BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Who sells the least expensive SSL certs right now?
- Subject: [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- Date: Mon, 22 Dec 2014 11:25:16 -0500
- In-reply-to: <BN3PR0401MB1204EBCF93E4073CBD100C5BDC560@BN3PR0401MB1204.namprd04.prod.outlook.com>
- References: <549251AB.8070607@horne.net> <54932731.1060401@gmail.com> <5493283A.6010407@horne.net> <CA+h9Qs63QnWrktgHaRstzAa9yLNPVVL1QUegx7sQwRXeymajqQ@mail.gmail.com> <5497701D.90103@horne.net> <CAFq0N1x37HaQkKD3gWEP8=CNQFnpvqupNsmVBmgKwQp5XL3S5Q@mail.gmail.com> <BN3PR0401MB12042C738604A70CDADFB62CDC560@BN3PR0401MB1204.namprd04.prod.outlook.com> <CAFv2jcZkz3pK-2OxLDZ75V7Bfs81s1M=YhY2e1R1Ji+LtDE3EQ@mail.gmail.com> <BN3PR0401MB1204EBCF93E4073CBD100C5BDC560@BN3PR0401MB1204.namprd04.prod.outlook.com>
I think you're missing the point. More quotes from the bugzilla discussion: > The problem is not them charging for revocations. If someone has lost their key > or got hacked, okay fine. Their own fault. > > The problem is that thanks to Heartbleed we now have potentially leaked private > keys (leaked due to circumstances outside of the control of anyone) and thus > insecure sites. > > Now with StartSSL charging for every single revoked certificate they are > encouraging people to "eh, the chance my key got leaked is so low, I'll just stay > with my old certificate" thinking and behaviour. > > This is actively compromising the security of SSL and consumers (no one I know > checks the SSL vendor on certificates of sites they visit if there's the lock icon and > it says it is trustworthy). Therefor customers and site users expose themselves to > potential security risks while the browser ensures them they are communicating > securely with the website. and another: > Spreading **** certificates all over the place for free and then forcing people to > pay for the revocation of those certificates is certainly not doing any good for > security. I can't see any reason why startssl.com should be in the truststore while > cacert.org (which do not charge for revocation nor for anything else) are denied > the same status. Now granted, these arguments are about whether slartssl should be in the firefox keystore, not about whether Bill should consider using startssl's free tier. But I disagree that the arguments are weak. On Mon, Dec 22, 2014 at 10:55 AM, Edward Ned Harvey (blu) <blu at nedharvey.com> wrote: > > > From: John Abreau [mailto:abreauj at gmail.com] > > > > As for StartSSL, a quick google search turns up some disturbing issues with it. > > Bah. That's a weak argument. There is nothing secret about charging for revocation, and I don't expect any other CA's to reissue certs for free either. -- John Abreau / Executive Director, Boston Linux & Unix Email: abreauj at gmail.com / WWW http://www.abreau.net / PGP-Key-ID 0x920063C6 PGP-Key-Fingerprint A5AD 6BE1 FEFE 8E4F 5C23 C2D0 E885 E17C 9200 63C6
- Follow-Ups:
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- References:
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jabr at blu.org (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: bill at horne.net (Bill Horne)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: jack at coats.org (Jack Coats)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- From: abreauj at gmail.com (John Abreau)
- [Discuss] Who sells the least expensive SSL certs right now?
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Who sells the least expensive SSL certs right now?
- Prev by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Next by Date: [Discuss] Who sells the least expensive SSL certs right now?
- Previous by thread: [Discuss] Who sells the least expensive SSL certs right now?
- Next by thread: [Discuss] Who sells the least expensive SSL certs right now?
- Index(es):