5 ms·
StartSSL has some of the worst support I've ever encountered. Normally bad support means clueless or non-responsive. However StartSSL support is often actively
by ascorbic 11y ago
StartSSL has some of the worst support I've ever encountered. Normally bad support means clueless or non-responsive. However StartSSL support is often actively hostile, treating customers as idiots or worse. I should point out that this isn't always the case, and I have used them in the past without trouble, but the times when it is bad are bad enough to write them off. Their site also looks like it was made in 1998, and while using client certificates is secure and everything, it's also seriously user-hostile. I have to remember which computer and browser I used a year ago to sign up? Yeah, I know I should back up client certificates, but seriously who does that?
- derFunk 11y agoI agree that their style in responding to questions is really bad (one liners etc). Yet I'm having the experience that they responded quickly and with helpful information if you had a question. I'm now just curious what happens to my data if they're sold to China. I mean, the amount of personal data they are asking for when acquiring a certificate is not really small.
- ascorbic 11y agoIt really varies. Sometimes you're right, and they respond quickly (if tersely) to questions. However other times they're rude and dismissive.
- Tepix 11y agoI've had good experiences lately, when they relaunched their website the option to create your own certificate for S/MIME had disappeared (on Mac - apparently it was still there when using Windows). I opened a ticket and the next day it was fixed. Now you can even upload your own CSR for S/MIME certificates which allows for 4096bit S/MIME keys. Previously they only had the in-browser key creation. Nice.
- josteink 11y ago> while using client certificates is secure and everything, it's also seriously user-hostile. I have to remember which computer and browser I used a year ago to sign up? Yeah, I know I should back up client certificates, but seriously who does that? So you want a secure website, and you agree that SSL is needed for things to be secure. But you're not willing to put in one inch of effort yourself to secure your own SSL keys. You can't even bother to back up the master key to your own certs, because it's too much work? Cognitive dissonance much? If you care about security, then do it properly. If you're going to do it half-assed, just don't bother at all. All you're doing then is contributing to security-theater, which is all the work and no real benefits.
- ascorbic 11y agoSo every other CA in the world is doing it half-assed? I'm not aware of any others that require client certs to access the site.
- ascorbic 11y agoI should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I know it's more common in enterprise situations. I'm supposed to have a workflow to backup my browser client certificates just for one site? It's not their fault that browsers mostly have poor UI for handling client certs, but it is their fault for requiring them. Let's not even get started on what happens when you get chain problems, or if the client cert expires, or any of the myriad other ways it can go wrong. Just use 2FA like every other secure site, and I'll store a secure password in LastPass.
- josteink 11y ago> I should add that of course I back up private keys, but in 20 years of using the web, I've not encountered a single other site that uses client certificates for authentication. I don't know what you have been doing the last 20 years on the web (and I'll assume it's more than just surfing facebook), but it's not entirely uncommon, and I've encountered it several places. Symantec's CA uses it. My online bank used to do so too. I've seen VPNs using it. Iirc some IPv6 tunnel-providers also require you to authenticate using certificates before letting you set up new IPv6 subnets. It may not be mainstream, but it's part of the standard. And it's much more secure than a regular username/password, for the same reason SSH keys are more secure than allowing username/password logins.
- ascorbic 11y agoThe fact I'm on Hacker News should probably give you an idea. I know it's relatively common on corporate intranets, but I don't use those. I can assure you that I've used lots of CAs, banking sites, VPN providers, registrars, hosting providers (and plenty of others) and made no specific effort to avoid them, and StartSSL is (almost) the only one I've found. I've remembered that the UK Government Gateway used to use them about 10 years ago, but they were optional. My point was that you referred to all other security as "half-assed" (and implied I was too), which would make almost all other sites half-assed. Now there are a lot of sites with half-assed security, but I'm not sure you could call all of these half-assed: https://twofactorauth.org/ https://twofactorauth.org/ http://www.dongleauth.info/ http://www.dongleauth.info/
- nickjj 11y agoI had a terrible experience with their support too. I'll never use them again. The guy kept throwing out extremely passive-aggressive lines while using smilies while I was nothing but polite. Things like: - "I understand your problem, maybe you should be more careful next time. ;)" - "Next time read the fine print! :)" This was all because I needed to get a certificate revoked. Due to their terrible and unclear interface I had managed to lose a private key that they generated for me and as you know, revoking certificates with StartSSL costs money. The hilarious thing is the revoke fee is way more expensive than just buying a certificate with a different provider. Thankfully I'll never have to deal with them again in my life because superior services exist to obtain/revoke free basic certificates.
- jhkaghjkga 11y ago> lose a private key that they generated for me Found your problem: you should never have someone generate a private key for you.
- nickjj 11y agoYeah I know. Since then I haven't done that. Keep in mind these series of events happened years ago. It's one of StartSSL's flaws too. They are an enabler of doing stupid things.
- slrz 11y ago> However StartSSL support is often actively hostile, treating customers as idiots or worse. Maybe that's because 90 % of them actually are? Oh, and they allow you to authenticate for their web interface using client certificates instead of form abominations? Sweet.