4 ms·
Given they are managing the certs anyway they can revoke on behalf of the "average pleb", Just like CloudFlare did. It is debatable how useful revoking is anyw
by abritishguy 11y ago
Given they are managing the certs anyway they can revoke on behalf of the "average pleb", Just like CloudFlare did.
It is debatable how useful revoking is anyway so I agree that this provides more security, I just wasn't sure (until reply from Sandstorm) whether it would be worth the effort of setting up private key rotation.
- kentonv 11y ago> they can revoke on behalf of the "average pleb", Just like CloudFlare did. Yes but the revocation infrastructure was totally overwhelmed by that and it's unclear if many of those revocations ever made it to users' browsers. E.g. Chrome only honors the revocation lists shipped with Chrome updates -- it does not query OCSP -- and browsers that do query OCSP will "fail open" if the servers don't reply (which they often don't). (It sounds like you recognize this, just stating it for those who might not.)