It’s sad that these arguments are still being shared. It was the same arguments years ago from people that would just assume that a free cert was inherently unsafe.
Comment on Let's Encrypt is 10 years old today !
jj4211@lemmy.world 2 days ago
Just two months ago, a security team member dinged one of our services for using Lets Encrypt, as “it’s not as secure as a traditional CA”.
EnderMB@lemmy.world 2 days ago
bfg9k@lemmy.world 2 days ago
I’d love for them to explain how, if anything the short cert validity and constant re-checking of the domain seems more secure than traditional CAs
dan@upvote.au 1 day ago
I’d also argue that the fact that it’s automated and their software is open source makes it objectively more secure. On the issuing side, there’s no room for human error, social engineering, etc.