Hacker News new | ask | show | jobs
by makmanalp 5302 days ago
http://www.theregister.co.uk/2011/06/21/startssl_security_br...

Yeah, fuck that. Like hell am I going to use a free CA as suggested. They have no incentive to keep things secure or in working order at all.

Great article otherwise though!

3 comments

That doesn't really follow.

"The hackers behind the attack on StartCom failed to obtain any certificates that would allow them to spoof websites in a similar fashion, and they were also unsuccessful in generating an intermediate certificate that would allow them to act as their own certificate authority, Nigg said in an email."

As opposed to the Comodo breach where the attackers successfully managed to get fake certificates for several high-profile sites.

They're not a free CA. They're a business that sells certificates, and just so happens to also give out certain types of certificates for free.

They have just as much incentive to secure their systems as any other CA. Their reputation is just as important to them.

It doesn't matter which CA you use. If your CA, or any other trusted CA is compromised, you're affected exactly the same.

Ha fair enough, and thanks! One problem with the CA system is that (as far as I understand) it really doesn't matter whether you choose a particularly secure CA or not - you're as vulnerable as the most vulnerable CA. That's why something like public-key pinning is important.