GoDaddy SSL Cert Scam
rentzsch.tumblr.com
rentzsch.tumblr.com
At work we use RapidSSL (a division of GeoTrust) for a handful of certs. Last night I received an email with a banner warning me, "Your certificate is ABOUT TO EXPIRE". The email goes on to list the expiration date as "Oct 12, 2011". Four months is certainly generous notice, but I've always taken this as a simple marketing attempt to maintain customer loyalty.
Usually I take these emails as tickler reminders and delete the first couple. When I eventually decide it's time to renew, I pull up the site by typing the URL into the browser. Upon reading this article, I wondered whether following the link in the email would result in a different pricing structure. As it turns out, the answer is yes, though after playing around, it doesn't appear to have anything to do with the email link.
The first page of RapidSSL's order form handles both new orders and renewals with a pair of radio buttons. Another section of the form allows you to specify the validity period from one to five years. The prices appear alongside the choices, and are currently the same for both initial orders and renewals.
First I visited "www.rapidssl.com" and clicked the "buy/renew" link for a single domain cert. I got an order form with the following prices for 1-5 years:
49, 86, 122, 159, 196
Then I pasted the link from the email (which contains a fairly simple query string that does not appear to have a unique identifier in it) into a different browser. I clicked the "buy/renew" link for a single domain cert, I get the same form with the following prices:
79, 138, 198, 257, 316
It's interesting to me that the difference in price actually increases as the validity period increases:
30, 52, 76, 98, 120
Still more interesting, after resetting the browser and pulling up "www.rapidssl.com" directly, the prices are completely different:
29, 51, 72, 94, 116
I tried the email link one more time and got the 49-86-122 pricing again. Then I tried it one more time and got 19, 33, 48, 62, 76. So clearly RapidSSL is varying their prices on the fly, presumably to gain insight as to what people are willing to pay. I was ready to claim the link in the email yielded higher prices, but that seems not to be the case. So I guess after all that, this isn't particularly interesting. I'll definitely hit the site a few times when it comes time to purchase though.
Unfortunately the pricing structure for a wildcard certificate never seemed to vary.
I suppose they think that since you're visiting their site directly, you wouldn't think (or know) to visit one of their reseller partners instead.
Pretty standard operating procedure here and highly unlikely to be a comment on their customer's web savvy. :)
Been doing this for the last 3 years: they are TRULY retarded for using such a scheme but hey! It catches some people, so I guess tactics like that got them the $2bn "investment" from the friends at Silver Lake.
Reasons why I wouldn't use GoDaddy:
GoDaddy is not really one of the cheapest registrars.
I find their pricing "tactics" (as also mentioned in the article) very questionable.
Their whole website isn't just really appealing to me (I know, very subjective).
http://online.wsj.com/article/SB1000142405270230458400457642...
I use GoDaddy because I manually renew all my domains at the same price as I signed up for. I agree their UX is awful, and they're not the most "good" company in the world... but it serves me for what I want out of a domain provider!
Renewal price hiking is a common practice... you just need to be a smart shopper if you want to save money!
I'd really like to switch, but one of these alternatives are going to need to really compete on price.
If you're not hosting with them, then you're doing it right.
I use Dreamhost for all my domain registrations and most DNS. Great admin interface compared to the competition, still very cheap, domain transfer codes plainly visible, no unlocking or calling or any of that. You just transfer it away. They are the most honest of the bunch and you can move each part of your service off them as you outgrow it.
Easiest to setup a domain for Google Apps too, just click a button.
I immediately transferred to Moniker - they're great, they let you configure absolutely everything. I think what I learned was to stay away from companies that do both domains and hosting. If they just do domains, they understand that you are always going to be sending your traffic elsewhere.
I may have said it elsewhere, but I'm a big fan of DirectNIC even though they are double GoDaddy's price. There interfaces are really clean, and any time I've transferred or sold a domain it has been an absolute breeze. And back in the day, when all the major registrars were shutting down their web-based WHOIS tools (NetSol et al), DirectNIC always kept their WHOIS tool open which always bought them a lot of good will in my book. (I wasn't aware of command line tools like 'whois' and 'nslookup' yet...)
