Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
"Yes. For everything."
Rather than perseverate about how retarded this question is, I'd just answer it clearly and move on with my life. -
No.
We require TLS1.2 minimal, setup with a nontrivial eliptic curve, and gcm minimal. And 4096byte valid 2y certs, signed by a good known CA.
SSL is not secure enough for us. -
@HiFiWiFiSciFi The concern I have in a vendor asking this question... is that it shows me they don't focus on security in the first place.
-
"What problems do YOU see with that question?"
The vendor has customers that answered with "SSL? Nah...if I can't pronounce it, I don't need it." -
Was that actually a question about whether you want one of their pricy snake oil certs instead of getting yourself a Let's Encrypt one for free?
-
@Oktokolo No fucking clue yet, it showed up in the onboarding survey we had to send back. Also, this vendor wasn't my choice.
Related Rants
Email from vendor: "Will you require SSL?"
WTF. So many problems with this question. Am I alone in my frustration? What problems do YOU see with that question?
rant
ssl