3 ms·
I really like this idea, but it seems fairly punishing for new / all remote / self-funded businesses. If you're running a company out of your own pocket (no SEC
by digisth 11y ago
I really like this idea, but it seems fairly punishing for new / all remote / self-funded businesses. If you're running a company out of your own pocket (no SEC filings), aren't anywhere near big or old enough to have a BBB entry, and are remote (what street address should someone use? their apartment?) I'd like to know what signals you'd recommend bootstrappers use to engender trust for a service like yours, because I don't think "person is known on HN, posts on medium / Twitter about their service" is necessarily amenable to automated analysis.
- Animats 11y ago"it seems fairly punishing for new / all remote / self-funded businesses." There's no right to run an anonymous business. It's illegal in the EU, and a criminal offense California if you accept credit cards. The customer needs to be able to find you and, if necessary, haul you into court to get a refund. You can register a D/B/A name and get a post office box to create a legal identity. That's fine. Hiding behind a web site with "private registration" is a scumbag flag. Read yesterday's article about how Venmo helps scammers by making anonymous payments easy.
- digisth 11y agoI definitely agree with that part. Does your service check WHOIS data, then?
- Animats 11y agoNo, WHOIS data is of such low quality that it's useless. SSL cert data is of better quality, for OV (Organization Validated) and EV (Extended validation) certs. Contact addresses found in text on the web site are also useful. Those we match to commercial business directory information.
- digisth 11y agoConsidering that many smaller companies use e.g. CloudFlare's SSL, I'm not sure that would help them, but good to know.
- Animats 11y agoWe ignore Cloudflare's many SSL certs. We have a short blacklist of MITM-as-a-service content delivery networks. Here's my paper on that.[1] The list is short. Here it is: cloudflare.com – a front-end network for sites, controlling 36,280 domains. incapsula.com – a front-end network for sites sonymusic.com – operates sites for their range of artists. Janrainengage.com – customer tracking service edgecastcdn.net – Verizon caching system fiducia.de – security service for banks vin65.com – wine seller with many sites for various wine brands. practiceweb.co.uk – a hosting service for accountants Sites which use those services are not blacklisted by Sitetruth, but the ownership data in their SSL certs is ignored as meaningless. The CA/Browser Forum is looking into ways to express this better in SSL certs. A cert with fifty unrelated businesses is just silly, and it's a transitional thing until everybody gets TLS-capable OSs and browsers so shared IP doesn't mean shared cert. (Windows XP/IE 6 being the problem). [1] http://john-nagle.github.io/certscan/whoamitalkingto04.pdf http://john-nagle.github.io/certscan/whoamitalkingto04.pdf