Hacker News new | ask | show | jobs
by lxgr 1284 days ago
Commercial CAs verify exactly two things: Administrative control over a domain name and a working credit card number.

Let’s Encrypt only gets rid of the latter, and given that fraudsters able to spoof the former can probably spare the $10 for the latter, I‘d argue that this is a good thing.