While these are shady practices, they are not illegal.
And the 1-month ahead renewal is not shorting you of a month. It's preventing you from getting into a situation where your cert expires because your CC details were invalid and it took to long to replace them. It also gives you time to configure your server, etc.
They are hardly the first company to offer a different initial price than the renewal, either. I hate that tactic, and watch for it, but it's not even unethical unless they don't tell you about it.
However GD can offer whatever they want. HOWEVER this is deceptive marketing AND I am fairly sure you can take em to courts over this.
Not at all. It implies deceit, but not necessarily illegality. Many scams are legal.
I use name.com and have been very happy. A lot of people here use namecheap. I bet other people will reply to this comment with more options.
Side benefits, CDN caching and threat detection/protection.
After dealing with registrars for a long time I've realized that paying extra $5 per domain per year is totally worth it if you don't have to deal with companies like GoDaddy.
I'm not familiar with the Amazon service, but if it's $1 per domain per month then you'd save $0.7 for every domain using DNSimple.
EDIT: I should link to another HN discussion on the subject: http://news.ycombinator.com/item?id=2753471. One comment that resonates by jbyers: "Read your registrar's terms. See if you still want to save that $6 a year".
With the hosted DNS solution you get access to stuff like the one click setups I mentioned earlier, API access, domain forwarding, vanity name servers and who knows what else. Keep in mind you can use their DNS service even if you don't register your domains with them.
Namecheap
Name.com
Moniker
DNSimple
Gandi
I think i might be missing a few but these are the most popular i remember off the top of my head.But "$10 dollars"?
"Click here to start a transfer. Just $10 dollars. As painless as possible."
EDIT: I see you answered this already in another comment (Key-Systems): http://news.ycombinator.com/item?id=2752284
BTW, I live 3 blocks away from you in Herndon. Pretty small world!
I just tried to buy a domain but can't fill out the form.
The commonly named alternatives seem (all for .com): Namecheap $10 Name.com $10 Moniker ??? DNSimple $14 Gandi 12,00 € (~ $17) Joker.com $12.80
Name registration is a commodity. I go with the cheapest provider.
if you register the domain with them, a standard ssl cert is included. Not sure if they issue certificates if the domain is somwhere else.
https://github.com/ioerror/duraconf/blob/master/startssl/REA...
If you're geeky enough to want your own ssl cert then you're geeky enough to root your phone & install CyanogenMod.
GoDaddy doesn't take a month off the length of the cert. They do start sending you reminders 60 days ahead that say your cert needs to be renewed in 30 days, but you get your full extra year. I've had the pleasure of doing this dozens of times for our certificates, the last thing we buy from GoDaddy after moving our domain business elsewhere.
All profits come from cross-selling, up-selling, and shady tactics.
A registrar that has sold 1 million domains at $10/year price, and does nothing else, is one that will make at most about $25,000/year in profit max after various costs (reg fees, support, etc), but more likely will be in the hole.
I stopped blaming GoDaddy a long time ago. This is just the nature of the game.
But the point here is GoDaddy by default puts all your services on auto-renewal. I am a bit paranoid over what goes on in my accounts ( especially PayPal) so i had disabled the auto renew when i saw it.
Talking about price hike, thats a marketing strategy. You usually don't get coupon codes for renewals ( if you do get, those are usually for bulk renewals ). These service providers always lure you to register at special prices so you stick with them forever and in this case it auto renewed :\
About the cert. expiration, that seems a bit odd but better talk to GoDaddy Support, they would help you out.
I'm not saying GoDaddy isn't shady. And they certainly are aggressive with their auto-renew policies. Heck how do you think they afford Superbowl ads and Danica Patrick at the prices they charge :) But the experience you described doesn't sound like a scam to me.
All this fee does is list your domain name or something similar in a GoDaddy ran business directory -- useless.
