Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nickf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
151.
▲
by
nickf
18y ago
Although the production costs are free, the maintenance costs (both short and long term) to make the certificates have any worth to purchasers is very significant.
152.
▲
by
nickf
18y ago
Sorry, but that's incorrect. The major browsers will let you in - you just have to pass all their audits, comply to all their regulations, and commonly have a WebTrust audit....which can set you back mid-$xx,xxx. All browsers/OSs are accept
153.
▲
by
nickf
18y ago
There isn't one. I very much doubt there ever will be.
154.
▲
by
nickf
18y ago
I work for a CA, a large public one. As someone mentioned - please don't equate the cost of the certificate to buy against the cost of the certificate to produce. Signing costs nothing (well, ignoring the expensive HSMs!). Most of the cost
155.
▲
by
nickf
18y ago
If anyone needs a cert (including the OP if he hasn't purchased yet) and help setting it up on pretty much any server/device/platform - email me. My address is on my profile. Mention HN and this thread, and I'll make sure you're looked afte
156.
▲
by
nickf
18y ago
I guess you haven't read any of the other discussions on this topic. If you don't have the identity verification, the encryption is worthless. If my grandma went to a site with a self-signed certificate - you're damn right I'd want an error
157.
▲
by
nickf
18y ago
You can say it's crap all you want, but until you've worked inside a CA and seen what goes on - you know shit. Good luck ordering a cert with your 'shopped docs...
158.
▲
by
nickf
18y ago
" Short of coming up with a way to create a trustworthy CA that runs for less than $20 a year, there is no great solution to this problem. " Good point. You won't find it - performing proper background checks cost more than that. That's not
159.
▲
by
nickf
18y ago
You can't. Seriously, try it. You can't get a 'proper' cert unless you go through the background checks. You can't get a domain-only validated one unless you control the domain.
160.
▲
by
nickf
18y ago
Encryption is nothing without identity assurance. If you don't know who you're sending the encrypted data to - why bother encrypting in the first place?
161.
▲
by
nickf
18y ago
It's amazing how many people still think Verisign are the only CA out there. There are a lot now, and if you hunt about, you needn't pay more than $10-$20 for a cert that's trusted in most browsers (granted, they are domain-only validated,