Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For example at Mozilla there are discussions about it, I suspect it's happening for other browsers too:

https://lists.mozilla.org/listinfo/dev-security-policy



Any links to specific threads? I don't find anything when searching that list for "revocation" or "revoke", though there seem to be lots of threads about CAs in general, so maybe there's relevant discussion in some of those.


https://groups.google.com/forum/#!searchin/mozilla.dev.secur... for example (3 years old).

The right keyword to search for is OCSP, because CRLs are completely impractical in the browser.

But then we have the issue that OCSP is a pretty retarded protocol. OCSP stapling helps with some issues, but there is still the issue that it doesn't really check if a certificate is valid, but whether a certificate bearing the given serial number is valid. Which didn't help AT ALL when using MD5 collisions people managed to create multiple certificates under the same serial number.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: