Skip to content

Comment on StartCom charges for reissuing SSL certs due to Heartbleed

Comments

Every CA that motivates cert owners to rather not revoke certs if they get compromised, should not be a trusted CA by anybody. It's that simple.

StartCom's been doing this for a long time. This is what makes them dangerous. It does not make them any more dangerous now than before.

Even if StartCom made an exception in this case, it should not change anything. Because even without hearbleed, certs still get compromised and StartCom's standard practice is to motivate owners to keep using known compromised certs.

Why does anybody trust a CA with this policy? Why is StartCom included in browsers and OSes? Why isn't anybody removing StartCom and CAs with similar policies from trusted CAs?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.