TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Where should someone buy a SSL certificate?

22 pointsby mihokabout 11 years ago
There always seems to be talk about some SSL cert service (VeriSign) that has been hacked or gone under. I&#x27;m trying to buy my first SSL certificate and there are so many options out there that its hard to know which one, what are the risks? Is any certificate authority okay? Will self signed certs be good enough?<p>Clearly the issue is the man-in-the-middle attack, which I have a high level understanding of, and makes every CA susceptible to the same attack if they are compromised.. but are there good CA&#x27;s that people have had experience with? Is it less safe to get a wildcard cert than individual certs for each domain?<p>Thanks HN

6 comments

sillysaurus3about 11 years ago
If you&#x27;re worried about certain governments MITMing you, the answer is that it&#x27;s hopeless to rely on SSL to provide protection.<p>I don&#x27;t know a good recommendation. I just wanted to clarify that SSL provides no protection in that particular case.
评论 #7462256 未加载
jipy9about 11 years ago
I used StartSSL class 1 certificate for my app (unherd.co). Its free and valid for one year. Here is a good guide that might be of help - <a href="https://konklone.com/post/switch-to-https-now-for-free?hn" rel="nofollow">https:&#x2F;&#x2F;konklone.com&#x2F;post&#x2F;switch-to-https-now-for-free?hn</a>
评论 #7470865 未加载
评论 #7466981 未加载
fskabout 11 years ago
My domain registrar (namecheap) offers SSL certificates cheap.<p>All you need is for your domain to show up with the little special icon in the browser when you use https. Other than that, it doesn&#x27;t matter. Get the cheapest one that browsers recognize.
评论 #7474690 未加载
clinton_sfabout 11 years ago
StartCom&#x2F;StartSSL thwarted a recent hack attack, according to: <a href="http://www.informationweek.com/attacks/how-startcom-foiled-comodohacker-4-lessons/d/d-id/1100043" rel="nofollow">http:&#x2F;&#x2F;www.informationweek.com&#x2F;attacks&#x2F;how-startcom-foiled-c...</a><p>Their due diligence on verifying who is requesting the cert probably helped; but I&#x27;ve seen some people complain that it&#x27;s not a quick&#x2F;easy process: <a href="http://danconnor.com/post/50f65364a0fd5fd1f7000001/avoid_startcom_startssl_like_the_plague_" rel="nofollow">http:&#x2F;&#x2F;danconnor.com&#x2F;post&#x2F;50f65364a0fd5fd1f7000001&#x2F;avoid_sta...</a>
ch215about 11 years ago
You get a standard SSL certificate free for a year with domain names at Gandi.net. I think I&#x27;m also right in saying transfers are included. Can&#x27;t really vouch for their security but from what I have read the company&#x27;s &quot;no bullshit&quot; approach is right up my alley. The riseup.net collective recommend them too.
评论 #7465747 未加载
评论 #7477706 未加载
ancardaabout 11 years ago
&gt;Will self signed certs be good enough?<p>For public consumption, no. For anything internal, yes.