This is a horribly misinformed article, and is incorrect about the most fundamental arguments it is making. E.g. Among many other issues, it implies that a compromised CA would allow passive MitM.
Pinning certs (HPKP) is too dangerous so very few people implement it. That means if I have a signing cert for any trusted CA, I can ssl-strip with ease. This really has nothing specific to do with Lets Encrypt however. Any trusted CA signing cert will do. Or even an unlocked server cert (missing constraints) will do.
> If DigiCert’s Key Management System is compromised, all of their SSL certificates will have to be revoked and re-issued. But if one of the other CAs is compromised, it would not affect Medium’s site.