Show HN: Snitch.io – SSL auditing and alerting
snitch.io
snitch.io
That said, I wouldn't pay for a service like this from a random person, I'd have my registrar do it (MarkMonitor or similar -- that's why they're paid the big bucks).
Can I ask why you wouldn't pay a "random person" as you say - since this information is by definition public?
Can you tell me a bit about your experience using MarkMonitor to do this?
For my personal set of servers (some 25-30, with ~50 SSL certs), I have Nagios for monitoring them plus calendar alerts, SMS alerts and sane cycling (everything expires in the same month).
My employer is an intermediary CA, they can issue their own certs but I've worked with people who use Markmonitor. As part of buying your cert through them is they worry about making sure your domains stay protected. They'll call you, text you and even mail you reminders. And they have a proven track record dealing with companies that are collective worth trillions.
In an old job for a mid-level bank, we had many behind the scenes (never showed up as a green padlock in any browser) integrations that would quit working when certs expired, frequently ones that we didn't purchase or control.
At the time, it was definitely worth it to me to get some notice before that happened. And it can be easier to plonk down a credit card than work though internal processes to have nagios (or patrol express, <shudder>) do the monitoring. It's the same thing that makes pingdom valuable.
CAs won't alert you if someone breaks into your server and replaces your certificate. They won't alert if you if you accidentally push a config change and start serving the wrong certificate to customers... And they certainly will not alert you if you are using a revoked certificate in production.
I've bought multiple certificates from different reputable vendors - I only ever got one Heartbleed notice. (This pattern repeats itself)
Many shops don't have a dedicated admin / webmaster auditing their certificates and even those that do have had public issues (Akamai, Apple, GitHub, Stripe...etc)
The value in a service like Snitch is that we worry about your SSL certificates. Many people don't have the interest or time in rolling their home grown monitoring of this stuff...
You have valid points, my advice would be to make that part of the message as clear as possible. as a sys admin I could be a potential customer but then again, I already have to worry about certs I implement.
I'd love to chat more out-of-band - would you mind emailing me (this username at currylabs.com or gmail.com)
Early bird special: Renew your <website> to save
Keep <website> Secure, renew your SSL
Last chance to save: Your <website> is expiring
ACTION REQUIRED: Your SSL needs attention
FINAL NOTICE: Your SSL expires tomorrow
LAST CHANCE: Your SSL expires today
SECURITY ALERT: Your <website> may not be secure
ACTION REQUIRED: Your SSL needs attention
SSL EXPIRED: Renew to rescue
CALL US: SSL for <website> is expired
Your last SSL expiration notice for <website>
I was actually relieved when they finally stopped mailing me...We've been working on this for a few months and would appreciate any feedback - thanks!
If anyone wants to email me directly it is my username at currylabs.com or gmail.com
PS: If you are an Open Source project we offer free subscriptions.
Have >25 certs? Add this check to Nagios: http://exchange.nagios.org/directory/Plugins/Network-Protoco...
Saved you $200/month :)
These are very different services.
Voodooalerts requires you to place JS on your page. Because of this I am sure they cannot run the full suite of audits that Snitch does.
The full paid version of Voodoo Alerts requires JS to be installed but that is for RUM alerting
Edit: you're right about it not doing everything that snitch.Io does, but saving $10 a month on simple alerting sounds good to me
I signed up for a free account on VA and put in a site with a revoked SSL certificate. It has not generated an alert. It has been over 12 hours. It is still prompting me to insert the JS on my site, by the way.
As to your second point. Snitch isn't simple alerting.
It runs a full range of tests on an SSL certificate: checking for expiration, checking for revocation, checking that all of the intermediate certificates have not been revoked, checking the certificate is valid for the domain (including SNI), checking that the certificate isn't signed with a weak algorithm such as SHA-1 that Chrome is about deprecate, checking that the certificate has not been changed (incorrect server config, malicious intent...)
Snitch is not targeted at people who just need to know if their site is up or down.
If you are are a business and users browsing to your site get a big red warning in their browser because your SSL certificate is expired/revoked/weak/misconfigured - that is a problem and you lose money. That is what Snitch is addressing.
In fact I'm probably breaking terms mentioning it...
I was wondering if you were also going to mention that you are VoodooAlerts' founder?
I, personally, think it is poor form to advertise features that don't exist while pretending to be a customer of VoodooAlerts.
I wish you the best of luck with VoodooAlerts!
Good luck in this field, it's competitive :)
That is definitely on the roadmap and will go out soon.
Where are you incorporated, if? The terms says nothing about it. Who is my contract party when I signup?
We're in Oakland, California.
Not a big fan of pricing plans that mix volume with features, always makes me feel I'm being screwed when I only need one or the other. (Even though I might be perfectly fine with paying the same amount if the pricing structure was different.)
Definitely something we'll consider. Email me if I can help out in any way! hn username at currylab.com / gmail.com
And only 25 for enterprise? Our midsize business is currently using 416 certs.
Unless those include SMIME certs, but still...
We do more than you can do by scripting OpenSSL. For example: as far as I know OpenSSL won't warn you if your certificate is signed using SHA1 - one of new several features we're about to push out.
More generally scripting OpenSSL requires knowledge, time and infrastructure many people aren't able or willing to invest (what is monitoring the monitor...)
Their monitoring includes SSL cert validity, among many other things.
In any case, very nice execution on the front end. Good job.
We're constantly improving and adding extra checks.
Does DigiCert provide any guarantees on how often they monitor your certificates? Do they offer any alert mechanisms other than email? Do they let you monitor certificates that are on your critical path but not necessarily ones you own (partners...etc)
You also mention cost..but since you are not paying them you are not their customer - you are their product.
Snitch is clearly aligned with customers since our goal is to help you succeed at securing your site. Our goal is to make it easy for you (site owner) to do the right thing and provide a good experience to your customers.
though i do wonder if "this is a feature, not a company"?
We're constantly improving and rolling out new features. We're confident that over your question will become less of a question :-)