CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox

28 points by freddyb


DustyFuzzy

This is, in short, cool shit. With this, assuming places outside Firefox adopt it, I could confidently say that revocation actually works (albeit with a delay of up to 12 hours, but that’s better than before)

cmcaine

Since OCSP requests are typically made over unencrypted HTTP, this information is also leaked to all on-path observers.

What clownshoes bullshit is this???