6 ms·
Show HN: Snitch.io – SSL auditing and alerting
- yourabi 12y agoWe built Snitch to make it simple and easy to get a handle on your SSL certificates. Our mission is to help people avoid getting blind-sided by SSL issues - losing customers, reputation and business in the process. We've been working on this for a few months and would appreciate any feedback - thanks! If anyone wants to email me directly it is my username at currylabs.com or gmail.com PS: If you are an Open Source project we offer free subscriptions.
- johns 12y agoWho's "we"? You need an about page.
- spacefight 12y agoGreat idea, will definitively check it out. Where are you incorporated, if? The terms says nothing about it. Who is my contract party when I signup?
- yourabi 12y agoThanks for the feedback. We're in Oakland, California.
- spacefight 12y agoAnd who's behind it?
- spindritf 12y agoYou do more than that but really the CA should handle alerts about expiring certificates. They have full knowledge of all certificates, and contact to the responsible party.
- rficcaglia 12y agotrue but then you need to actually renew it amd then install it....too many times tickets are filed but get put at the bottom of this list until last minute, or worse a customer reports the nasty browser security warning page though i do wonder if "this is a feature, not a company"?
- yourabi 12y agoThanks for the feedback. We're constantly improving and rolling out new features. We're confident that over your question will become less of a question :-)
- _asciiker_ 12y agoI think you're trying to solve a non-problem since the company that sells the certificates warns you (sometimes even more than those intervals), afterall, they want you to renew as well. As for checking for quality, that should be the sys admin task or the webmaster. good luck though!
- ianmcgowan 12y agoPerhaps a non-problem for startups, but it's definitely a problem for bigger companies where the group that purchases certs may not be the one using them...
- danielbln 12y agoI would think that bigger companies would use dedicated IT staff over a start-up for something crucial like SSL cert checking.
- aroch 12y agoGiven that Microsoft and Amazon have both had their SSL certs for their cloud businesses expire, a little extra reminding probably can't hurt. That said, I wouldn't pay for a service like this from a random person, I'd have my registrar do it (MarkMonitor or similar -- that's why they're paid the big bucks).
- yourabi 12y agoThanks for the feedback and thoughts, aroch. Can I ask why you wouldn't pay a "random person" as you say - since this information is by definition public? Can you tell me a bit about your experience using MarkMonitor to do this?
- aroch 12y agoI don't see the value in paying someone and then trusting them with something (as you say) important to my business when they have no track record. For my personal set of servers (some 25-30, with ~50 SSL certs), I have Nagios for monitoring them plus calendar alerts, SMS alerts and sane cycling (everything expires in the same month). My employer is an intermediary CA, they can issue their own certs but I've worked with people who use Markmonitor. As part of buying your cert through them is they worry about making sure your domains stay protected. They'll call you, text you and even mail you reminders. And they have a proven track record dealing with companies that are collective worth trillions.
- junto 12y agoCool idea. I had the same idea back when Heartbleed was in full swing. Nice to see that someone has actually executed the idea. Bravo!
- mobiplayer 12y agoThere are various implementations of the same idea out there and they've been there for long. In any case, very nice execution on the front end. Good job.
- yourabi 12y agoThank you! We're constantly improving and adding extra checks.
- yourabi 12y agoThank you for the kind words!
- bowlofpetunias 12y agoGreat idea, will certainly give it a try. Not a big fan of pricing plans that mix volume with features, always makes me feel I'm being screwed when I only need one or the other. (Even though I might be perfectly fine with paying the same amount if the pricing structure was different.)
- _asciiker_ 12y agohow do you mean? this is SaaS, and charging for resource magnitudes is the only actual fair way in order to get some transparency.
- yourabi 12y agoThank you for the feedback! Definitely something we'll consider. Email me if I can help out in any way! hn username at currylab.com / gmail.com
- Thaxll 12y agoBetter off using your own solution with Nagios or something similar.
- evandena 12y ago$10 a month for one certificate seems kind of expensive, considering a script with openssl can do the same thing for free. And only 25 for enterprise? Our midsize business is currently using 416 certs.
