Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

http://www.trustico.co.uk/products/rapidssl/cheap-rapidssl-s...

Cheap, no certificate chain, and everything seems to have the roots installed.

It doesn't really matter where you get them from, the whole thing is a bit of a scam anyway. Since your security is as weak as the worst issuer, there's no point in buying a "premium" certificate.



Since your security is as weak as the worst issuer, there's no point in buying a "premium" certificate.

True for most of us here, but not universally true. Extended validation certificates are expensive but provide an unparalleled level of reassurance for users: http://en.wikipedia.org/wiki/Extended_Validation_Certificate


Yeah, I would disagree with this as well - they're supposed to provide more reassurance, but all the studies of user awareness of this - and security UI in general - generally conclude that almost nobody has a clue what these mean or even noticed their existence:

- http://www.securityfocus.com/print/columnists/405 - read the linked PDF, if you haven't already - it's pretty eye-opening. - http://i.imgur.com/u7PFH.jpg - this turned up on reddit the other day.


I respectfully disagree. I recently bought an EV certificate from VeriSign and, apart from some paperwork, the only "extended" validation was a two minute phone call from a VeriSign rep. Well worth the EUR 575,- :/


What I mean is the "green bar" or "green text" in the Web browser. I'm no SSL expert (though not a novice either) but I do like seeing that appear when logging into online banking or PayPal. If it didn't come up that way, I'd be immediately suspicious.


I assume they verified that you are in fact a citizen of a first-world country, possibly with an actual company that pays its taxes. That's basically all the trust an average site needs. It's not so much that your website can now be trusted to never do anything nasty, but if it ever does there is someone to hold accountable.


There will of been at minimum checking for address and phone listings for the company (yell or scoot for UK EV's) in addition to the human telephone validation for signer and approver.


Different applications for EV certs will be required to provide certain additional information and all validations must pass CAB guidelines.

We personally use Comodo for our 'cheap' certificates as we get massive buy discounts and GlobalSign for EV as they've have a 2048 bit default root since the start.


EV only really got in the news after Comodo resellers were caught issuing 'validated' certificates with no actual validation whatsoever. (Conveniently, there was a fresh release of IE that displayed EV certs in green.) Any validation process is as weak as the worst issuer, 'extended' or otherwise, and promising to do better validation for more profit doesn't really serve to deter the actual violation that got us here to begin with.


You are assuming that the users will notice the lack of green text for the EV certificate in their browser. It is not an error to use a non-EV certificate, even if the site 'should' have one.

(defining 'should' here is difficult)


This can be read in the process of issuing a wildcard certificate a Trustico: https://www.trustico.co.uk/geodirect/order/step1.php

The server count option tells us how many physical servers you intend to install RapidSSL Wildcard on. A licence will be activated for each physical server installation and you must pay the full product price for each additional server installation. Most customers choose to install RapidSSL Wildcard on 1 physical server only. RapidSSL Wildcard includes 1 server licence free of charge and can be installed an unlimited number of times on each licenced physical server.

Licenced SSL certificates per server? Come on.


I agree it's a scam but are they recognized in mobile phones? I cannot find a cheap one that is good for my android phones at work.


Try https://tracker.oneis.co.uk/ in your phone -- it's got a cheap cert on it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: