3 ms·
Mozilla's solution to this is to run every single certificate in the CT log through the filter, and remedy any false positives with an extra layer. The filter a
by tbodt 6y ago
Mozilla's solution to this is to run every single certificate in the CT log through the filter, and remedy any false positives with an extra layer. The filter also has a date attached, so potential false positives that are newer than the filter can be checked with OCSP.
https://blog.mozilla.org/security/2020/01/09/crlite-part-2-end-to-end-design/ https://blog.mozilla.org/security/2020/01/09/crlite-part-2-e...