Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's nice that this service is trying to make it easier, but why should anyone trust tinycert? How can I trust that tinycert won't issue certificates without my concert? Or sell my private keys to others?

The commands really aren't that complicated. You can (and really should) learn how to do this if you need to issue certificates.

Also, deleting CA's doesn't seem to work.



Thanks for the bug report. I'll look into that.

As for why to trust it... you won't know to trust me any more than a real CA. With a real CA you also only have their word. I've taken as many steps as I can to ensure that the private keys are not kept unencrypted anywhere where this is not needed (and they are only needed when signing something and when you request a download) and that the passphrase is in flight as short as possible.

While anything is theoretically possible with enough malicious intent, I've made the selling private keys or issuing certificates with your private key without your consent as exceedingly difficult as possible for myself.


Deletion is fixed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: