Hacker News new | ask | show | jobs
by feld 4102 days ago
StartSSL has been on the naughty list for a while

They charge for revocation, so it negates the entire idea of a "free certificate" if you can't properly revoke them without forking over money. It literally breaks the entire idea of revocation.

This was made very clear when Heartbleed happened

1 comments

Revocation is pretty broken even without that. Instead of explaining why I'll just link this:

http://news.netcraft.com/archives/2013/05/13/how-certificate...