Earlier quoted context omitted.
Eh, honestly, that's what getting an SSL cert used to be like 15 years ago. They can knock it all they want, but really, the process functioned pretty much as expected. Like a lock on your front door, the purpose is not to prevent unwanted people from ever getting inside (no lock will ever accomplish that), but to both make it take long enough the likelihood of being noticed is high, and to put enough hurdles in plac…
Funny how Let’s Encrypt is so popular because it doesn’t inconvenience people, and as a result more websites than ever have been secured, to the betterment of society.
In the past you used to be fairly sure a company was somewhat legitimate and responsible if they has an SSL cert and could supply card information to them without too much worry, as someone had vetted them as a real company (to some degree). These days, that doesn't happen, and whether I'm willing to give a company my credit card has nothing to do with if they are secured with a cert (which is a bare minimum to use the site). That cert doesn't really imply much anymore though. These days, I'll only enter my card into large reputable sites, or if they are using a payment service I trust (PayPal, Amazon, Square, etc), as they've presumably done a lot of the vetting that the SSL companies traditionally did.