It's an extra charge they hope you don't notice, and it's only added to your cart when you add Whois Privacy protection.
You need to remove it from your cart afterwards.
The trick with GoDaddy, don't check the box to leave your credit card with them. You'll then have to manually renew all services and you never run into the risk of forgetting to uncheck some auto-renew option...
All insurance companies work the same way, try hard to get a new customer, milk them dry on the tail end because they are too lazy to search out a better deal.
Can we agree the "auto-renew" was not scammy? They didn't rip you off a year. Just reminding you 60 days early as they should.
Can we agree its not shady or unethical to charge different prices for 1st year versus a higher price for subsequent year renewals? Or different prices for different people, in some type of A/B test? Everyone does that. Even amazon.com shows different prices to different people.
Can we agree their customer support was really helpful to you?
So what's the problem exactly?
If you raise prices, you need to do your due diligence to make sure your customers are aware they're paying more. This kind of a price increase should really be opt-in rather than opt-out.
I guess they're all the same.
Gandi has been nothing but ethical in my dealings with them.
You don't have to deal with the abuses of the godaddys of the world, you just have to be willing to pay a bit more to support companies that aren't out to fuck you over.
Yes, it's a scam. The fundamental basis of a contract is a meeting of the minds. If people think they are buying a cheap thing and then it turns out to be expensive, then there wasn't a meeting of the minds.
It happens to be a legal scam, but that doesn't make it much better.
It do not offer strong encryption and do not do personal identification (obviously - it is free), but it is very cost-effective solution to have https:// on your website to prevent eyes droppers sniff traffic.
(not sure if it is enough for e-commerce, like google checkout tho)
Now you have no excuse to not have https:// in your website where people enter their passwords =)
Godaddy can be insanely cheap if you never auto renew and always manually renew with discount codes.
Though yes you need to get off Godaddy. As do I. Just waiting for a little more revenue from my site to move to Rackspace Cloud :)
Except that's nuts -- many of their customer's certs would lapse before they renewed. That's so bad that most sites should even put up with the extra 30 bucks to reduce their risk.
Pay the protection money, get a string of bits which cost the vendor nothing to produce. Or choose between zero security or users' browsers whining about "self-signed certificate" every time they visit your site.
My requirements for hosting are always 'Anyone but godaddy."
This times 1000
I experienced this exact same issue. I was pretty pissed to say the least but I called, got a human in about 60 seconds, and they refunded me as well as told me how to disable auto renew. I see no problem here.
Really, you don't see a problem with their "better ask forgiveness than permission" tactic?
uh, isn't that what PG and all the other people here constantly say is what you should do in business?
If I'm wrong, please include a few citations and I'll admit it.
"It's better to ask forgiveness than permission" is not a universal truth to be applied to every aspect of startups/tech work. It is often a good idea when there's a lot of bureaucratic red tape and/or you need to get approval from other people about things. This is a very different situation: you're charging your customers ~4x more than they originally paid for something automatically. Are there other companies that do this sort of thing? Sure. Maybe it makes sense financially, but it's not a good way to treat your customers.
But, I guess that makes me a bad customer from the point of view of an investor. There are plenty of people who will just take it, and I can certainly see why investors would prefer to focus on those people.
It's also important to note that not everyone in the community shares similar standards. Hell, over time the same person might not even have similar standards.
Three problems: 1) You had to notice the price change. If you have never not noticed anything, then you might have gotten taken. 2) You had to have the will to object. Willpower is a limited commodity. Is vendor bullshit what you could best be spending it on? 3) Your time is worth something, and GoDaddy just wasted it because they can make more money that way.
At my company, our rough rule of thumb is that a technical person's time is worth $250/hr. (We don't pay them that much, but we care more about opportunity cost.) Even if GoDaddy's shenanigans only take 10 minutes, that's still $41.67 lost. And that's not even counting the fact that next time I do something with them I have to spend time figuring out how they're going to try to cheat me.
Dealing with asshole vendors is rarely worth it once you take everything into account.
Are there any alternatives for EV certs that are not a ripoff?