There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.
There are not any significant costs to obtaining SSL certificates, so a new CA is hardly likely to change the SSL landscape at all.
StartCom's $60 wildcard is the cheapest I've ever seen. I'm impressed with StartCom's model overall, and it was a great inspiration to me with the SSL co-op. I feel like the more diversity in approaches there is, the better off the CA ecosystem will be. If nothing else, another voice for sanity in the relevant standards bodies (CA/Browser Forum, for instance) can only be of value.
It is $60 for as many as you need, for multi-name certificates too, as long as (presumably, I'd need to recheck the smallprint to remind myself) they are all for you and you aren't signing certificates for others. The fact that they are signed for two years instead of one is handy too.
I've recently signed up for that to get some wildcard+multiname certs mainly for convenience (not having to sign a new cert for every tld/sub-domain combination), and not have s wildcard cert for my vanity domain and one for all the names associated with a project that I'm trying to work on (.domain.net, .domain.com, .domain.co.uk, .domain.uk all in one certificate). Remember before considering this though: there is some extra security in having separate certificates for everything instead of a huge wildcard-for-all arrangement. If you PK for a combined wildcard certificate leaks from any one location any security problems that causes affects every location you have that one certificate in use, so I am trading off a convenience gain against taking a little extra risk.
Well, it'll slightly increase the attack surface against the CA model, so there's the (probably very small) chance that something will go wrong and it will introduce a massive (temporary) hole in TLS, since CA-based trust has a "weakest-link" failure model.
Which is logical. Running a CA and getting the root certificate into the right places is not cheap. Unless someone with money (e.g. Google, as they do with their CDN) decides to provide this service for free some money needs to be earned.
All of Google's free services (CDN, DNS, Chrome, etc) are centred around improving the experience of using the web, so more people use it for longer (and, hopefully, do more searches with Google and/or visit more webpages with AdSense ads on them). I'm not sure how more SSL-secured traffic feeds into that, exactly, but if anyone at Google wants to talk sponsorship, I'm all ears...