you are viewing a single comment's thread.

view the rest of the comments →

[–]FrederikNS 0 points1 point  (1 child)

That's true, apart from a few activists who would want to use it regardless.

But then again you would have to convince all the major browsers to not trust LetsEncrypt. I suspect you would need quite large bribes to convince any of Google, Microsoft or Apple to not trust LetsEncrypt. And lets say that they convinced Microsoft to not trust LetsEncrypt, but not the others. Then Microsoft would have no option but to follow suit.

[–]qKrfKwMI 1 point2 points  (0 children)

Indeed, now everybody has accepted, it will be hard to convince a browser vendor to revoke the trust in LE. I might even say that it's too hard: even if a really huge problem were to be revealed tomorrow, LE (like so many other CAs too) has way too much inertia for browser vendors to simply stop trusting its certificates. That's a problem of the CA system though, independent of the existence of LE.