7 ms·
Comodo has filed for express abandonment of LetsEncrypt trademark applications
- deleted 10y ago[deleted]
- ocdtrekkie 10y agoIt's amazing how a bit of bad press can expedite such matters. :) Nice try, Comodo, better luck next time.
- nacs 10y ago"A bit" is a bit of an understatement. The Comodo issue was one of the most upvoted on both HN and Reddit. People immediately realized how much of a terrible company Comodo is and the negative feedback had to have poured in.
- criddell 10y agoEven if you forgive them for this, there's plenty of other reasons to dislike Comodo.
- Rantenki 10y agoThere: http://www.myce.com/news/comodo-ships-ad-injecting-https-intercepting-adware-worse-lenovos-superfish-75063/ http://www.myce.com/news/comodo-ships-ad-injecting-https-int... Sure: http://www.infoworld.com/article/2623829/authentication/weaknesses-in-ssl-certification-exposed-by-comodo-security-breach.html http://www.infoworld.com/article/2623829/authentication/weak... Are: http://dottech.org/10032/paying-a-price-to-use-free-software-the-dark-side-of-comodo-products/ http://dottech.org/10032/paying-a-price-to-use-free-software...
- AdmiralAsshat 10y agoEvidently the company realized they were fighting a losing battle, particularly after the CEO's disastrous response: https://forums.comodo.com/general-discussion-off-topic-anything-and-everything/shame-on-you-comodo-t115958.0.html;msg837411#msg837411 https://forums.comodo.com/general-discussion-off-topic-anyth...
- ars 10y agoI give him credit for actually talking publicly with people. Most CEO's hide behind the PR department, or speak only one-way, without replies.
- woodman 10y ago> Most CEO's hide... As they should when they're so divorced from reality that they provide the justifications that this guy has. Open dialog is nice, but it doesn't mean much when the underlying message is that of hostility.
- kstrauser 10y agoI'm loathe to give him credit for publicly saying the most ridiculous things imaginable from one in his position.
- ademarre 10y agoRight. I'm glad he spoke publicly because it shines more light on how ridiculous his position is. He actually tries to justify (or deflect) stealing the Let's Encrypt trademark by claiming LE stole the concept of a 90-day cycle. Ridiculous.
- cbd1984 10y ago> He actually tries to justify (or deflect) stealing the Let's Encrypt trademark by claiming LE stole the concept of a 90-day cycle. Ridiculous. You can patent business methods, but saying a 90-day cycle is an "inventive concept" would likely cause a competent attorney to take you to one side and quietly convince you to not point that fifty-caliber BMG at your leg. https://en.wikipedia.org/wiki/Business_method_patent https://en.wikipedia.org/wiki/Business_method_patent
- hosh 10y agoThat's not really the heart of the issue. He seems to be taking it as a point of honor, as if someone is stealing his business model ... but LE isn't a business. Comodo might or might have innovated a 90-day free trial. But let's say for a moment that Comodo did invent the 90-day free SSL trial. The intent is for the promotional purpose of purchasing paid products. LE has no paid tiers, and the primary motivation is to help the internet get encrypted, not to sell certificates. What's ridiculous isn't the idea that a 90-day cycle got "stolen", but that the Comodo CEO persistently thought of ISRG as a business competitor when they are not even in business. (No one is fighting you, dude). What I don't get is why so many people kept playing into that erroneous assumption of his instead of calling him on it.
- AdamGibbins 10y agoGreat to see a resolution to this issue, but this doesn't change the huge distrust in the organisation I've now gained. I won't be for the foreseeable future be buying any Comodo service again. They're clearly horribly misaligned with my values.
- ovt 10y agoGlad they gave up, but calling it collaboration and speaking of thanking is silly bullshit.
- jtokoph 10y agoToo late for me. Already renewed my expiring certs elsewhere yesterday.
- oolongCat 10y agoI wonder if several hundred people like youself had anything to do with their "express" abandonment.
- diegorbaquero 10y agoStill, will never buy from them again.
- tommoor 10y agoYup, that reply from the CEO alone is enough for me to never want to buy a cert from Comodo again.
- nneonneo 10y agoIn the original Comodo forum thread about this issue (where the CEO made some claims about owning the 90-day certificate) there is this new response from a staff member (https://forums.comodo.com/general-discussion-off-topic-anything-and-everything/shame-on-you-comodo-t115958.0.html;msg837436#msg837436 https://forums.comodo.com/general-discussion-off-topic-anyth...): > With LE now being an operational business, we were never going to take the these trademark applications any further. Josh posted a link to the application and as of February 8th it was already in a state where it will lapse. > Josh was wrong when he said we’d “refused to abandon our applications”. We just hadn’t told LE we would leave them to lapse. > We have now communicated this to LE. On LE's blog post, they mention that they have repeatedly asked Comodo to abandon the applications since March 2016. If Comodo was going to let the applications lapse as they claim, why not communicate this at the earliest opportunity? To me this is a dodgy answer at best. I am not so familiar with trademark law, but I don't believe that an application "being in a state where it will lapse" is in any way disarmed - it is my impression that Comodo could simply have opted to continue the process, but is pretending that they wouldn't have in order to avoid bad press.
