The CEO seemed really self absorbed and saw himself as an innovator with letsencrypt stealing business processes from him (which makes filing for trademark infringement make less sense). He took it as a personal insult, and did not even appear to understand that letsencrypt was a public service rather than a for-profit product.
There was a fan who claimed to be a paralegal cheering on the CEO's rant yet appeared to confuse trademarks with patents with copyrights.
At least with the forums alone, that thread read like teenage high school soap opera, not a business. It was like an echo chamber of the CEO's fixation.
And now this. Sounds like there was a deliberate business decision to use faulty tech, and forgetting the wider social impact of operating a CA.
https://forums.comodo.com/general-discussion-off-topic-anyth...
Here's the HN discussion
Otherwise, I applaud the initiative.
If you would like to use it without root/sudo, you can pass flags changing the directory it uses. For example:
certbot --logs-dir ~/SSL --work-dir ~/SSL --config-dir ~/SSL 1etsencrypt.orgPublic key pinning seems like it would prevent this attack though.
It's good to encrypt things, but I wouldn't be too surprised if it were possible for folks to issue bad certs via them, as well.
This OCR issue with Comodo in TFA concerns WHOIS data, which may or may not be more reliable than unsigned DNS data. Regardless your point remains valid.