Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 05:30:35 PM

Login with username, password and session length

669084 Posts
71141 Topics
145753 Members

Latest Member: lostcoast

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Business / Enterprise Security Products & Services
| |-+  Digital Certificates
| | |-+  SSL Certificate
| | | |-+  Facebook app's SSL, and why are trusted SSL cert's not free?
« previous next »
Pages: [1] Go Down Print
Author Topic: Facebook app's SSL, and why are trusted SSL cert's not free?  (Read 9375 times)
J2897
Comodo's Hero
*****
Offline Offline

Posts: 333


Limted User Account Enforcer


WWW
Facebook app's SSL, and why are trusted SSL cert's not free?
« on: September 05, 2011, 10:35:52 AM »

I remember reading a thread on here a long time ago whereby Melih was pretty much laughing about SSL cert's signed by CA's, and then he explained how EV cert's were different. He was basically saying that any criminal can display a yellow padlock.

Question:
So my question is, why aren't trusted (by browsers) SSL cert's free?

The reason I ask is because I'm currently building a "Security Awareness" Facebook application in PHP which will show Facebook users exactly what data they may be putting at risk when they're about to install a Facebook application. So I need SSL for security, but I don't want to pay for security: I'm not asking for a freebie. I'm asking for general advise.

  • I plan to host my Facebook applications on my local VMware ESXi server.
  • The "Security Awareness" Facebook application data won't be stored in a database.
  • Facebook are forcing app' developers to use SSL by 1st October this year.
  • Self-signed cert's may not be sufficient.

I was going to post this on the Facebook forums. But I thought, "Maybe I should ask the experts?"  Grin

If I have to pay for security, my Facebook application development attempt ends 1st October this year.
Logged

J2897
Comodo's Hero
*****
Offline Offline

Posts: 333


Limted User Account Enforcer


WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #1 on: September 06, 2011, 06:28:05 PM »

Very scary/interesting blog post: [ Link ]

Unfortunately: [ Link ]

It seems that, if you want security, you have to pay the rich; even if you're not a criminal.
« Last Edit: September 06, 2011, 06:31:18 PM by J2897 » Logged

Sal Amander
Comodo Staff
Comodo's Hero
*****
Offline Offline

Posts: 610



WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #2 on: October 22, 2011, 10:40:46 AM »

It seems that, if you want security, you have to pay the rich; even if you're not a criminal.

Someone has to pay the employees.  They don't work for free now. Roll Eyes
Logged
AyeAyeCaptain
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 619



Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #3 on: October 22, 2011, 12:14:48 PM »

Someone has to pay the employees.  They don't work for free now. Roll Eyes

Exactly, people who work for Comodo have family to feed, Comodo give enough away as it is for free and in turn doing so dedicate a lot of resources/money to the cause. You can't expect them to also offer the revenue side of the business for nothing surely?

Don't take offense OP, surely even you can understand this?  Angel
Logged

Film Scum Remake
Comodo: Where is your Tool
User: What Tool?
Comodo: This f****** Tool.
Protect Yourself With Comodo...... lol
J2897
Comodo's Hero
*****
Offline Offline

Posts: 333


Limted User Account Enforcer


WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #4 on: January 16, 2012, 11:25:20 AM »

any criminal can display a yellow padlock
As long as they pay the SSL bribe of course.

You should also be aware that I wasn't referring to EV certs. And nor was it me who mentioned Comodo staff. I meant all CAs who sign DVs autonomously.

Luckily, Facebook allows self-signed certs. So you can host your Facebook app's locally. Just tell your users to be aware that their browser may warn them that the site's not "trusted".
Logged

J2897
Comodo's Hero
*****
Offline Offline

Posts: 333


Limted User Account Enforcer


WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #5 on: January 16, 2012, 11:42:27 AM »

Watch from 2:05. The video has more dislikes than likes, yet everything he says about DVs is right (in my opinion)...
http://www.youtube.com/watch?v=MAi7xdCBgeE
Logged

Melih
CEO - Comodo
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 12949



WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #6 on: January 16, 2012, 01:29:31 PM »

Watch from 2:05. The video has more dislikes than likes, yet everything he says about DVs is right (in my opinion)...
http://www.youtube.com/watch?v=MAi7xdCBgeE

all the dislikes are most likely from our DV competitors Smiley
Logged

J2897
Comodo's Hero
*****
Offline Offline

Posts: 333


Limted User Account Enforcer


WWW
Re: Facebook app's SSL, and why are trusted SSL cert's not free?
« Reply #7 on: January 16, 2012, 06:45:09 PM »

all the dislikes are most likely from our DV competitors Smiley
You could punish them by giving out DVs for free.  Grin

This could also solve the DV problem. The general consensus would likely become that the "yellow padlock" just means that the connection is secure; and nothing more...

I think it would then be easier for IT people to explain the difference between DVs and EVs.
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.047 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com