And that's a big mistake. Certificates means authentication first and encryption second. Encrypting without proper authentication is useless. Yes, you encrypt, while communicating with who?

This is just alike the abysmal state of domain registration. Crooks can easily get millions of domains, including those very close to legitimate ones. Allow them to easily get certificates also and everything becomes useless to protect users.

The whole PKI architecture was designed with a proper vetting procedure before releasing a certificate in mind. Without it, it can't work. Actually, EFF & C. aren't making communications more secure, they're making them less secure.

