neo wrote:
Ox- wrote:
I use StartSSL for small un-important sites. Free is a great price and there's nothing wrong with the certs. I just wouldn't use them for security critical sites because StartSSL has been compromised in the past.
I think a few of you guys misunderstand how the whole system works. In order to impersonate your web site to the clients, all I need is a certificate for your web site issued by any of certificate providers. In other words, if I can compromise StartSSL, than I can impersonate your web site, no matter where you got your certificate from.
Correct, but (usually) a compromised CA is removed from root certificates. This, in affect, revokes your cert. I say usually because StartCOM seems to be an exception. I think they take security seriously, and I wouldn't even be surprised if they are more "hardened" than most CA's, but it still makes me hesitant to use them for a high security site.