3 ms·
Unless they activate HSTS, it shouldn't be a problem. They can always go back to HTTP if they want. Also, Let's Encrypt doesn't even revoke certificates for ma
by jdu9 6y ago
Unless they activate HSTS, it shouldn't be a problem. They can always go back to HTTP if they want.
Also, Let's Encrypt doesn't even revoke certificates for malware and phishing sites. [1]
Maybe they're doing this for better caching performance? It makes SSL flood attacks impossible, but is that really worth it?
[1] https://community.letsencrypt.org/t/how-to-report-abuse/41106/4 https://community.letsencrypt.org/t/how-to-report-abuse/4110...