StartCom operated solely in China: an analysis of the new StartCom website
percya.com
percya.com
After trying to log in to their portal using my old client certificate, I realized that they have supplemented this mechanism by a simple pass code that it sent per mail. This effectively negates all of the security benefits the old approach had and means that my account has no two factor authentication and anyone who can intercept the mail or access my account, can log in. It's literally one factor since there's no account password, the code that is sent per mail is sufficient. I hope they reconsider this.
I was a happy StartCom customer in the past and I hope that the new owners safeguard my personal data/passport scan that I uploaded during validation just as well as the old owners did. The interactions with Eddy Nigg that I had were really friendly (long time customer, when the company was young he'd do the validation phone calls himself and respond to customer tickets), and StartCom was really important before Lets Encrypt existed and they did a good job at it.
StartCom has/had a policy of keeping your personal data for seven years after validation, so yeah. Makes you wonder what happens to customer data when companies get sold. Even if you trust them today, you don't know what will happen in the future.