Let's Encrypt is based in the United States and subject to the laws of the United States, including National Security Letters. What are the implications for foreign sites that use Let's Encrypt?
Here's what I have come up with thus far:
- Let's Encrypt could be forced to revoke a certificate
- Let's Encrypt could be forced to issue a counterfeit certificate
- Let's Encrypt could be forced to keep any activities secret
Furthermore, Let's Encrypt is controlled by the Internet Security Research Group which includes members whose companies are part of the US PRISM program (Google, Facebook, etc).