> How do you do that part today? Not via Let’s Encrypt.
Not even via TLS.
In all seriousness, PKI at web scale is a joke. Nobody knows which CAs are installed in their browser, who these entities are, how trustable they are, etc.
I have long accepted that TLS brought encryption, but certainly not trust.
I wouldn't say that it's all a "joke" in the context of assurance. I know a number of vendors that implement mTLS as part of their customers onboarding. I wouldn't be surprised to see product movement in this space to better address the consumer markets (maybe financial first?) with something that better manages and abstracts this for them. This, in many ways, solves a lot of exposure issues, but at the cost of what's overly complex for most users today.
Not even via TLS.
In all seriousness, PKI at web scale is a joke. Nobody knows which CAs are installed in their browser, who these entities are, how trustable they are, etc.
I have long accepted that TLS brought encryption, but certainly not trust.