Skip to content

Comment on StartCom charges for reissuing SSL certs due to Heartbleedparent

Comments

Why does it have to be free? 5 bucks a year for an SSL cert is peanuts.

If you want free, push for killing CAs :)

Charging any amount of money adds friction. $0 to $5 is a bigger jump than $5 to $50. All I care about is having SSL everywhere.

Maybe someone like CloudFlare could cover the "Free CA" project.

5 bucks a year for an SSL cert is peanuts.

'per year' pricing is one of the most insidious aspects of the current CA system.

Certificates don't rot.

They claim that annual renewal is necessay to protect us from a rogue but unrevoked certificate; however any malicious activities would be quite profitable well within a year.

So why not set renewal to be monthly, just to be extra-safe? Weekly? Perhaps I should suggest that to them. The resulting outcry from users might be the only way we can disrupt the CA situation.

I think the billing interval is relatively unimportant.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.