robkelk Wrote:I'm not determined that they must be bad. What I've been saying all along is that I don't know what they are.
Well, it sure feels like it sometimes. Like, the information on why you don't need to add their CA to anything, it's not that hard to find.
There's something kind of funny about suggesting that a site with thousands more users than us be our mine canary. But how long does their track record need to be? The only new technology here as I understand it is the automated certificate renewal process, which has a relatively benign failure mode... but from here, it isn't looking like they have that problem very often. Especially considering just how many certificates they're responsible for.
-Morgan.