DDOS attacks and what's going on SSL certificate issues, are separate things. For the non-techy, DDOS attacks keep you from visiting the site period or intermittently getting in. You'd be able to login without issue just 1 attempt in 100x or so. Certificate issues are different and consistently throw the errors observed. Cert issues also allow eavesdropping.
I think OH2 is a threat, and I know I'm about the 50th to state this but...it feels like a threat to providers and visitors b/c of the certificate issues.
https://eccie.net/showthread.php?t=2831422