|
|
|
|
|
by justhere4beer
1523 days ago
|
|
I applaud the Let's Encrypt founders, past and current team for solving the automation problem that's plagued the SSL/TLS industry. The yang to that ying is a lack trust. I have zero trust in a site owner using LE certs. Domain vetting only means control of the domain ... everything inside that beautifully encrypted traffic can be insightful, helpful or script kiddies scamming the vulnerable. If one finds the scam, LE shrugs, "not our problem bruh. We just issue certs to those who control the domain." They single handedly reduced the price of entry for douchebag asshats ability to pretend someone they are not and harm a non-technical populace. Two steps forward, one step backward. |
|
None of this was the fault of Let's Encrypt. They just exposed the mistakes that were OV and EV certificates and incorrect education.