I am also concerned about the centralisation of everyone going to Let's encrypt. Yes they are non-profit but they are located in the United States and must follow US laws.
If LE is compromised a few times and some fraudulent facebook.com or google.com certs leak out, how long before Firefox/Chrome/Edge blacklist their root cert like they did with Symantec[1], and end up breaking half the internet?
I understand that ACME is an open standard, but can someone point me to an alternative ACME provider that isn't "please call us for a quote" enterprise-grade?
[1]: https://blog.mozilla.org/security/2018/03/12/distrust-symant...
Anyway I'm not arguing that it would be impossible to create an LE2 but it would not be that simple. Especially if the buyer is someone already in the certificates business that wants to destroy the "free-for-all" concept.