3 ms·
Considering that a majority of the Lets Encryot userbase would probably be running http rather than https if it weren't for free certs, it's still probably pref
by Thriptic 7y ago
Considering that a majority of the Lets Encryot userbase would probably be running http rather than https if it weren't for free certs, it's still probably preferable to have only one
or a handful of malicious entities able to observe traffic. You're not wrong though overall, the certificate model doesn't have built in protections for malicious CAs.
Overall I would argue that companies that are dealing with sensitive data should be using EV certs anyway to help users defend against phishing attacks which Let's Encrypt doesn't offer to my knowledge. This is tangential to your point though.