Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To clarify: DO NOT DO THIS.

1. Never give your private key to anyone

2. Especially not if it is sent over an unencrypted connection (the site doesn't even use https)

3. Don't. Just don't.

This is either the weakest attempt of the NSA to collect private SSL keys ever, or this company actually has zero knowledge of the product they're selling and shouldn't be trusted with your site's security



Never attribute to malice that which is adequately explained by stupidity.

This just seems like some newbie programmer was like "hey, wouldn't it be cool if"... and built themselves a weekend project that they released on the site.

Obviously it's terrible for a site that sells SSL stuff, but concluding that this is the NSA is pretty hugely premature.

edit: Duh, didn't pick up on the sarcasm. In my defense, the parent text was way more vague at the time. :)


To be fair, I'm pretty sure he had his tongue firmly in his cheek. But point well made. Whenever this point comes up I think of a scene from 'the cube', is it a massive conspiracy or utter incompetence combined with some kind emergent process?


Or likely the NSA firmly has their tongue in their cheek teasing and scaring us because they can.


I love how suddenly the NSA is the only entity out there who has an interest in private keys.


I think it is pretty hard to argue that they are not one of the most aggressive entities doing this.


at least we know that's it is the most interested, funded and staffed to do it.


No, they're just the only ones dumb enough to get caught ;)


Nobody else got the subtle sarcasm, but I did. No worries, man. But seriously, if it was the NSA, I like how quick everyone is to dismiss the notion!


There are thousands of us who see the subtle implications of comments, and roll our collective eyes at the knee-jerk, replies from people who missed it. The proclivity for this type of boring, predictable reply is the main reason I don't post very much. I tend to get the "you are either stupid or a jerk!!" replies myself.

(Rest assured, it's the latter, not the former.)




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: