Hacker News new | ask | show | jobs
by internetisthesh 4198 days ago
CRLset contains a fraction of all actual revocations. As far as I remember Chrome chose this solution to minimize download size. I'm my opinion, if revocation checks only are done sometimes it cannot be trusted. I am not arguing that Chrome e is better or worse than other browsers, just that their current model is broken and give users a false sense of security.

Don't you agree that the current method where the Chrome team choose a limited set of revocations to push to users is broken?