Doesn't ssl handshake require knowing the private key?
Doesn't ssl handshake require knowing the private key?
And yes, technically he's not wrong. Well, technically he is wrong, in that it wouldn't be a MITM attack, exactly, but if an attacker can intercept requests sent to your domain by LE and respond however they want, they can generate an LE cert for your domain, even if you're not using Let's Encrypt. That said, they can't intercept generation of the LE certificate - the HTTP request is just to prove that you've got enough control over the domain to justify issuing one.
Using HTTPS wouldn't prevent that. I'm actually not sure how you would prevent that, short of removing HTTP-01 from the spec and requiring DNSSEC and so on. EDIT: I see a sibling comment pointed out that Let's Encrypt are aware of this, and are using "multi-perspective validation" to make requests from multiple regions, making this attack much harder to pull off (but never impossible, I suspect): https://letsencrypt.org/2020/02/19/multi-perspective-validat...
Let's Encrypt uses Multi-Perspective Validation (https://letsencrypt.org/2020/02/19/multi-perspective-validat...) in order to protect from most interception of the DV request.
Also, I think you meant TLS but that is only used in HTTPS not HTTP.