Hacker News new | ask | show | jobs
by b112 134 days ago
Isn't that a really, really juicy target though?
1 comments

LetsEncrypt doesn't see your private key when you obtain the certificate. So no, it's not _really_ a juicy target.
On the other hand, who's gong to notice a LE issued cert that they did not request in the certificate transparency logs?
The ones who monitor their domains in the CT log.

(Mom-and-pop-stores probably won’t. Other orgs might.)