Show HN: Simple SSL Scanner
expeditedssl.com
expeditedssl.com
You only pass 4 out of 5 of our own test :P.
Though, you're probably right that I should upgrade it sooner (see, the scanner is working and forcing people to upgrade - including myself).
Further, though this isn't really explained well, is that there are some optional security elements like http->https redirection, HSTS that are just blips on the SSLLabs report that I think should be of more importance.
The Simple report was meant to be a sort of executive summary, not a deep dive.
Like it or not, many times non-technical people are in charge of approving technical budgets and requirements.
Also where is firefox's HSTS cache? Can I see it? It would be interesting.
You can remove HSTS cache per-site by selecting "Forget About This Site" -- HSTS is still cached in any currently opened tabs though
So, for example, after visiting Hacker News once, the next time you type "news.ycombinator.com" into the URL bar, your browser will simply go directly to "https://news.ycombinator.com", rather than making the initial request to "http://news.ycombinator.com" as it usually would. This ensures that all future communications between the client and server are over a secure channel.
Becoming an intermediary is hard and expensive because we want the CA system to be as secure as possible. And some security measures and auditing takes money
By and large, the process prevents fraudulent certificates and at the cost of $5/y, I'm not horribly upset.
Would the world be a better, more perfect place with the CA system was organized differently? Maybe. But the likes of StartCOM are not the answer (predatory pricing is no bueno).
https://github.com/okTurtles/dnschainhttps://github.com/okTu...
also for some more background on some concerns with CAs see: https://konklone.com/post/certificate-authorities-are-actual...
I would love to see TACK implemented first.