3 ms·
I'm not an expert, and I'm not saying they're doing it wrong. But for what it's worth, just because they thought for a long time doesn't mean they made the rig
by throwaway20371 5y ago
I'm not an expert, and I'm not saying they're doing it wrong.
But for what it's worth, just because they thought for a long time doesn't mean they made the right choices. Some of their design decisions have been not great. You can still create perfectly valid domain certs for domains you don't control with a variety of common attacks. Then there was the ACME API vulns. Either they knew about all this and chose a simpler design that's more flawed on purpose, or all that thinking just didn't end up being correct.
- traceroute66 5y agoYawn. If you're after a Let's Encrypt bashing session then I suggest you take it elsewhere. They might not be perfect, but you get what you pay for, just like open-source software. Free but no warranty. Fine by me since Let's Encrypt is available 99.999% of the time, outages are the exception rather than the rule (plus you should always be renewing your certs in good time and not at the last minute).
- deleted 5y ago[deleted]