3 ms·
>By the standards of modern disk and network, couldn't they download revocation caches the way they do with malware? The whole point is to check if a cert has
by acoard 6y ago
>By the standards of modern disk and network, couldn't they download revocation caches the way they do with malware?
The whole point is to check if a cert has been revoked. If you have an out of date cache, you'll falsely approve a cert that should be revoked. I'm not defending the system as a whole, but if you care about revoking authentication – which they clearly do – then a cache directly undermines that goal.
A malware hash doesn't get revoked, new ones just get added.
- Dylan16807 6y agoSo update it every hour. Or every time it feels the need to check a program, instead of asking about that program, it could ask for all revocations from the last day.