Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The only identity verification done by the vast majority of CAs is that you must be able to reply to email sent to one of a few email addresses at the domain you are trying to get a cert for. There have even been cases where people have gotten certs for free email providers just by signing up for one of those email addresses.


Aye, which I assume (but as I've not tried it I can't say for certain) is essentially what they do for the free certs. So they would be no less useful as encryption only certificates than the cheap paid-for ones, assuming the level of acceptance by browsers is adequate for the needs of the site using the cert.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: