|
|
|
|
|
by SilasX
1972 days ago
|
|
>it didn't happen every time True, but it didn't make much difference, since the reports from the thread showed it had a bizarrely short cache time. >the server didn't keep any logs Well, that's the rub isn't, it? Part of privacy-centric design is that you shouldn't have to risk such information being exposed or trust such reassurances; if they don't need the information, they shouldn't get it at all. There are privacy-respecting ways to do what they wanted to, which are also more efficient. For example, periodically update the machine's local revoked cert list, and check signatures against that (as several users recommended). >etc Was there anything substantively different from my characterization? |
|