Comment Re:Historical perspective (Score 1) 63
Comment Re:Historical perspective (Score 1) 63
Comment Re:Not Suprising (Score 1) 33
In theory Multi-VA [letsencrypt.org] should still prevent getting a TLS certificate
Yeah, that's why I only said plausibly, rather than possibly, as it'd take that 1:20 shot to make it happen. But plausibly may be overstating it a bit, still.
Any certificates from LE would also appear in the certificate transparency log that currently only has EnTrust and DigiCert certificates. A few hundred pages' worth of certificates.
Given everything we've learned here, do you think they're actually monitoring CT logs? Or hiring a brand reputation service to do it for them? I would bet a lot of money on the answer to that question being no. As you said, asleep at the switch
Comment Re:Naturally (Score 2) 94
Comment Re:You are mistaken. (Score 1) 4
Note: I'm largely basing this on the fact that the comments@whitehouse.gov email address stopped being referenced after the W administration's website. I also found some old reports on dnsspy and such from years ago (including during the previous administration) that had no mx records at all.
Comment Incorrect (Score 1) 4
organizations which support email exchanges with the Internet are encouraged to support AT LEAST each mailbox name for which the associated function exists within the organization.
Emphasis mine.