| ▲ | monerozcash a day ago | |||||||
You can't decrypt anything with letsencrypt root certs, you can issue your own certificates but it would be impossible to use those at any significant scale. It's also worth considering that CT makes it extremely noisy to use such certificates to attack web browsers. | ||||||||
| ▲ | hollow-moe a day ago | parent [-] | |||||||
I'd bet they could absolutely proxy large parts of people and make use of these certs. I wonder how much are CT logs scrutinized, would these "rogue" certs be found easily because we can't find traces of them being generated by letsencrypt ? Browsers checks CRLs but are they checking CT logs to be ensure the cert they're checking was logged ? | ||||||||
| ||||||||