4 ms·
> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.
by jonathantf2 1y ago
> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs"
This is NOT a reason to distrust a website.
- bob1029 1y agoNot outright, but it's more likely that a malicious actor utilizes the simpler or cheaper solution. $300/yr+ adds up, especially if you need to go through due diligence to acquire the EV.
- jonathantf2 1y agoTrue - but if browsers don't show the EV cert until I click 3 buttons and my bank don't use one is there really a point?
- bob1029 1y agoFrom a customer & technical perspective, not really. From a compliance, regulatory & risk perspective, definitely. The EV certificate often comes with additional liability protection to cover any end customer claims related to certificate issues (i.e., if the authority is compromised and the customer's PII becomes exposed).
- spiffyk 1y agoThis absolutely IS a reason to distrust a website claiming to be owned by a bank (or any other institution working with such sensitive assets). To be precise, such a website absolutely needs to have a certificate granted not only on the basis of "yes, I control the machine this domain points to" (which is what Let's Encrypt does), but also based on other, more physical and reliable means.
- deleted 1y ago[deleted]
- mnw21cam 1y agoYou're talking about EV certificates. They're dead.[0] I personally would trust something signed by Lets Encrypt more readily than many other certificate providers. They appear to know what they are doing. [0] https://www.troyhunt.com/extended-validation-certificates-are-really-really-dead/ https://www.troyhunt.com/extended-validation-certificates-ar...
- lxgr 1y agoThe only thing other CAs do (after EV certificates stopped being a thing, as a sibling commenter already mentioned) is to take more money from you than Letsencrypt, in exchange for longer validities and historically some other concessions (although the browser forum has been clamping down on that, for good reasons). In other words, if the bank is following best security practices, they're fine with Letsencrypt; if they don't, they might need somebody else.
- jonathantf2 1y agoMy bank don't have an EV, they have just a plan Amazon cert.
- jmholla 1y agoFollowed up with: > While everyone can register for free on Let’s Encrypt, only (or mostly) serious companies pay money to register on DigiCert, GoDaddy, and so on. GoDaddy is not a serious anything. DigiCert perhaps, but GoDaddy has repeatedly shown themselves to be scummy and untrustworthy. That said, I do see the value in having an entity like a bank pay for a stricter cert with identity validation versus leveraging Let's Encrypt's free infrastructure which only validates domain/site control.
- lxgr 1y ago> While everyone can register for free on Let’s Encrypt, only (or mostly) serious companies pay money to register on DigiCert, GoDaddy, and so on. Serious companies donate the money they saved by not buying snake oil to Let's Encrypt.