3 ms·
Companies like Microsoft are king-makers so they essentially get to pick and choose who gets to be a "trusted" certificate authority, and therefore we wind up w
by nickf 14y ago
Companies like Microsoft are king-makers so they essentially get to pick and choose who gets to be a "trusted" certificate authority, and therefore we wind up with a competition-less market.
Not really. Each browser and OS has it's own benchmark to be included as a root CA, and it's certainly not a 'pick and choose' thing. There are clearly defined rules for each, most of them relying on an independent audit to either WebTrust or an ETSI standard - neither of which are particularly 'easy' or 'cheap'. You're welcome to go and get an audit, set up your CA infrastructure and apply to MS and become a 'trusted' CA. Then you just have to repeat that for all the other big software/OS vendors, and then wait a few years till those versions in which you're included are in wide distribution (or not, as things like Windows have an auto-update mechanism and the auto-update of Firefox and the like are making the process much easier!).
Many of these companies claim this excess cost
There is an inherent cost in the verification of some certificates. Sometimes, it's just an automated domain-verification. Certificates are often sold on the level of verification performed - and in some cases the browsers treat these differently and display different UI chrome as a result.
(over the technical costs which are low)
Again, not really. It's certainly not a low cost to have an infrastructure to pass one of the aforementioned audits. Not only that, there are some significant costs in supporting the revocation infrastructure - especially if you happen to have a certificate on a high-traffic site (think Twitter, any of Apple/Microsoft/Amazon etc.) You'll have to support both a CRL infrastructure (TB a day of transfer) and an OCSP infrastructure (not as much transfer, but not 'just' static files). We're taking tens to hundreds of thousands of hits/second.
But in my experience, from buying certificates, certificate authorities never do this
Ignoring that the plural of 'anecdote' is not 'evidence', I'd say that there certainly are certificates where the ordering process is very simple and has nothing more than a domain-ownership confirmation. There's probably more verification in the payment end. However, getting an EV certificate does contain a significant verification process that sadly isn't the easiest. Code-signing certs tend to require a bit more in the way of ID verification also.
Honestly any SSL certificate which costs more than $5~10 is a rip-off
If you don't want to pay 'extortionate' costs for a certificate, try offers like this - or as someone else suggested below, StartCom - Eddy runs a great company and gives away a lot of certificates and charges minimal costs for the rest.
'Course, we should always buy things based on what we think they should cost, not what they actually do...
Disclaimer: I work for a CA. Just wanting to add a viewpoint from the 'other side'. I won't disagree we're a reasonably un-liked industry in places (HN especially!). There are a few misconceptions, though.