- iancarroll 12y agoCan I ask how you've created 416 certificates for a mid size company? Holy shit, lol. Unless those include SMIME certs, but still...
- evandena 12y agoLots of internal web services, web servers, VM hosts, MQ channels, LDAP stores, etc (times 5, for different platforms and locations). Everything gets a cert, haven't been using wildcards. Lots of internal signed certs, but they suffer the same problems that this service is trying to solve.
- yourabi 12y agoThank you for the feedback - interesting to hear that your midsize business generated 416 certs. We do more than you can do by scripting OpenSSL. For example: as far as I know OpenSSL won't warn you if your certificate is signed using SHA1 - one of new several features we're about to push out. More generally scripting OpenSSL requires knowledge, time and infrastructure many people aren't able or willing to invest (what is monitoring the monitor...)
- cddotdotslash 12y agoIdea is great, but pricing seems a bit expensive. Have >25 certs? Add this check to Nagios: http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check_ssl_cert/details http://exchange.nagios.org/directory/Plugins/Network-Protoco... Saved you $200/month :)
- leesfer 12y agoYeah especially since some people offering this same service for free http://voodooalerts.com/free http://voodooalerts.com/free
- yourabi 12y agoSorry, but that is not factually correct. These are very different services. Voodooalerts requires you to place JS on your page. Because of this I am sure they cannot run the full suite of audits that Snitch does.
- leesfer 12y agoNo, Voodoo Alerts FREE has no JS. Its a server ping just like Pingdom or this service, except its free. The full paid version of Voodoo Alerts requires JS to be installed but that is for RUM alerting Edit: you're right about it not doing everything that snitch.Io does, but saving $10 a month on simple alerting sounds good to me
- yourabi 12y agoThank you for visiting Snitch.io. Unfortunately, your statements are still not correct. I signed up for a free account on VA and put in a site with a revoked SSL certificate. It has not generated an alert. It has been over 12 hours. It is still prompting me to insert the JS on my site, by the way. As to your second point. Snitch isn't simple alerting. It runs a full range of tests on an SSL certificate: checking for expiration, checking for revocation, checking that all of the intermediate certificates have not been revoked, checking the certificate is valid for the domain (including SNI), checking that the certificate isn't signed with a weak algorithm such as SHA-1 that Chrome is about deprecate, checking that the certificate has not been changed (incorrect server config, malicious intent...) Snitch is not targeted at people who just need to know if their site is up or down. If you are are a business and users browsing to your site get a big red warning in their browser because your SSL certificate is expired/revoked/weak/misconfigured - that is a problem and you lose money. That is what Snitch is addressing.
- ef4 12y agoI use and really like http://wormly.com http://wormly.com. Their monitoring includes SSL cert validity, among many other things.
- michaelmior 12y agoThis is seems potentially quite useful. It would be nice if it could also notify you if your server is not configured according to best practices in terms of things such as protocol versions and cipher suites.
- yourabi 12y agoThanks for the feedback! That is definitely on the roadmap and will go out soon.
- msane 12y agoI think this is a brilliant idea, and seeing what you've built I'm sort of kicking myself for not having acted on the same idea. It's the sort of thing that is feasible for a company to do on their own but is difficult enough that it is very seldom done.
- yourabi 12y agoThank you for the kind words, msane.
- yugcesofni 12y agoConsidering you can get much of this functionality from programs created by CAs (for example, https://www.digicert.com/cert-inspector.htm https://www.digicert.com/cert-inspector.htm from my CA), this seems... way too expensive.
- deleted 12y ago[deleted]
- yourabi 12y agoThere are some pretty crucial and obvious differences between these two products. Does DigiCert provide any guarantees on how often they monitor your certificates? Do they offer any alert mechanisms other than email? Do they let you monitor certificates that are on your critical path but not necessarily ones you own (partners...etc) You also mention cost..but since you are not paying them you are not their customer - you are their product. Snitch is clearly aligned with customers since our goal is to help you succeed at securing your site. Our goal is to make it easy for you (site owner) to do the right thing and provide a good experience to your customers.