4 ms·
The fact that this slows down devices boils down to a rushed or simply incompetent implementation. It's sensible to require waiting for a certificate check the
by pushrax 6y ago
The fact that this slows down devices boils down to a rushed or simply incompetent implementation.
It's sensible to require waiting for a certificate check the first time an app is launched, but after that, the cache validity should be indefinite, and updates should occur asynchronously in batches.
The timeout settings were also excessive.
Can't forget the blatant lack of encryption. They either forgot or thought it would be too much effort to set up.
- WesolyKubeczek 6y agoWhen you have a good broadband, it gets so easy to assume that internets grow on them trees, latency is negligible, and servers are fast and always up.
- angry_octet 6y agoYes it is ridiculous that an internet query is in the path of starting a local app for the first time in X hours. If it has to be done, it could be done in a daily batch for all apps when the connection is idle, and on install. Using bloom filters to check for recent invalidations would be even better.
- WesolyKubeczek 6y agoHow many false positives are possible with bloom filters? In the described use case, you don’t want even one.
- sneak 6y agoA positive on on the bloom filter is just an indicator that you do the bigger, more expensive (and privacy-reducing) check, like an encrypted OCSP query for that specific certificate. It's not the final verdict, specifically because of the risk of false positives. Bloom filters are a way of making it so that you don't have to do that bigger, privacy-leaking query every time.