4 ms·
> Without widespread adoption of a must-staple extension, OCSP is cosmetic. The decision to disable it didn't come from simplicity fascists; it came from people
by problems 9y ago
> Without widespread adoption of a must-staple extension, OCSP is cosmetic. The decision to disable it didn't come from simplicity fascists; it came from people like Adam Langley. AGL isn't right about everything, but if you take the position that something he does with Chrome TLS is ludicrous, my default will be that you don't understand the issue as well as he does.
Well, please, do explain where I'm mistaken here - is OCSP required not the most secure option? And it was rejected simply due to usability reasons on Chrome?
And the option to do so anyways for power users doesn't exist because Chrome is a browser for ease of use?
I'm not saying it's entirely ludicrous - for a good chunk of the user base CRLs are at least decent - but having an option for power users who desire more security should be available. And it's mandatory for any browser that wants to be used by power users.
Stop with the appeals to authority and make an actual argument if you disagree.
- tptacek 9y agoI don't understand the questions you're asking here, but, no, OCSP wasn't disabled simply due to usability reasons, but rather because it did not work.
- problems 9y agoIt works just fine if you require an OCSP response and hardfail. Soft-failing is for usability and it's the cause of the problem. Yes, must-staple is the optimal solution, but OCSP required is the best available today. Look at some of the numbers here: https://www.grc.com/revocation/crlsets.htm https://www.grc.com/revocation/crlsets.htm
- tptacek 9y agoSoft failing isn't for "usability". OCSP simply doesn't work in situations where you would otherwise soft-fail, not because of any problem with the certificate, but because the protocol itself does not work.
- problems 9y agoHow so? Replay might be a bit of a concern, but it's fairly time limited. The other stuff cited by Langley is just down to usability alone.
- tptacek 9y agoYou are using the word "usability" to describe a situation in which extremely popular sites that are themselves doing everything right from a security perspective simply stop working --- because OCSP does not work. This is a silly conversation, and I'm opting out of it now.
- problems 9y ago> simply stop working How would this happen? Are you suggesting that network failures are something that shouldn't impact even advanced users who've opted themselves in to the potential pitfalls in order to gain security? I'm not suggesting hard-fail be the default, I'm suggesting CRLs be the default with hard-fail as an option for advanced users who know how to resolve problems when they do occur.