Hacker News new | ask | show | jobs
by LordIllidan 4287 days ago
Given that ssl certificates are free nowadays (e.g. https://www.startssl.com/), how was this not an issue before?
1 comments

startssl is convenient but they force you to pay to revoke your certificates. I've heard rumors of startssl being close to getting on blacklists due to this behavior -- tons of certs were never revoked after heartbleed, for example.
Why would a phisher want to revoke their certificate?