This seem legit...
trustico.ch
trustico.ch
1. Never give your private key to anyone
2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https)
3. Don't. Just don't.
This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security
This just seems like some newbie programmer was like "hey, wouldn't it be cool if"... and built themselves a weekend project that they released on the site.
Obviously it's terrible for a site that sells SSL stuff, but concluding that this is the NSA is pretty hugely premature.
edit: Duh, didn't pick up on the sarcasm. In my defense, the parent text was way more vague at the time. :)
(Rest assured, it's the latter, not the former.)
Me: I wanted to know more about your certificate key matcher isn't the private key always meant to remain... private?
Emanuele: Yes, it should. We offer the tool to help verify the correspondence SSL certificate it is lost.
Me: But it would be sent over HTTP and viewable to anyone along the network.
Emanuele: The page can also be accessed through HTTPS.
Me: I think it should be enforced. Also something like this should be done client side. Perhaps using crypto.js
Emanuele: OK, I will pass your comment to our General manager.
I don't think you've thought this through.
I haven't been able to access the site though, so I may be way off in my understanding of what it does.
I don't condone this at all, but if they're adamant about providing this service they should at least try and make it less damning than it already is.
The tool was made available for customers to legitimately check if the Private Key matched the SSL Certificate that was being installed - a common question and feature request from our customers.
However, upon review of the comments made in the internet community we have made a decision to remove this specific tool and to review all other tools that we make publicly available via our websites.
We also saw a heavy attempt to hack/abuse this tool over the past few hours, perhaps to look for exploits, an action I find absurd for those who make out to be security conscious.
I welcome any further comments on how we can improve our service and do hope that our actions to remove the tool today were prompt and satisfactory.
Zane Lucas General Manager Trustico Online Limited
What were you thinking? That's not a loaded question. I literally have no idea what was going through the mind of anyone at your company when it was decided to build this abomination.
Want to make sure that your bitcoin address works? Just send money to
1JqjU7zBvbhyrDFjtJG6xAwMm5BUVmtpau
and if you don't receive an error, you can rest assured that your bitcoin address works!
Watching with interest... xD
1PtQmxewNJWYeDUieM2cLqU9XcAoBEfWaQ
You send the money there, it sends you back the double amount.
... Wat?
EDIT: I am a dumbass, the terms and conditions are clearly facetious. Read them, they are hilarious in parts.
Also, the terms and conditions are fake too.
"If you read all the legalese up to this point (or just got there by random scrolling), you probably have noticed that this document is complete nonsense. [...] First, chapter 10 of Mary Shelley's /Frankenstein/. Second, a copy of some treaty."
Damn, this is becoming addictive.
- I cheated, I admit.
"Hello, the tool will be removed from all our websites within the next 30 minutes. Thanks."
http://www.trustico.ca/ssltools/match/cert-and-key-pem/check...
My personal opinion is don't use these guys; this is either a school boy error/complete incompetence or totally dubious.
Maybe it just says that for any and all inputs??
1. created a CA key+cert (selfsigned) 2. created a keypair K 3. signed the public key of K with the CA 4. uploaded the CA-signed cert and the private key of K --> "Your Certificate and Key match" 5. uploaded the CA cert (not the one of K) and the private key of K --> "Certificate an Key do NOT match."
that tool will be removed from all our websites within the next 30 minutes.
Trustico Online Limited
They were helpful but thank god I didn't buy a cert from them: this page is a terrible, terrible idea that erodes their trust completely.
http://www.trustico.ch/ssltools/convert/pem-key-to-der/conve...