Of course the same applies to the for profit CAs. And yes, I am very much aware of the Symantec disaster. None of that addresses the questions I raised, which have to do with “free” and “automated” resulting in a “fire and forget” complacency.
I am helping a couple companies right now rebuild their sites after having been hacked… Both thought their sites were “secure” because they had an SSL cert from LE.