> This shows that Let's Encrypt security is a joke because now any large national ISP can use same MiTM to issue a certificate for any site hosted within a country. The SSL infrastructure is completely compromised.
the information available right now are too vague to come to a conclusion this bold.
Instead, I find it something like the following more plausible:
jabber.ru and xmpp.ru seem to use "exotic" DNS servers (at least as I checked right now).
https://uk.godaddy.com/whois/results.aspx?itc=dlp_domain_who...
All it then takes is an exploit there in the DNS server, or a badly set-up ACME DNS-01 there, in order for Let's Encrypt to grant an SSL certificate.
https://letsencrypt.org/docs/challenge-types/#dns-01-challen...
The moment you're able to write a (TXT) record for some domain name, you have proven to be eligible for getting an SSL certificate for that domain name.