This is NOT a reason to distrust a website.
This is NOT a reason to distrust a website.
I personally would trust something signed by Lets Encrypt more readily than many other certificate providers. They appear to know what they are doing.
[0] https://www.troyhunt.com/extended-validation-certificates-ar...
In other words, if the bank is following best security practices, they're fine with Letsencrypt; if they don't, they might need somebody else.
From a compliance, regulatory & risk perspective, definitely.
The EV certificate often comes with additional liability protection to cover any end customer claims related to certificate issues (i.e., if the authority is compromised and the customer's PII becomes exposed).
> While everyone can register for free on Let’s Encrypt, only (or mostly) serious companies pay money to register on DigiCert, GoDaddy, and so on.
GoDaddy is not a serious anything. DigiCert perhaps, but GoDaddy has repeatedly shown themselves to be scummy and untrustworthy.
That said, I do see the value in having an entity like a bank pay for a stricter cert with identity validation versus leveraging Let's Encrypt's free infrastructure which only validates domain/site control.
Serious companies donate the money they saved by not buying snake oil to Let's Encrypt.