

#92
post #91
post #66

Earlier quoted context omitted.

My point is that regular domain validated CA should be the sole job of registrars. It would even prevent parallel certs being fraudulently issued - a domain can only be registered at one registrar at one time. Sure, you could have the other CAs still offer EV (real-world identity) validation as a value-add. But it's pretty silly that, currently, you have to pay a third party (today's CAs) to validate something that t…

The other side of that argument is that if your registrar is also your CA, they have the ability to give bogus SSL certs to an evil server and the ability to direct your domain to that evil server.

They can already do that, as they could temporarily hijack your NS records and buy a cert somewhere else. If you can't trust your registrar, you have bigger problems (I'd say "all is lost")

On the flipside, having a registar act as the only valid CA would mean that choosing a trustworthy registrar suddenly has real value. Power users could make an educated opinion on the trustworthyness of a given domain validated CA. Domain owners could be sure they're not at risk for how in the current system, an adversarity could get a valid parallel SSL certificate from a sloppy bargain-bin CA, even if the domain owner picked the most expensive and diligent CA and registrar for themselves.

Re: Our First Certificate Is Now Live

#93
post #75

I feel like these initiatives to make SSL available for everybody just lead to the same conclusion: EV will be the only viable alternative to show real trust, and EV is much, much more expensive than regular SSL ever was.

But that's nothing new. If you need real trust, you need EV. The win from LetsEncrypt and any other attempt to make SSL more mainstream is the encryption, not the trust. If you're using SSL you're protected from some government and ISP snooping, and from having the contents of your message or webpage altered in mid-stream by a nefarious third party like AT&T.

Of course it's new. It's new since there are free certificates. Before, you had to pay, always. The amount was irrelevant, but you had to show your credit card. You had to prove your identity. That's a whole new felony there: stolen ID, carding, etc.

Re: Our First Certificate Is Now Live

#94
post #79
post #63

Earlier quoted context omitted.

I run https://certsimple.com : we only do EV certificates, we're the fastest place to get an EV cert, we check as much as we can before you pay us a cent, and our application process is 80 seconds.

These shameless plugs are getting really annoying. We know about you, we know CloudFlare and Let's Encrypt are kinda competitors with their free certificates, but you don't have to comment on each post about them. Really, stop annoying us - it doesn't do you any good, honestly!

These shameless plugs are getting really annoying. We know about you

I for one had never heard of these guys and appreciate the mention. Besides, as far as I can recall, it's never been considered problematic to promote your own service on HN as long as the mention is topical and done tastefully.

Re: Our First Certificate Is Now Live

#95
post #82
post #63

Earlier quoted context omitted.

I run https://certsimple.com : we only do EV certificates, we're the fastest place to get an EV cert, we check as much as we can before you pay us a cent, and our application process is 80 seconds.

You might want to fix your webdesign: http://i.imgur.com/zQbWnUI.png And this is in Firefox, which renders fonts more bold than other browsers.

In Chrome is better but still terrible :/

Re: Our First Certificate Is Now Live

#96
post #81
post #79

Earlier quoted context omitted.

These shameless plugs are getting really annoying. We know about you, we know CloudFlare and Let's Encrypt are kinda competitors with their free certificates, but you don't have to comment on each post about them. Really, stop annoying us - it doesn't do you any good, honestly!

In this case, the previous commenter was explicitly asking for advice about how to get certificates more conveniently today, so the replies about existing services that can do so seem quite relevant.

Oh, the commenter asked for the overly expensive EV type? Let's not be the devil's advocate. This is the wrong way to advertise. This is not the beginners corner. You advertise once, twice, three times, people remember, you can search HN - no need to annoy people till the end of the world. The company seems desperate for new business this way anyway.

Re: Our First Certificate Is Now Live

#97
post #35

It's amazing that it takes a free provider to make things simple: https://letsencrypt.org/howitworks/ I'd actually pay more than I do now for SSL certs to get that kind of simplicity.

Looks awesome!

Does anyone know if there's an undo command for `$ letsencrypt run`?

I would love to try this, but too scared to do it and mess up with my nginx configs.

Re: Our First Certificate Is Now Live

#98
post #81
post #79

Earlier quoted context omitted.

These shameless plugs are getting really annoying. We know about you, we know CloudFlare and Let's Encrypt are kinda competitors with their free certificates, but you don't have to comment on each post about them. Really, stop annoying us - it doesn't do you any good, honestly!

In this case, the previous commenter was explicitly asking for advice about how to get certificates more conveniently today, so the replies about existing services that can do so seem quite relevant.

It's like trying to sell a Ferrari to a guy who's looking for a regular car...
Post reply on HN