Conversation

Replying to
I'd rather they finish getting accounturi / validationmethods to production. Has been on staging for ages. It makes domain validation actually work as people would probably expect. Makes CT more valuable for people who don't track each valid cert on each server for it too.
1
1
Replying to and
Most people checking CT are just going to see a bunch of Let's Encrypt, nothing else, and call it good because they trust LE. Meanwhile, they verify domain control via ~2x unauthenticated HTTP requests happily hopping between a bunch of servers / domains to find the challenge.