Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Safari (wel, the OSX Keychain) doesn't include StartCOM in it's Truststore -- which I'm pretty OK with. I revoke it from all my trsutstores


(a) That's not my experience. This site of mine is secured with a StartCom cert, and Safari has always been perfectly happy with it: https://mappiness.me

(b) Why? I understood they were among the better providers.


> This site of mine is secured with a StartCom cert, and Safari has always been perfectly happy with it: https://mappiness.me

My Safari can't verify the identity of that website. This is Safari 5.1.7.


Interesting, and a bit concerning. I just checked it on a friend's MacBook too, and that worked (Safari 6.0.5). Perhaps there's been a change at some point?


a) Well, if you setup your startcom SSL cert with the browser, that means you've been forced to add StartCOM to your truststores.

b) I simply don't trust them, particularly since they use a keybased auth system -- any compromised computer that was used to setup a startcom cert can download the private keys


a) True, but I set it up from Firefox.

b) I think it's moot whether this is better or worse than a password, but I'd probably pick the key-based system (which requires you to physically have my computer) over a password-based one (which might be hacked remotely).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: