7 ms·
> I think the article suffers from a clear point that I can put my finger on He doesn't trust LE not to hand over a mitm certificate to some us american three
by Jon_Lowtek 5y ago
> I think the article suffers from a clear point that I can put my finger on
He doesn't trust LE not to hand over a mitm certificate to some us american three letter agency and therefor refuses to use it.
> "LE is definitely a NOBUS" sounds a lot like a conspiracy theory
It sure does.
> you have CAs in your browser/machine that are far more sketchy
LE is in the focus of the headline, because people keep bringing it up to him. That is in the first paragraph. People complain about their browsers having trust issues with his webserver, and then go karen and suggest he uses LE, instead of establishing trust between the endpoints.
> LE doesn't force you to add CAA DNS records.
That you seem to misunderstand. The large selection of sketchy CAs the browser trusts are the reason why webmasters should use CAA DNS records. His page has both a TLS certificate and a CAA record, but the CA that issued it and is named there is not trusted by the browser vendors.
- josephcsible 5y ago> He doesn't trust LE not to hand over a mitm certificate to some us american three letter agency and therefor refuses to use it. The flaw in this logic is that LE could do that just as easily whether or not you use them for your legitimate certificate. And if you're worried about things like that, running insecure HTTP instead is about the worst thing you could do.
- Jon_Lowtek 5y agoyeah you are right, that can't be it. Maybe the core point is that he considers the whole browser vendor based pki to be nonsense and refuses to partake, offering a self signed certificate instead. He probably memorized the key fingerprint and can verify it in person. The core point might be that those who want him to use LE barely care enough to make their browser not show warnings, they don't actually care about establishing trust.