Skip to content

Comment on StartCom charges for reissuing SSL certs due to Heartbleedparent

Comments

Well, that is with good reason. A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system (see the DigiNotar affair from 2011).

A rogue or insecure root CA which is trusted by major browsers/OS'ses would basically invalidate the whole CA system

The CNNIC root is still trusted by most browsers/OSes.

Sure, but it goes counter to "I wish someone could do a genuinely free SSL CA with "reasonable" procedures".

So bad news: it's hard. good news: people are trying.

So bad news: it's hard. good news: people are trying.

More bad news: They're failing pretty hard. CACert have been around for a long time, and still haven't managed to get themselves audited.

There was an interesting thread on the subject on the crypto-list last year ("How much does it cost to start a root CA ?"), see eg:

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

And for good measure, on the subject of certs and trust, the thread after:

"another cert failure" (2011)

http://lists.randombit.net/pipermail/cryptography/2013-Janua...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.