3 ms·
Thanks for your feedback but I strongly disagree and I think recent history supports that CAs don't do much for you once they've collected your payment. CAs w
by yourabi 12y ago
Thanks for your feedback but I strongly disagree and I think recent history supports that CAs don't do much for you once they've collected your payment.
CAs won't alert you if someone breaks into your server and replaces your certificate. They won't alert if you if you accidentally push a config change and start serving the wrong certificate to customers... And they certainly will not alert you if you are using a revoked certificate in production.
I've bought multiple certificates from different reputable vendors - I only ever got one Heartbleed notice. (This pattern repeats itself)
Many shops don't have a dedicated admin / webmaster auditing their certificates and even those that do have had public issues (Akamai, Apple, GitHub, Stripe...etc)
The value in a service like Snitch is that we worry about your SSL certificates. Many people don't have the interest or time in rolling their home grown monitoring of this stuff...
- _asciiker_ 12y ago"CAs won't alert you if someone breaks into your server and replaces your certificate. They won't alert if you if you accidentally push a config change and start serving the wrong certificate to customers... And they certainly will not alert you if you are using a revoked certificate in production." You have valid points, my advice would be to make that part of the message as clear as possible. as a sys admin I could be a potential customer but then again, I already have to worry about certs I implement.
- yourabi 12y agoThank you for that feedback! It is very valuable to hear that I didn't message this effectively - I'll work on improving that. I'd love to chat more out-of-band - would you mind emailing me (this username at currylabs.com or gmail.com)