Lol. "This is pretty bad. Someone circunvented the ban on emitting public certificates but also disrespected Google's CAA rules. Hope this CA gets banned on Microsoft OSes for good."<p>Yeah, this is after the certificate was issued, and my guess, used.<p>Also, has anyone tried to look up CT logs lately? I tried. Can get maybe a single FQDN if you look, but trying to do wildcards or name-alikes, nothing worked. Most of the CT searching websites were straight up broken. Clearly nobody is actually looking at CT logs.<p>CAs are a joke. There's a dozen different ways to exploit them, they <i>are</i> exploited, and we only find out after the fact, if it's a famous enough domain.<p>We could fix it but nobody gives a shit. Just apathy and BAU.