3 ms·
Your concerns are completly right but there is a catch: Let's Encrypt is trying to lower the barrier in money and time to offer encrypted connection between a s
by Kurnihil 11y ago
Your concerns are completly right but there is a catch:
Let's Encrypt is trying to lower the barrier in money and time to offer encrypted connection between a server and you.
Even now there are different level of certificate in the standard, you could notice it when you see the lock icon in your browser turning green or not. Hacker News, for example, doesn't offer owner information so it's grey; Twitter instead turn green as it uses the most secure certificate.
The fact is that when you connect to my website ilikeapple.com in which I write about my experience as a apple farmer, you don't need to be sure of my server identity ('cause you don't even know my website) but you could still need message confidentiality ('cause you don't want your rival farmer to know that you are interested in planting apple tree next year).
So, don't put your credit card number in a site that not offer server identity (Hacker News for example) but don't worry too much about the certificate of let's Encrypt because are the lower level possible of certificate.
P.S. They are working to expand the same concept at "higher grade" certificate but of course is a work in progress (and is not sure it's possible)