14,766 Let's Encrypt SSL Certificates Issued to PayPal Phishing Sites
bleepingcomputer.com
bleepingcomputer.com
By that logic, I would much sooner be outraged at registrars for allowing those guys to obtain domain names that put the PayPal name in the address bar. But of course even that is a silly argument, as it's not the registrar's job to enforce trademark protection for any company.
//edit: Trademark protection gets even easier as CT logs present such potential violations on a silver plate.
It's not Let's Encrypts job to protect users from fraud.
When I see the 'green' colour followed by the word 'secure' when visiting a website using chrome, I know that this does not mean immediately that I have to trust the site. I presume the vast majority of hacker news readers will know better too. But what about the normal, average users?
I think we should just be more proactive in telling people what an SSL certificate actually is, and what https guarantees. Otherwise, we are not really having a discussion.
Let's Encrypt's only job is to not issue certificates to people who don't own a domain. Not to ensure the content of the domain is legitimate. That's what EV certs are for.
Your username has been reported. I was about to discuss sensitive information with you. Luckily ycombinator will act.
.. in ordinary English, a "certificate" is a proof or guarantee of authenticity.
Since all new Let's Encrypt certificates get reported to certificate transparency sites, why not set up a bot that searches them for 'paypal' and send alarms to PayPal and the registrar about possible abuse?