That’s why CT came around.
Some background for those unfamiliar.
https://scotthelme.co.uk/revocation-is-broken/
https://medium.com/@alexeysamoshkin/how-ssl-certificate-revo...
Although OCSP stapling is used more now IIRC.
HN doesn’t set OCSP must staple so we’re still a while away from being able to trust it.
https://medium.com/@alexeysamoshkin/how-ssl-certificate-revo...
Although OCSP stapling is used more now IIRC.