Now that's honest.
The only time I didn't use them was a weird edge case recently where I needed a multi-domain certificate, and NameCheap did not support those, so I purchased direct from GeoTrust.
I ended up getting an EssentialSSL Cert from namecheap.
It is even totally unimportant if your provider is "insecure". If any of the commonly trusted CAs is hacked it affects the security of your service as well as if it's the CA you use.
Therefore I would go with StartSSL (https://www.startssl.com/). They are trusted on all important plattforms, are free for one subdomain per domain and very cheap otherwise. You only pay the verification of your identity, unlimited domains, wildcard etc. then. I haven't seen any cheaper one. You might get some competitive prices if you combine the use of single subdomain ones through SNI, but I wouldn't prefer that over a inexpensive wildcard one.
What is the worst that can happen? If the revocation servers go down, the browser just shows a small warning symbol, but everything still works. If your CA gets hacked and untrusted in common browser, you have to buy a cert somewhere else ... this is the risk of every CA and a new cert is just minutes away ...
There is no way to determine who is more secure against hacks etc. If they are trusted where you need them, they are all equal.
StartSSL wants $200 for two years, additional ones cost $50 then. Haven't seen anything cheaper.
The cheapest SSL options there ($20 and under) offer NO verification of the applicant of the certificate. Thus, you could be a scammer for all they care, as long as you control your site (even a phishing site) they've give you the "domain validated" certificate.
Stick with either EV (green bar, extra assurance) or a high-assurance only shop like DigiCert, Symantec, Entrust, or GlobalSign. It'll also show your users you care about trust and identity assurance online.
Your logic is wrong here. It is totally unimportant which CA you use, as long as any commonly trusted CA just checks the domain ownership using a mail address. A man-in-the-middle could simply replace your cert with that one and the user gets no warning.
> Stick with either EV Green/blue bars are a remarkable feature the user sees and might give trust. Those one are already available for $200 for 2 years. But I'm not sure if a user would realize that a MITM attack has removed the color. He wouldn't get a warning as long as any valid cert is still used. See my response above.
> or a high-assurance only If you need assurance, then yes. But a normal user doesn't care of that. And you should then also check the exact terms and conditions as well as other assurance services.
Could you explain why that matters for the site owner?
Google issues its own, GitHub uses DigiCert(http://www.digicert.com), Hacker News uses Entrust (http://www.entrust.net).
In general, Verisign (http://www.verisign.com/) will be the most expensive and presumably the most widely supported, but there's no need to pay up for it when DigiCert will work just as well.
https://dl.dropboxusercontent.com/s/x7q6tme55gerkql/2013-05-...
after having been a reseller for geotrust for years, lately, i ended up buying all my certificates from namecheap. the namecheap end user prices are even lower than my rapidssl reseller prices...
a. whether you want a certificate for a single hostname, several hostnames, or a wildcard;
b. whether you want extended validation or not; and possibly
c. what country you're based in.
Perhaps other factors as well.
How is that relevant? I would also say the targeted plattforms (which browser, OS) are the most important point.
Diginotar