- hosh 10y agoHow is it that the Comodo CEO kept assuming Let's Encrypt and ISRG is a business, when it isn't? It's like he's fixated on that assumption and is dragging everyone else into it. Further, the last time I read through things about trademarks, my understanding is that they don't work the way some of the people posting say it does. Trademarks are influenced by whether it is a distinguishing mark or not. You can lose trademark protection if it comes into common use. Once registered, you have to keep defending it as a distinguishing mark. So I'm not sure where the "paralegal" in that forum thread is coming up with the argument that it somehow works like a "first-to-file" -- the person who possesses the paperwork possesses the right. Maybe my understanding is incorrect. If it isn't off though, I can see their lawyers saying, Comodo really doesn't have much of a case (but it'd still eat up a lot of time and resources a small non-profit won't have).
- jlgaddis 10y agoThe paralegal in that forum thread is also talking about copyright -- and claims some knowledge about it. Yet this issue centers around trademarks, which are very different from copyrights.
- davidgerard 10y agoWe are switching our Comodo certs over to Let's Encrypt because certain old Android versions we have to support work with LE certs but not with Comodo. Particularly important for APIs. The 90 day expiry is a bit of a faff, but we've mostly automated it using acme.sh and automated DNS edits, and now we just need load balancer access (we just moved to new hosts). LE is a godsend and fully up to commercial use in our experience. After this, there is no way on earth we're giving Comodo money again. I would rather pay Thawte than these bozos.
- technion 10y agoI've dealt with this issue for years. Comodo certs have two possible chains. If you want to be supported by older Android (and older iOS) devices, you needed to configure your server to hand out the longer of the chains. When you buy a cert, this is not the chain they will recommend. This is easy under Linux if you can find the right certs, a huge PITA if you're on IIS. They do an incredibly poor job of documenting this or informing their support on how to address it.
- davidgerard 10y agoWe switched to Let's Encrypt literally because of this, so that's a direct penalty for their stupidity on this one ;-) Do you know a writeup anywhere of the cert chain issue? (I ask for idle amusement, no way we're going back to them.) Oh, and when I say "fully up to commercial use", we plan to use LE certs for our dev instances too (so we're SSL at all stages of development).
- technion 10y agoNo write up anywhere that I ever found. The best investigative tool is the SSLLabs SSL test, which will show you both possible paths from the cert. By looking at which certificates that test shows the server provided, you can divine which path things are going to take. If you find yourself landing at a root CA which is newer and not trusted by as many devices, those devices won't intelligently realise it's cross-signed, unless you switch the certs the server offers to send them up that path.
- skywhopper 10y agoAlas, it's too late to save the business they lost forever from my company and others who switched our business to another provider literally yesterday. Thanks Comodo, for letting us know you are not a company we wish to do business with.
- technion 10y agoIt's a statement made by what appears to be a new employee, who earlier on in that thread appeared to contradict their CEO. Melih's arguing on that thread has reached the level of trollbait.
- ShakataGaNai 10y ago> thank the Let's Encrypt team for helping to bring it to a resolution. Translation: Thank you LE team for sending the seething rage of internet masses after us. We surrender.
- tetrep 10y agoWhy do I see this post as "[flagged]"?
- admksx45v65uqpw 10y agoI was wondering this too, seems to have been removed though.
- woodman 10y agoThis happened on the other link to their message board, and it doesn't surprise me - the CEO has plopped himself in the middle of a very charged issue, making it difficult to discuss the issue without it getting personal. HN is great, due in large part to the moderators knowing what they're doing, but a little more transparency on flagging would be nice (like @dang's unlink and retitle messages). This sort of thing is only going to become more important as information manipulation in old media becomes less effective on people who form their opinions in places like this.
- ausjke 10y agoNever used Comodo, and never will. Beside abusing the legal system, there is something else called right and wrong by common sense. A CEO does not get that really should try a different job.
- pmontra 10y agoA wise decision to limit losses and a face saving statement. They shouldn't have started this, hopefully a lesson for other companies.
- dsr12 10y agoLet's Encryption updated their blog post: "Update, June 24 2016 We have confirmed that Comodo submitted Requests for Express Abandonment for all three trademark registration applications in question. We’re happy to see this positive step towards resolution, and will continue to monitor the requests as they make their way through the system. We’d like to thank our community for their support."
- viraptor 10y agoI'll never be sure if this is true, but it will be in my memory... User robinalden is the CTO, who I tweeted ~2h before the response was posted (https://twitter.com/viraptor/status/746138644537237504 https://twitter.com/viraptor/status/746138644537237504). Given that he only posted 13 times on those forums, I hope I actually caused him to ask Melih what he's doing :)
- stanislavb 10y agoHackerNews has won!
- nojvek 10y agonot really, hn still uses certs from comodo. cloudflare still uses certs from comodo. cloudflare and hn dropping comodo would have been close to a win
- ComodoHacker 10y agoOK, I won't change my nick to ComodoPhacker this time as I planned to. Does anyone know a good free alternative to their Comodo Internet Security product? I know there are plenty of free AV products, but I also use its firewall and HIPS features, especially detailed logging.
- 56k 10y ago"the trademark issue is now resolved", amazing. They clearly wanted to put them out of business because they see them as a competitor!