Hacker News new | past | comments | ask | show | jobs | submit login

Would be more awesome if they offered free certificates and an API to renew them.

Right now enabling https is not a one-time investment, since a new certificate has to be requested and installed each time the old one expires.

Computers are supposed to bring down cost and automate tedious tasks, for https the opposite is the case.

It’s worth mentioning that https://www.startssl.com/ does offer free certificates. But without a paid account they last only a year and cannot be issued to wildcard domains, so you quickly end up with a lot of certificates that has to be manually renewed each year.

The SSL CA model is deeply flawed, so it bothers me that I have to pay into this broken cartel.

An effective social network for website trust, combining cryptographic assurances with trust networks that already exist, is my dream.

(Edit: Clarify that the SSL CA model is flawed for the Internet at large, but has many useful applications elsewhere.)

> Would be more awesome if they offered free certificates and an API to renew them.

If someone were able to do this and pull the rug out from under the SSL cartel overnight, that would be awesome.

Many "free" certificate services don't give reissued certificates for free, though, so if something like Heartbleed happens again, you might still pay a fee.

What about a kickstarter to subsidize SSL costs? Or how about one to buy a root CA and make it free?

There is already a community-driven CA: http://www.cacert.org/

The problem is that it's not only about money. You need to follow certain procedures or browsers and OSs won't include your root certificate.

I don't think anyone has confidence in CACert anymore. IIRC they bombed their internal audit...

They are free to get, but you have to pay money if you need to revoke that certificate.

Which you don't really need to. Sure it disables all the security, but if you only care about the speed boost/cover your ass part it is a non-issue.

Yes, you do. If there is another Heartbleed, your certificate is worthless if someone has the chance to grab it.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
