Why we don't sell domain validated SSL certificates
certsimple.com
certsimple.com
Still waiting for a cert request they flagged "for check within 2-3 hours" two weeks ago…
I have no idea about StartSSL, but some cheaper EV providers Comodo immediately ask you to use a lawyer or CPA to write professional opinion letters.
This allows the CA to do less work according to the EV guidelines, but massively slows down the validation process and may incur additional fees unless you have an in-house legal team or CPA.
We're also doing some future work to make EV more affordable. I'll have more to announce in the next month.
In the meantime, EV works out to be around $20 a month, which is not significantly different to what you pay for GitHub Enterprise or Trello.
We didn't renew our EV SSL and went to a domain validated SSL. Our number of daily orders actually went up (this is probably just company growth.)
Amazon should be ashamed of themselves in 2015. No assets let alone their home page should be non-HTTPS.
Anyway, I doubt most users even check for the padlock and will gladly send their data trough HTTP. Even if they do chack, they'll have no idea what the green bar means.
Wildcard certs only work one level down, when I looked into this Firefox was the last browser to remove support for doing multiple levels.
CertSimple argues (https://certsimple.com/blog/wildcard-ev-certificate) the EV restriction on wildcards is to prevent google.com.fraud.ru from getting an EV certificate. The single-level wildcard restriction already prevents that.
Re: your edit: as the other poster notes, the DV cert would have to be for '*.com.fraud.ph'. That's entirely possible though.
> Our CA, DigiCert, does the final checks before issuing your certificate, so you should speak to them directly.
What exactly are you offering here other than reselling DigiCert?
1. We check your company registration, status, and DNS/whois and CSR while you apply - and before you pay.
2. Better CSR creation. There is no software to install, and no command line Q and A or clicking. You just paste a command onto your server, in either bash or pwoershell, then paste back the results.
3. We're massively faster than standard CAs. CertSimple deliver EV certificates in an average of 5 hours. The standard time for an EV cert is 7-10 days.
And a bunch more. See https://certsimple.com/about
In your position I would fear that my business/model/product could be easily replaced by any other partner/reseller of a CA, or the CA themselves. Unless your intention is to build volume then either be acquired by a CA or become a CA yourself under somebody elses root?
No probs: I understand the cynicism: the SSL industry is dominated by sales and marketing giants that market snake oil like SGC and seal in search, I wouldn't trust any of them either.
There's not a lot of people who get UX and get crypto: I've got my name in RHEL and I've also built consumer facing web apps for Google and Microsoft. That's 17 years of pretty unique experience, and we launch new features every couple of weeks. If a CA tries to follow - and they will - bring it, we'll smoke them.
Your final point is accurate.
It's easy for me to forget especially when commenting here (HN) that not everybody knows what they are doing and I often undervalue services which bridge a knowledge gap when I have that knowledge.
Thinking again, yes I can see the "doing one/few things very well" working during what is going to be a major shift in the market, especially with the intended end goal.
> I've already ordered - who can I talk to about getting my company validated?
I'd propose the answer to that FAQ needs some sort of improvement, to appear less standoffish.
This is just the “sour grapes” rationalization from CertSimple.
Let's Encrypt want to do EV too - they've also asked CertSimple for help previously to do it. it's significantly more work than automating DV again (which has already been done) are CertSimple are far ahead of the entire SSL industry when it comes to speedy EV validation.
Encrypting something with a public key, without knowing who that public key belongs to, largely defeats the purpose of encryption.
The moment you're deploying an _app_, you've already solved the hard problem that certificates are meant to help with. Just activate certificate pinning and you get a lot more security to boot.
CAs "help" in the case where you're navigating to a site via a URL bar and you have no other stored information to help identify them. An app is stored on your device already, and doesn't have a URL bar so you don't need to care about the colour of the lock icon.
Of course, in a world of apps and certificate pinning, the business model for CAs looks even more questionable than on the web. In theory, your bank's site should show a green lock and if you click on a phishing link, you get a nasty red one. In practice, you'll see red on your bank's page every now and then when they forget to renew their certificate and, to quote security researcher Peter Gutmann: "The only place you're guaranteed never to see a certificate error is on a phishing site. They don't use SSL at all, and people still visit them."
That's why the jurisdiction is shown in the address bar. However it'd be worth seeing how effective that is.
This just seems like a straw man argument. I can't say that I've encountered either a network engineer or even an end user (s/EV/green icon) who thinks that an EV says anything about the quality of the company they're working with. End users accept that it means 'more secure'. Network engineers of average ability or above do, in fact, know better.
There's a specific person that's well known on HN that mentioned a pirate site had an EV cert at Edge conf, implying they shouldn't have been able to get one. They have a registered business, and a real address in London, and the EV cert simply assures that identity.
Most people in network ops have very little idea of EV,so I don't think naming individuals is productive.
See 'Do DV or EV SSL certificates mean this is a good company?' at https://certsimple.com/blog/are-ev-ssl-certificates-worth-it
A even better reason for CertSimple to not support DV certs is that it is simply impossible to complete on price with the big guys. And will be even more difficult once Let's Encrypt launches.
It's wishful thinking on the certificate providers to hope for people to want SSL certificates to actually prove identity.
And if you want SSL for your private website, tough luck.
Yes, see my response to the price point above.
Deleted comment
Anyone who's tried to use something.else.s3.amazonaws.com as an Amazon S3 bucket URL will have found that this is FUD.
Wildcards are single-level - <star>.example.com won't cover <star>.<star>.example.com.
Deleted comment
Related: http://security.stackexchange.com/questions/73476/why-is-ava... and http://serverfault.com/questions/699005/google-chrome-says-m...
Deleted comment