6 ms·
I work for a CA, a large public one. As someone mentioned - please don't equate the cost of the certificate to buy against the cost of the certificate to produ
by nickf 18y ago
I work for a CA, a large public one.
As someone mentioned - please don't equate the cost of the certificate to buy against the cost of the certificate to produce. Signing costs nothing (well, ignoring the expensive HSMs!).
Most of the cost is performing the vetting/validation.
Then there's support costs.
Then legal costs (insurance, warranties etc).
There's often inherent costs with owning/controlling the root certificates - WebTrust annual audits just to get in the major browsers, plus any fees that some manufacturers charge for root-embedding.
Infrastructure costs - CRLs and OCSP responders. CRLs may be tiny files, but we can serve TB a day in a 160KB file :)
Ask any questions - I'll answer as best I can.
- swombat 18y agoI've bought numerous certificates in the past and there's rarely been any serious form of vetting. As for the 1 TB / day, I would hope that at $100/client/year you would be able to afford that without even noticing the costs... Can you give us a breakdown of roughly how much each of those activities costs, or is that private information?
- nickf 18y agoI doubt I can give too much information out publically, sadly. As for the level of vetting, a lot depends on who you bought it from, and what type of cert.
- moe 18y agoAs for the level of vetting, a lot depends on who you bought it from, and what type of cert Which is part of the absurdity here. The CA's make us pay ridiculous fee's for the validation but can't even protect us from other CA's issuing certs for the same domain.
- moe 18y agoEhm, excuse me but gimme a break. Owning a CA is a license to print money - it's as simple as that and really no need for excuses. The costs you cite are dwarfed by the profits. Vetting/validation and support is a fixed cost (support squad), legal costs can't be too rough (how often is that warranty actually claimed?) and well, cry me a river about the chain of extortion going up the CA chain. Yeah, it's really annoying you can't build your own money-printer, you have to rent it! Honestly, a tiny bit of math sobers me of any pity: 1 million customers, $100 bucks a year. That's a solid one hundred million bucks annually. That kind of money buys quite a bit of vetting/validation and legal costs. It might even cover your 30T/month crl-traffic. Barely.
- nickf 18y agoI'm not making any excuses. It's just that there's been a lot of discussion about SSL certs the past few months, and I'm willing to bet there's no more than a roomful of people worldwide with the knowledge and experience to understand how to run a CA and the costs associated. Does your anger extend towards the domain name companies? Webhosts? After all, running on free software and 'cheap' commodity hardware - Dreamhost probably make the same figures you're talking about, and they don't have a lot of the large up-front an annual costs. Just an example, really. To address each point: Validation - not a fixed cost. Some can take several real man-hours to complete, and additional costs of access to third-party databases, translation costs. I see it possible to make a loss on some certs purely in validation. Legal costs - insurance premiums for something this specialised are high, regardless of how many claims made. CA chaining - as per other comments, you're lookat at potentially $50K a year just in audit costs, just to get into the mainstream browsers, with a 5-10 year wait to become ubiquitous enough to be commerically viable. You can pay to get a sub-CA and bypass this step, but it will cost...you can go into 7 figures annually. Again, I'm not attempting to make excuses. I do agree some certificates are overpriced. I am just trying to show how the CA industry is no more a 'racket' or 'license to print money' than many more of the internet-centric businesses that exist, even though it may seem that way without insight. Plus, it keeps me gainfully employed :)
- tc 18y agoIt really is a license to print money. That's not an attack though, most SaaS businesses are. What's unique about being a SSL issuer is the relatively low levels of innovation involved. There is little technical innovation, and no time spent thinking about how to design a product that people want. Putting all the pieces together and striking the right deals certainly requires a bit of business savvy, especially to have done it in 1997, but otherwise the business is rather straight-forward. I think part of the hostility towards SSL issuers comes from the seemingly monopolistic pricing structure. As you note, validation is the largest expense. Largely, that only needs to be done once though, so why doesn't the cost drop dramatically in the second year? And it seems clear to most people that the cost of servicing a domain and its subdomains should not be an order of magnitude higher. If a SSL issuer charged me an upfront service fee representing the cost of validation, then low yearly maintenance fees, and didn't gouge me for subdomains or multiple domains with clearly the same ownership (.com .net), they would have my business forever and my gratitude.
- publius 18y agoWhy are people like Mike Zusman get certificates for already existing domains, which can then be used for extremely effective phishing attacks? The "verification" is a joke at best, harmful at worst.