My impression was the CA's made the likes of Standard and Poor look rigorous, but I'm happy to learn more from actual experience of them rejecting such an application.
My point wasn't to discredit LetsEncrypt, but to point out that Google's claim to mitigate the MITM attack vector with https-first wasn't a very strong argument. I mean, yes, sure: if you can't intercept or downgrade to HTTP the MITM doesn't work. But all the HTTP seems to do was redirect to a malicious payload. But you can also do a redirect in HTTPS.
So if you can spoof someone to go to https://g00gle.com/ it should be just as easy to launch the attack chain from there.
Source: Have to be that human from time to time
If you get the normal DV cert they don't provide any more verification than Letsencrypt.
And since browsers have moved away from indicating OV/EV certs to end users, not many organizations are paying for those anymore.
OTOH, Certificate Transparency Logs will give the game away, so there's that.
Are you saying that CAs should be refusing to issue certs for potentially spoofed domains?
I just mentioned LetsEncrypt because it's free and exceptionally easy to use. I'm not implying in any way they aren't providing a great service, it's just that that service also gets misused because it's cheap and easy.