
You go to a different CA

You go to a different CA

You do make a good point. However, Let’s encrypt is run by the IRSG which is a non profit focused on improving internet security. They are the ones who are pushing for shorter certificate lifetimes among other things.

ZeroSSL is probably what OP is looking for

The private key isn’t used for encryption

The certificate is only used for authentication. The actual data is encrypted with a temporary symmetric key that is generated via a diffie-hellman exchange
Even if they had your private key they still wouldn’t be able to decrypt the data

Maybe I’m mistaken but aren’t the logs cryptography verifiable? (As in you can’t create a rouge cert without it creating a trace)

Let’s encrypt is very transparent and has been designed to be auditable. What are you worried about exactly?

Lost Lemmings?

Allows is doing a lot of heavy lifting
The are deliberately adding ads
The transparency logs would mean that any rouge certificates created would leave a paper trail not to mention there is nothing stopping them from issuing a certificate for any domain of their choosing