Hacker News new | ask | show | jobs
by mballantyne 4442 days ago
Do CRLs even work? My understanding is that the only browser that hard-fails to load a page if OCSP is blocked is Chrome for certs in CRLSets. Everyone else is vulnerable to MITM if access to the CRL / OCSP servers is blocked.

I would love to be wrong. Does anyone know if anything has changed for the better since 2011?

http://blog.spiderlabs.com/2011/04/certificate-revocation-be... http://dev.chromium.org/Home/chromium-security/crlsets https://www.imperialviolet.org/2011/03/18/revocation.html