$1.99 SSL certificates offered by Namecheap
namecheap.com
namecheap.com
I love them but after they "updated" their design, every time i try to buy/renew domains I'm having nervous breakdown :
* It's impossible to find what I'm looking for.
* Facebook style panel menu ( I don't know how they calling it ) makes only sense on tablets/phones, on desktop it's just pain...
* New design uses screen real estate really bad. My screen filled with big buttons, big texts and senseless images... Information that I'm looking for is lost between them.
* Gray text on white background... Not so readable...
Curious - are you still encountering those issues? That may be from the initial launch in January but we haven't heard about this from others. We definitely appreciate the feedback though.
Tamar, Namecheap's Community Manager
The only other issue I've noticed is a large disconnect between the new aesthetic of the landing page (which I quite enjoy) and the yet-unchanged UI of the dashboard.
Teddy, head of product @ namecheap
I don't know why others didn't reported UI issues but in my case : Opening a support ticket didn't seem to be a good option, it was an UI issue and wasn't related to billing or some technical problem.
I'll check ssls.com
Biggest downside is that they don't support many advanced DNS features such as Anycast, GeoDNS, and DNSSEC.
The Namecheap redesign is also a bit messy. They have a mix of the old design plus some new interfaces. Also, we've been waiting for ages for them to implement 2 factor authentication and when they finally do it, it's an SMS only solution that's no good for those that are without constant coverage or need to travel outside the country.
http://www.uniregistrar.com (two-factor, free privacy, cayman islands)
http://www.easydns.com (two-factor, canadian)
http://www.pairnic.com (super lock, requires id to unlock if you enable it)
http://www.namebright.com (two-factor)
http://www.name.com (two-factor)
http://www.gandi.net (two-factor)
Security is really important for your name so make sure you go with someone who offers some sort of two-factor or extra security lock.
Also, http://startssl.com give SSL certificates for free and they're accepted by all major browser vendors. It's hard to beat free
Based on pricing ($9.99/.com) and a growing irritation with GoDaddy, I finally moved my domains to Dynadot:
They have a (custom) 2FA app and 2FA SMS. BTW this friend referral https://www.dynadot.com/?s9N6j7d9G8B07i73 gives you & me $5 after purchase.
There are some cheaper SSL-certificates, but they fairly low price, and with good UI/support.
Their regular prices aren't expensive -- $9.78 for Comodo PositiveSSL and $11.90 for Geotrust RapidSSL. But it would be nice to have a moderate recurring discount instead of a one-time break.
How do I choose? What happens when I exceed a limited amount of traffic?
A) Maximum insurance offered
and
B) Making sure they do not miss out on $$$ from a big customer who signs up for $5 certificate
- Warranty amount ($10k on the PositiveSSL certificate)
- Single domain
- Only domain validation
Larger e-commerce stores may need wildcard or multiple domain certificates, a higher warranty amount, organization, or extended validation (the green bar in the address bar). There isn't any inherent limitation to bandwidth or traffic with these certificates.
Look at Comodo for instance. To collect their insurance policy they have to issue a certificate to someone who isn't you, and then that certificate has to be used to steal someone's money. In that case they may actually already be liable, but they're saying they'll just give you up to $10,000 to deal with it.
> We believe it is important to protect the end user. If we were to mis-issue a certificate to a fraudulent site, that fraudulent site has an SSL link with an end user and as a result of this the end user loses money the end user had what they thought was a "trusted session". Comodo should never have provided the fraudster with the ability to engineer this situation we therefore have insurance to pay the end user for any losses that they may incur. Why would we do this?
http://www.instantssl.com/ssl-certificate-support/ssl_faqs/s...
If any of them goes rouge, you're still on the line, whoever you buy from.
But a wildcard is not difficult for anyone to implement- it is literally just adding an asterisk to the host name in the cert.
Nothing beats the profit margins of the SSL industry.
I remember breaking a piggy bank to secure a single domain back then, it was around $99+.
Then dropped to $49.99 and now it's $9.99.
With SQL Server, you can get the Express Edition for $0 or the Enterprise Edition for $thousands. But to build the Enterprise Edition, they actually compile it from the same source code without some #defines that enable various Express Edition data size limits.
They do less work yet charge you infinity times the price. Now that's a ripoff!
Maybe you can just ignore them, or maybe you can't. Anyway, it's not a no-brainer.
It's pure profit/rent seeking. That same $25 applies regardless of the reason. OpenSSL compromised? Fuck you, pay me. Miskeyed the CN? Fuck you, pay me. Want a different type of cert for the same domain? (XMPP instead of web?) Fuck you, pay me. You get the idea. It doesn't cost $25 for a few byte fingerprint to be automatically appended to the end of a file.
In some of these cases they don't even need to revoke the other cert, just delete the erroneously created one from their system because it was never used anyways!
Never mind the fact that their UI would have been an embarrassment a decade ago, and they absolutely require certificate-based login to get into the UI, which is a huge PITA.
Have you seen the article with Cloudflare and Globalsign's CRL?
Also, if you read the Namecheap promotion page, they explain that they are donating $0.5 to Fight for the Future for every purchased certificate.
Yes, but you can donate almost 4x that with the money you save. It's hardly a reason to choose Namecheap.
I always found those "$x from your purchase will be donated" annoying. How about you let me keep my $0.5 and I'll donate it to whoever I want? I might not even want to support the organization they chose!
I don't trust Fight for the Future. Too many times I've gone to the page for one of their causes, and found a prominent form asking for my email, sensationalistic claims about the issue that included outright factual errors, and no link to the actual text of whatever bill they were up in arms about.
Why not donate to the EFF instead? The EFF is occasionally wrong, too, but I never get the impression when the EFF is wrong that they are deliberately being wrong in order to stir up more interest. Also, EFF donations are tax deductible.
So yeah, $0/year, but definitely not "no bullshit."
Please encourage other sites, companies and services you use to join too: http://resetthenet.org
Also:
"Neither self-signed nor CA-signed certificates are securely authenticated, so the padlock is completely misleading."
>Neither self-signed nor CA-signed certificates are securely authenticated
CA-signed certs are authenticated by the certificate authority. You cannot trust that a website presenting itself as google, is google, without any prior information. But google can get a certificate issued by a ca, and you can trust the ca.
Why do you think ca signed certs are not securely authenticated?
It sounds like you're thinking about running a blockchain node locally. DNSChain is exactly fixing that issue. It is even more efficient than the current system.
> A-signed certs are authenticated by the certificate authority.
Incorrect, CA-signed certs are authenticated by any certificate authority.
> Why do you think ca signed certs are not securely authenticated?
Your answer is in the link that I posted. Here it is again: https://news.ycombinator.com/item?id=7826503
Kinda sad. We deserve a better internet than this. Use the blockchain for free and actually secure certificates: