Live data from Hacker News

Don't submit to the SSL cert racket. You can get one for no charge

startssl.com

1–10 of 88 posts

Re: Don't submit to the SSL cert racket. You can get one for no charge

#3
My understanding is free ones are not trusted/accepted by the browsers, hence to have something that isnt tossing errors at your users requires a small payment to a CA.

I've used positivessl from namecheap whenever I need certs, its something crazy cheap like $5

Re: Don't submit to the SSL cert racket. You can get one for no charge

#4

My understanding is free ones are not trusted/accepted by the browsers, hence to have something that isnt tossing errors at your users requires a small payment to a CA. I've used positivessl from namecheap whenever I need certs, its something crazy cheap like $5

StartSSL works fine with all recent browsers. (I think IE 7+)

Re: Don't submit to the SSL cert racket. You can get one for no charge

#5
I've used StartSSL in the past. I will never do so again.

Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#6

I've used StartSSL in the past. I will never do so again. Yes, the certs are free, and yes, they work in all common browsers. But the process of obtaining them is a horror of Lovecraftian proportions. I'll happily pay a few dollars to Namecheap to be able to avoid the nightmare that is StartSSL's UI.

This hasn't been my experience. Their web site is ugly and lame but once you're logged in it's about a 3-step process to apply for the cert. Both times I was emailed within 10 minutes that my cert was ready, and it works fine.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#8
post #7

[deleted]

>Unlike the attacks on Comodo and other certificate authorities, these attackers did not

>gain enough access to issue valid certificates for arbitrary domains to themselves, StartSSL

>said. The attackers were also unsuccessful in generating an intermediate certificate that

>would allow them to act as their own certificate authority, The Register reported.

Re: Don't submit to the SSL cert racket. You can get one for no charge

#9
post #2

I'd feel a lot better about using this if its website looked a bit more professional.

This seems to have been downvoted but its not an invalid point. The web is old enough now that a certain level of design is expected of things people need to trust. A shop down a side alley with a hand written sign inspires less confidence than something plastic on the high street - however wrong that initial impression may be.

People with background knowledge may know startssl is legit/good but to a newcomer I can easily see why their first impression is off.

Post reply on HN