3 ms·
It sounds like that's how it used to work, and then it changed for some reason, maybe to do with the size of the list and a need for faster updates. Actually t
by JackC 6y ago
It sounds like that's how it used to work, and then it changed for some reason, maybe to do with the size of the list and a need for faster updates.
Actually that unknown exposes the problem with the original article's demand that critics explain what they want to replace Apple's system. No one outside of Apple is in a position to design a system that addresses all of the design constraints -- we don't even know what they all are. But we are in a position to assert some additional design constraints, such as requiring that the system not leak developer certs to eavesdroppers every time an application is run, and expect Apple to figure out a solution that takes them into account.
- kelnos 6y ago> It sounds like that's how it used to work, and then it changed for some reason, maybe to do with the size of the list and a need for faster updates. If that's true, that's a lazy excuse on Apple's part. Differential updates has been a solved problem for many, many years. Hourly or even daily diffs would be tiny (likely much less traffic than the OCSP checks that occur now), and expired certs could be dropped from the local store, so it wouldn't grow without bound. (Sure, ok, people could turn their clocks back and defeat that last bit, but doing that would break other things, too, like TLS to any website with a reasonably recent cert.)