3 ms·
I don't think it's a scam, no. Disclaimer: 'it' pays my wages. As another poster mentioned, encryption is worthless without having some kind of validation of t
by nickf 17y ago
I don't think it's a scam, no.
Disclaimer: 'it' pays my wages.
As another poster mentioned, encryption is worthless without having some kind of validation of the other end-point you're communicating with. Granted, the CA industry has made some mis-steps in this regard (domain-only validation certificates as an example), but we're doing things to rectify this situation albeit slowly (the CAB forum and EV 'green bar' certificates).
Not only that, while the cost for certificates I believe can be justified, it's dropped significantly over the years to the point where even the labour-intensive EV certificates can be had for more reasonable costs. Site owners really should be factoring the cost of certificate(s) into the operational costs of owning and running a site nowadays - just as they must with the domain, hosting, dns, email etc.
That said people like Eddy Nigg and his company StartCom are driving down the costs of certificates (something I know isn't cheap or easy).
As another poster mentioned, you can get some basic certificates for free, or for not much more than the cost of a domain elsewhere. And with Eddy's efforts, yes - they work in 'most' modern browsers. More power to him.
- wmf 17y agoSite owners really should be factoring the cost of certificate(s) into the operational costs of owning and running a site nowadays - just as they must with the domain, hosting, dns, email etc. That's no problem for big sites, but it doesn't work for the "long tail". When a domain costs $8/year and you can get Web hosting ranging from free to $100/year, any paid cert starts to look disproportionately expensive. People will not blindly accept spending close to 50% of their budget on security.