Hacker News new | ask | show | jobs
by agwa 4661 days ago
They're not broken; they're simply using cacert.org instead of a mainstream CA. From a business standpoint, that's a terrible idea for selling to the general public, but from a security perspective it's fine.

Incidentally, they sign their order confirmation emails with PGP. :-)