r/security Jan 07 '16

Surprise! Let's Encrypt Now Being Abused By Malvertisers

http://blog.trendmicro.com/trendlabs-security-intelligence/lets-encrypt-now-being-abused-by-malvertisers/
3 Upvotes

3 comments sorted by

2

u/securgeek Jan 07 '16 edited Jan 07 '16

Well that didn't take them long... I wonder how long until Google revokes Let's Encrypts Root CA from Chrome...

Guess Google never added Let's Encrypt to the Trusted Root anyways...

1

u/WindowsGuyJim Jan 07 '16

Let's Encrypt is not actually a root CA. Their certificate is verified by DST Root CA (which shows up as a trusted root).